Summary
Togoder Security scanned the npm package undici@6.28.0 on Oct 6, 2026. An AI review of 99 source files produced 3 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 11
Potential denial of service
NPS-93936706AB99
The multipart parser does not limit resource consumption in several loops and buffer operations. For example, collectASequenceOfBytes scans from a given position to the end of input without a maximum length, and input.indexOf() could scan large portions of input. An attacker providing a very large multipart/form-data body could cause excessive CPU or memory usage. However, this is a general parser robustness concern, not a malicious pattern.
Weak Cryptographic Fallback
NPS-6E15FB61EAA1
The code attempts to require 'node:crypto' and falls back to a non-cryptographic PRNG using Math.random() if the module is unavailable. Math.random() is not cryptographically secure and would produce predictable WebSocket masking keys, which could weaken WebSocket protocol security (masking keys must be unpredictable per RFC 6455). While this is a graceful degradation fallback rather than intentional malice, it introduces a security weakness in environments without crypto.
File system manipulation
NPS-0836E37DC521
The script reads a file from a relative path './undici-fetch.js' and then overwrites the same file with transformed content. While this is likely intended to fix encoding issues, it modifies files outside the typical package scope and could corrupt or alter the target file if run unintentionally.
Debug logging of sensitive connection details
NPS-1FBCF89B50CA
The code subscribes to diagnostics channels and logs detailed connection information (host, port, protocol) at debug level. While gated behind NODE_DEBUG environment variables, this could expose sensitive network topology or internal hostnames if debug logging is enabled in production or misconfigured. This is a potential information disclosure risk, though it is standard practice for debug logging in libraries like undici.
Unvalidated regex matching (ReDoS)
NPS-8A4C9CF50908
matchValue uses user-provided RegExp.test without input bounds. If a malicious or user-provided regex with catastrophic backtracking is used, it could cause denial of service when matching paths or headers. This is a standard library capability but worth noting.
Dynamic code execution via function callbacks
NPS-9E7C5BA4B930
The mockDispatch function invokes user-supplied callbacks via mockDispatch.data.callback(opts) and _data({...}), and matchValue executes match as a function. In a testing/mocking library this is expected behavior, but it allows arbitrary code execution if malicious callbacks are injected into the mock dispatch configuration.
Network fallback bypass of mock isolation
NPS-94EC76282F49
buildMockDispatch's checkNetConnect function can call originalDispatch, forwarding requests to the real network when the mock does not match. This behavior could bypass test isolation and potentially leak request data if misconfigured by a malicious agent configuration.
Assertion via node:assert
NPS-EAF33BE6F0A7
The code uses assert from 'node:assert' for internal invariant checks. While not a direct security flaw in this context, using assertions in production code can lead to abrupt process termination if the invariants are violated (e.g., due to malformed input). This is not malicious, but could be a robustness issue.
Unbounded file Content-Type and filename
NPS-72DECFBB24E6
The parser extracts contentType and filename without explicit length limits, which could allow memory exhaustion or unexpected behavior when creating File objects. Again, this is a robustness issue, not a security exploit pattern.
Crypto Dependency Resolution
NPS-CDE428E2875F
The module imports 'node:crypto' via a conditional require. In normal Node.js runtime 'node:crypto' is always available, so the fallback path is effectively dead code. However, if the package is bundled or executed in a modified environment (e.g., a polyfilled or stubbed crypto module), an attacker could substitute a malicious crypto implementation. There is no integrity check on the resolved module.
