Togoder security

npm package security report

typescript@6.0.3 security report

Risky patterns found that deserve a look.

Needs review Version 6.0.3 Files reviewed 7 Size 41.4 KB Scanned

Summary

Togoder Security scanned the npm package typescript@6.0.3 on Oct 6, 2026. An AI review of 7 source files produced 1 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
6
low

Findings 7

medium

Process Spawning and Shell Command Execution

NPS-0A770B22ECBB

The code uses child_process.execSync to execute npm install commands. While this appears to be legitimate TypeScript typings installer functionality, executing shell commands based on npm package names and paths could potentially be exploited if inputs are not properly sanitized.

lib/_typingsInstaller.js:152
low

Dynamic code execution via global object

NPS-BF3542914DCA

The code checks for global.gc and calls it via global.gc call. This is a standard Node.js feature (--expose-gc) and not inherently malicious, but it references global object properties.

lib/_tsserver.js
low

File system manipulation outside package scope

NPS-34BD5A55B15C

The code logs to files and can read/create directories in user home/cache locations (e.g., LOCALAPPDATA, XDG_CACHE_HOME). This is expected TypeScript tsserver behavior for logging and caching typing information.

lib/_tsserver.js
low

Spawning processes or shell commands

NPS-35C04EEAFE8C

The code uses child_process.fork to spawn a typings installer process (typingsInstaller.js). This is a standard TypeScript feature for downloading type definitions, but it involves executing a child process.

lib/_tsserver.js:133
low

Spawning processes or shell commands

NPS-2702692DF766

The code uses child_process.execFileSync to launch an external script (watchGuard.js) via the Node.js executable. This is a legitimate TypeScript tsserver feature for Windows directory watching, but process spawning capabilities require scrutiny.

lib/_tsserver.js:278
low

Array Indexing Error

NPS-68447948CA4D

On line 159 within the indent function, there's a bug where str.replace(/ ? /, ...) lacks the global flag 'g', so it only replaces the first newline occurrence instead of all occurrences. This is a code quality issue rather than a security vulnerability.

lib/_typingsInstaller.js:159
low

File system access

NPS-41E90572B1A2

The script uses fs.watch with recursive option on a directory provided via process.argv[2]. This is a legitimate pattern used by TypeScript's watchGuard to test whether recursive file watching is supported. It closes the watcher immediately and exits, with no data exfiltration, credential harvesting, or external network activity.

lib/watchGuard.js:18

Files reviewed

FileVerdictWhat the reviewer saw
lib/_tsserver.js medium The file is a legitimate TypeScript tsserver component with expected child process spawning for watch guard and typings installer, but no clear malicious patterns were identified.
lib/_typingsInstaller.js medium This is a legitimate TypeScript typings installer file from Microsoft that spawns npm commands to install type definitions, with no evidence of malicious patterns like data exfiltration, credential harvesting, or obfuscated code.
lib/tsc.js safe The code is a benign shim that enables Node.js compile cache before loading the real module, with no malicious patterns detected.
lib/tsserver.js safe No malicious patterns detected
lib/tsserverlibrary.js safe Cleared by Jev triage; no further analysis needed
lib/typingsInstaller.js safe The shim only enables Node's built-in compile cache and loads the locally scoped implementation file, with no malicious patterns detected.
lib/watchGuard.js safe This appears to be a legitimate TypeScript compiler helper (watchGuard.js) that tests recursive fs.watch support and contains no malicious patterns.

Affected version ranges

None of the 3 scanned versions of typescript are flagged high or critical. The latest scanned version, 7.0.2, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

5.5.47.0.2
VersionsVerdictCountRangeTop findings
6.0.3 – 7.0.2 Needs review 2 >=6.0.3 <=7.0.2 Process Spawning and Shell Command Execution; Process Spawning
6.0.2 Not scanned 1 6.0.2
5.9.3 Needs review 1 5.9.3 Process spawning; File system access
5.5.4 – 5.9.2 Not scanned 7 >=5.5.4 <=5.9.2

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of typescript

VersionVerdictFilesScanned
7.0.2 Needs review 111 Oct 4, 2026
6.0.3 Needs review 7 Oct 6, 2026
5.9.3 Needs review 7 Oct 4, 2026

Frequently asked questions

Is typescript safe to use?

No confirmed malware was found in typescript@6.0.3, but the review flagged 1 medium, 6 low severity findings for risky patterns worth checking before you rely on it.

Does typescript contain malware?

No malware was identified in typescript@6.0.3 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was typescript checked?

Togoder Security downloaded the published npm package and had an AI model read its 7 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan typescript together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in typescript@6.0.3, cost nothing.

Related security reports