Togoder security

npm package security report

uglify-js npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 3.19.3 Files reviewed 13 Size 998.7 KB Scanned

Summary

Togoder Security scanned the npm package uglify-js@3.19.3 on Oct 6, 2026. An AI review of 13 source files produced 3 medium, 7 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
3
medium
7
low

Findings 10

medium

dynamic code execution

NPS-7420FDA76866

The DEFNODE function uses new Function(code.join(""))() to construct AST node constructors from dynamically generated strings. While the generated code is built from internal, developer-controlled strings, this pattern is functionally equivalent to eval and could be abused if the type, props, or methods arguments were ever influenced by untrusted input.

lib/ast.js:77
medium

Dynamic code execution

NPS-C40BD02D9BC6

Uses new Function() with dynamically concatenated source from local files (lib/*.js). While these are trusted local files, the pattern is a dynamic code execution vector and would become dangerous if the files were tampered with or if input were included.

tools/node.js:17
medium

Monkey-patching process.exit

NPS-E83D181836F9

The code overrides the global process.exit function in a catch block. This modifies core Node.js runtime behavior, which can mask errors, alter application control flow, and potentially interfere with security tooling or sandboxing that relies on standard process termination semantics.

tools/tty.js:11
low

Dynamic code execution

NPS-D67DCDBEAF40

The map() function uses new Function() to dynamically generate AST conversion functions from property map strings. While the generated code is derived from internal hardcoded strings and not external input, the use of new Function() is a dynamic code execution pattern that could be exploited if the propmap strings were ever influenced by untrusted input.

lib/mozilla-ast.js
low

Prototype pollution / unsafe property access

NPS-DF2FCBDB430C

VariableDeclaration uses a computed object lookup {const: AST_Const, let: AST_Let}[M.kind] where M.kind comes from the Mozilla AST input. If M.kind were 'constructor' or '__proto__', this could resolve to Object.prototype properties rather than the intended constructor, potentially leading to unexpected behavior.

lib/mozilla-ast.js
low

Top-level side effects on import

NPS-3FCBB4157128

Executes code at module load time (the new Function(...)(...)). This is expected for a build tool but still represents import-time execution behavior that should be reviewed in third-party packages.

tools/node.js:17
low

File system read

NPS-B5CC464F2BB1

Reads multiple files via fs.readFileSync using require.resolve paths limited to the package's own lib directory. Scope is confined to the package, so risk is low.

tools/node.js:19
low

Environment variable read

NPS-8DEC078609B4

Reads process.env['UGLIFY_BUG_REPORT'] and conditionally overrides exports.minify to produce debug output containing source code and options. Not credential harvesting, but reads environment variables at import time.

tools/node.js:30
low

Access to internal Node.js stream handles

NPS-EED82AF87C18

Directly accesses private/internal properties process.stdout._handle and process.stderr._handle and calls setBlocking(true). Reliance on undocumented internals is fragile and could be leveraged to alter I/O behavior in unexpected ways.

tools/tty.js:4
low

Uncaught exception handler manipulation

NPS-A16B445A0EB7

Registers a process.once('uncaughtException') handler and then throws the original exit function. This suppresses normal exception propagation and delays process termination based on internal stream buffer state, which could be abused to hide crashes or prolong execution unexpectedly.

tools/tty.js:13

Files reviewed

FileVerdictWhat the reviewer saw
lib/ast.js medium The file is the legitimate UglifyJS AST definition module; it contains one dynamic code generation pattern via new Function, but no data exfiltration, credential harvesting, obfuscated payloads, network calls, or filesystem manipulation were detected.
lib/mozilla-ast.js medium UglifyJS's mozilla-ast.js uses new Function() for internal code generation and performs some unguarded property lookups, but contains no data exfiltration, credential harvesting, network activity, or backdoor patterns.
tools/node.js medium This appears to be the legitimate UglifyJS build/tools script; it uses new Function and reads env vars but shows no clear malicious behavior like exfiltration, credential theft, or process spawning.
tools/tty.js medium The file is not overtly malicious but uses fragile internal APIs and monkey-patches process.exit with an uncaughtException handler, which is a suspicious pattern that could be used to manipulate runtime behavior and should be reviewed further.
lib/minify.js safe No malicious patterns detected; the code is a standard JavaScript minification library with source map handling and option normalization.
lib/output.js safe No malicious patterns detected; the file is the standard output module of the UglifyJS library containing only code generation and formatting logic.
lib/parse.js safe UglifyJS's lib/parse.js contains only standard JavaScript tokenizer/parser logic with no malicious patterns detected.
lib/propmangle.js safe No malicious patterns detected; this is the standard UglifyJS property mangling module from the official repository.
lib/scope.js safe No malicious patterns detected; the code is a legitimate scope analysis module from UglifyJS with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior.
lib/sourcemap.js safe Cleared by Jev triage; no further analysis needed
lib/transform.js safe No malicious patterns detected; the file contains legitimate AST transformation logic from UglifyJS.
lib/utils.js safe Cleared by Jev triage; no further analysis needed
tools/exports.js safe Cleared by Jev triage; no further analysis needed

Scanned versions of uglify-js

VersionVerdictFilesScanned
3.19.3 Needs review 13 Oct 6, 2026

Frequently asked questions

Is uglify-js safe to use?

No confirmed malware was found in uglify-js@3.19.3, but the review flagged 3 medium, 7 low severity findings for risky patterns worth checking before you rely on it.

Does uglify-js contain malware?

No malware was identified in uglify-js@3.19.3 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was uglify-js checked?

Togoder Security downloaded the published npm package and had an AI model read its 13 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan uglify-js together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in uglify-js@3.19.3, cost nothing.

Related security reports