Encoding manipulation
NPS-46F4BD26B24D
The script uses Buffer transcode to convert the file from utf8 to latin1 and then writes it back. This could be a benign fix for encoding problems, but it alters the file's content in a way that might hide malicious modifications or introduce subtle changes.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/core/diagnostics.js | medium | The file contains debug logging of network connection details, which is a minor information disclosure risk, but no malicious patterns such as data exfiltration, credential harvesting, or code execution were detected. |
| lib/mock/mock-utils.js | medium | The code implements a mocking utility for undici with expected dynamic callback/function invocation patterns, but no clear malicious exfiltration, credential harvesting, obfuscation, or process spawning was found; only low-severity concerns around callback execution and regex matching. |
| lib/web/websocket/frame.js | medium | This WebSocket frame builder is a legitimate implementation derived from the 'ws' library with no clear malicious intent, but it includes a cryptographically weak Math.random() fallback for mask generation that could reduce security in unusual environments. |
| scripts/strip-comments.js | medium | The script performs a potentially unsafe in-place file transformation on a relative path, which could be used to alter package files, though no direct exfiltration or code execution is present. |
| index-fetch.js | safe | No malicious patterns detected; this is a standard entry point for the undici HTTP client library that exports fetch, WebSocket, EventSource, and dispatcher APIs. |
| index.js | safe | No malicious patterns detected; the file is a standard entry point for the undici HTTP client library. |
| lib/api/abort-signal.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/api/api-connect.js | safe | No malicious patterns detected; this is legitimate Undici HTTP CONNECT handler code with no data exfiltration, credential harvesting, obfuscation, or suspicious system/network activity. |
| lib/api/api-pipeline.js | safe | No malicious patterns detected; the code is a legitimate Undici HTTP pipeline implementation with no data exfiltration, credential harvesting, obfuscation, or other red flags. |
| lib/api/api-request.js | safe | No malicious patterns detected; the code is a legitimate HTTP request handler from the undici library with no data exfiltration, credential harvesting, dynamic code execution, or suspicious behavior. |
| lib/api/api-stream.js | safe | No malicious patterns detected; the code is a legitimate HTTP streaming API handler with standard error handling and no data exfiltration, credential harvesting, obfuscation, or process spawning. |
| lib/api/api-upgrade.js | safe | No malicious patterns detected |
| lib/api/index.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/api/readable.js | safe | No malicious patterns detected in this file; it is a legitimate port of Node.js undici's readable body implementation. |
| lib/api/util.js | safe | No malicious patterns detected |
| lib/core/connect.js | safe | No malicious patterns detected; the code implements a standard TCP/TLS connector with session caching and timeout handling. |
| lib/core/constants.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/core/errors.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/core/request.js | safe | No malicious patterns detected; the code is a legitimate HTTP request implementation with proper input validation and error handling. |
| lib/core/symbols.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/core/tree.js | safe | This is a benign ternary search tree implementation for HTTP header lookups with no malicious patterns. |
| lib/core/util.js | safe | No malicious patterns detected; the code is a standard HTTP client utility module (undici) handling URL parsing, headers, and body streams without exfiltration, credential harvesting, or code execution. |
| lib/dispatcher/agent.js | safe | No malicious patterns detected; the file is a standard HTTP dispatcher agent implementation with expected validation, client pooling, and lifecycle management. |
| lib/dispatcher/balanced-pool.js | safe | No malicious patterns detected |
| lib/dispatcher/client-h1.js | safe | This is the legitimate undici HTTP/1.1 client dispatcher with no malicious patterns; WebAssembly is used only for the llhttp parser, and no data exfiltration, credential harvesting, obfuscation, or process spawning is present. |
Show 74 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/dispatcher/client-h2.js | safe | No malicious patterns detected; the code is a legitimate HTTP/2 client dispatcher implementation from the Undici library. |
| lib/dispatcher/client.js | safe | This is a standard HTTP client dispatcher implementation from the undici package with no malicious patterns, no obfuscation, no external data exfiltration, no credential harvesting, and no unexpected code execution. |
| lib/dispatcher/dispatcher-base.js | safe | No malicious patterns detected |
| lib/dispatcher/dispatcher.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/dispatcher/env-http-proxy-agent.js | safe | No malicious patterns detected; the code is a legitimate proxy agent implementation that reads standard proxy environment variables. |
