# typescript@6.0.3 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:24:45.000Z
- Files reviewed: 7
- Findings: 1 medium, 6 low severity findings
- Report: https://security.togoder.click/npm/typescript@6.0.3
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package typescript@6.0.3 on Oct 6, 2026. An AI review of 7 source files produced 1 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Process Spawning and Shell Command Execution

Finding ID: `NPS-0A770B22ECBB`

File: `lib/_typingsInstaller.js:152`

The code uses child_process.execSync to execute npm install commands. While this appears to be legitimate TypeScript typings installer functionality, executing shell commands based on npm package names and paths could potentially be exploited if inputs are not properly sanitized.

### [low] Dynamic code execution via global object

Finding ID: `NPS-BF3542914DCA`

File: `lib/_tsserver.js`

The code checks for global.gc and calls it via global.gc call. This is a standard Node.js feature (--expose-gc) and not inherently malicious, but it references global object properties.

### [low] File system manipulation outside package scope

Finding ID: `NPS-34BD5A55B15C`

File: `lib/_tsserver.js`

The code logs to files and can read/create directories in user home/cache locations (e.g., LOCALAPPDATA, XDG_CACHE_HOME). This is expected TypeScript tsserver behavior for logging and caching typing information.

### [low] Spawning processes or shell commands

Finding ID: `NPS-35C04EEAFE8C`

File: `lib/_tsserver.js:133`

The code uses child_process.fork to spawn a typings installer process (typingsInstaller.js). This is a standard TypeScript feature for downloading type definitions, but it involves executing a child process.

### [low] Spawning processes or shell commands

Finding ID: `NPS-2702692DF766`

File: `lib/_tsserver.js:278`

The code uses child_process.execFileSync to launch an external script (watchGuard.js) via the Node.js executable. This is a legitimate TypeScript tsserver feature for Windows directory watching, but process spawning capabilities require scrutiny.

### [low] Array Indexing Error

Finding ID: `NPS-68447948CA4D`

File: `lib/_typingsInstaller.js:159`

On line 159 within the indent function, there's a bug where str.replace(/?
/, ...) lacks the global flag 'g', so it only replaces the first newline occurrence instead of all occurrences. This is a code quality issue rather than a security vulnerability.

### [low] File system access

Finding ID: `NPS-41E90572B1A2`

File: `lib/watchGuard.js:18`

The script uses fs.watch with recursive option on a directory provided via process.argv[2]. This is a legitimate pattern used by TypeScript's watchGuard to test whether recursive file watching is supported. It closes the watcher immediately and exits, with no data exfiltration, credential harvesting, or external network activity.

## Files reviewed

- `lib/_tsserver.js` (medium): The file is a legitimate TypeScript tsserver component with expected child process spawning for watch guard and typings installer, but no clear malicious patterns were identified.
- `lib/_typingsInstaller.js` (medium): This is a legitimate TypeScript typings installer file from Microsoft that spawns npm commands to install type definitions, with no evidence of malicious patterns like data exfiltration, credential harvesting, or obfuscated code.
- `lib/tsc.js` (safe): The code is a benign shim that enables Node.js compile cache before loading the real module, with no malicious patterns detected.
- `lib/tsserver.js` (safe): No malicious patterns detected
- `lib/tsserverlibrary.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/typingsInstaller.js` (safe): The shim only enables Node's built-in compile cache and loads the locally scoped implementation file, with no malicious patterns detected.
- `lib/watchGuard.js` (safe): This appears to be a legitimate TypeScript compiler helper (watchGuard.js) that tests recursive fs.watch support and contains no malicious patterns.

## Version ranges

None of the 3 scanned versions of typescript are flagged high or critical. The latest scanned version, 7.0.2, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 6.0.3 – 7.0.2 (`>=6.0.3 <=7.0.2`): medium (Process Spawning and Shell Command Execution +4 more)
- 6.0.2 (`6.0.2`): not scanned
- 5.9.3 (`5.9.3`): medium (Process spawning +3 more)
- 5.5.4 – 5.9.2 (`>=5.5.4 <=5.9.2`): not scanned

## Scanned versions

- [7.0.2](https://security.togoder.click/npm/typescript@7.0.2): medium, 2026-10-04T15:35:20.000Z
- [6.0.3](https://security.togoder.click/npm/typescript@6.0.3): medium, 2026-10-06T14:24:45.000Z
- [5.9.3](https://security.togoder.click/npm/typescript@5.9.3): medium, 2026-10-04T16:41:46.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