| lib/dispatcher/fixed-queue.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/dispatcher/pool-base.js | safe | No malicious patterns detected; the code implements a connection pool dispatcher with standard event handling and queue management, containing no data exfiltration, credential harvesting, obfuscation, or suspicious system/network operations. |
| lib/dispatcher/pool-stats.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/dispatcher/pool.js | safe | No malicious patterns detected; the code is a standard connection pool dispatcher with no exfiltration, credential harvesting, obfuscation, or process execution. |
| lib/dispatcher/proxy-agent.js | safe | No malicious patterns detected; the file implements a legitimate HTTP/HTTPS proxy agent for the undici library with proper credential handling, no dynamic code execution, no exfiltration, and no suspicious lifecycle or filesystem behavior. |
| lib/dispatcher/retry-agent.js | safe | No malicious patterns detected; the code implements a standard retry dispatcher for HTTP requests without suspicious behavior. |
| lib/global.js | safe | No malicious patterns detected; the code is a standard global dispatcher implementation for the undici HTTP client library with no exfiltration, obfuscation, or other red flags. |
| lib/handler/decorator-handler.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/handler/redirect-handler.js | safe | No malicious patterns detected; the code implements HTTP redirect handling with proper validation and no exfiltration, credential harvesting, or dynamic code execution. |
| lib/handler/retry-handler.js | safe | No malicious patterns detected; the code is a legitimate HTTP retry handler with standard retry, range, and ETag logic and performs no suspicious network, filesystem, process, or credential operations. |
| lib/interceptor/dns.js | safe | No malicious patterns detected; the code implements a DNS caching and load-balancing interceptor without any suspicious behavior. |
| lib/interceptor/dump.js | safe | No malicious patterns detected; the code implements a benign dump-size-limiting HTTP interceptor with no external calls, credential access, or dynamic execution. |
| lib/interceptor/redirect-interceptor.js | safe | No malicious patterns detected; the code is a standard HTTP redirect interceptor with no exfiltration, code execution, or credential access. |
| lib/interceptor/redirect.js | safe | No malicious patterns detected; the code is a standard HTTP redirect interceptor with no suspicious behavior. |
| lib/interceptor/response-error.js | safe | No malicious patterns detected |
| lib/interceptor/retry.js | safe | No malicious patterns detected |
| lib/llhttp/constants.js | safe | No malicious patterns detected |
| lib/llhttp/llhttp-wasm.js | safe | The file is a legitimate wasm binary for the llhttp HTTP parser (the same module used by Node.js core), containing only the compiled WebAssembly code with no executable JavaScript malicious patterns at import time. |
| lib/llhttp/llhttp_simd-wasm.js | safe | This file is a base64-encoded WebAssembly binary for the llhttp HTTP parser (a legitimate dependency of Node.js core), with no malicious patterns such as network exfiltration, credential harvesting, obfuscated code execution, or process spawning. |
| lib/llhttp/utils.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/mock/mock-agent.js | safe | No malicious patterns detected; this is a standard mock agent implementation for the undici HTTP client library with no data exfiltration, credential harvesting, or dynamic code execution. |
| lib/mock/mock-client.js | safe | No malicious patterns detected in the mock client implementation. |
| lib/mock/mock-errors.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/mock/mock-interceptor.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/mock/mock-pool.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/mock/mock-symbols.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/mock/pending-interceptors-formatter.js | safe | No malicious patterns detected; the code is a benign utility for formatting pending interceptor data using Node.js streams and console. |
| lib/mock/pluralizer.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/util/timers.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/web/cache/cache.js | safe | No malicious patterns detected |
| lib/web/cache/cachestorage.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/web/cache/symbols.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/web/cache/util.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/web/cookies/constants.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/web/cookies/index.js | safe | No malicious patterns detected; the code implements standard cookie parsing and serialization using webidl validation without any exfiltration, dynamic execution, or filesystem/process manipulation. |
| lib/web/cookies/parse.js | safe | No malicious patterns detected |
| lib/web/cookies/util.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/web/eventsource/eventsource-stream.js | safe | No malicious patterns detected; the file is a legitimate EventSource stream parser from undici with no network, filesystem, or code execution concerns. |
| lib/web/eventsource/eventsource.js | safe | The code is a standard implementation of the EventSource API (Server-Sent Events) for the undici HTTP client library, with no malicious patterns detected. |
| lib/web/eventsource/util.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/web/fetch/body.js | safe | No malicious patterns detected; the code implements standard WHATWG Fetch body handling logic. |
| lib/web/fetch/constants.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/web/fetch/data-url.js | safe | No malicious patterns detected |
| lib/web/fetch/dispatcher-weakref.js | safe | No malicious patterns detected; the code is a legitimate compatibility workaround for WeakRef and FinalizationRegistry in Node.js v18. |
| lib/web/fetch/file.js | safe | No malicious patterns detected; the code is a legitimate implementation of a File-like polyfill with no suspicious behavior. |
| lib/web/fetch/formdata-parser.js | safe | No malicious patterns detected; the file is a standard multipart/form-data parser with some potential denial-of-service robustness concerns but no data exfiltration, code execution, credential harvesting, or backdoor behavior. |
| lib/web/fetch/formdata.js | safe | No malicious patterns detected; the file is a standard FormData implementation with only legitimate Web IDL converters and File/Blob handling. |
| lib/web/fetch/global.js | safe | No malicious patterns detected; the code simply manages a global origin URL symbol with proper validation. |
| lib/web/fetch/headers.js | safe | No malicious patterns detected; the code is a legitimate implementation of the WHATWG Fetch Headers API from undici-fetch. |
| lib/web/fetch/index.js | safe | No malicious patterns detected |
| lib/web/fetch/request.js | safe | No malicious patterns detected; this is a standard WHATWG Fetch Request implementation from undici with no exfiltration, obfuscation, process spawning, or install-time code. |
| lib/web/fetch/response.js | safe | No malicious patterns detected |
| lib/web/fetch/symbols.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/web/fetch/util.js | safe | No malicious patterns detected; the file implements standard WHATWG Fetch API utilities without suspicious network, filesystem, process, or dynamic execution behavior. |
| lib/web/fetch/webidl.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/web/fileapi/encoding.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/web/fileapi/filereader.js | safe | No malicious patterns detected; the code is a standard FileReader implementation with WebIDL validation and event handling, with no network, filesystem, process, or dynamic execution concerns. |
| lib/web/fileapi/progressevent.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/web/fileapi/symbols.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/web/fileapi/util.js | safe | No malicious patterns detected; the file implements standard FileReader/Blob reading operations without exfiltration, credential harvesting, dynamic code execution, or other red flags. |
| lib/web/websocket/connection.js | safe | No malicious patterns detected |
| lib/web/websocket/constants.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/web/websocket/events.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/web/websocket/permessage-deflate.js | safe | No malicious patterns detected; the code implements standard per-message deflate decompression for WebSocket with payload size limits and no external calls, obfuscation, or process execution. |
| lib/web/websocket/receiver.js | safe | No malicious patterns detected; this is a legitimate WebSocket frame parser implementation. |
| lib/web/websocket/sender.js | safe | This is a legitimate WebSocket send queue implementation with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution. |
| lib/web/websocket/symbols.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/web/websocket/util.js | safe | No malicious patterns detected; the code implements standard WebSocket protocol utilities without any data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior. |
| lib/web/websocket/websocket.js | safe | No malicious patterns detected in the WebSocket implementation; it follows the WHATWG WebSocket specification with standard imports and no suspicious behavior. |
Affected version ranges
None of the 4 scanned versions of undici are flagged high or critical. The latest scanned version, 8.11.2, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 8.11.2 | Needs review | 1 | 8.11.2 | Potential path traversal / unsafe filename handling |
| 7.30.0 | Not scanned | 1 | 7.30.0 | |
| 7.29.0 | Needs review | 1 | 7.29.0 | Potential path traversal / unsafe filename handling; Obfuscated code / encoded payload |
| 7.18.2 | Not scanned | 1 | 7.18.2 | |
| 6.27.0 โ 6.28.0 | Needs review | 2 | >=6.27.0 <=6.28.0 | Potential denial of service; Weak Cryptographic Fallback |
| 6.21.3 | Not scanned | 1 | 6.21.3 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of undici
Frequently asked questions
Is undici safe to use?
No confirmed malware was found in undici@6.28.0, but the review flagged 3 medium, 8 low severity findings for risky patterns worth checking before you rely on it.
Does undici contain malware?
No malware was identified in undici@6.28.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was undici checked?
Togoder Security downloaded the published npm package and had an AI model read its 99 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan undici together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in undici@6.28.0, cost nothing.