Togoder security

npm package security report

undici@7.29.0 security report

Risky patterns found that deserve a look.

Needs review Version 7.29.0 Files reviewed 114 Size 1.2 MB Scanned

Summary

Togoder Security scanned the npm package undici@7.29.0 on Oct 6, 2026. An AI review of 114 source files produced 3 medium, 19 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
3
medium
19
low

Findings 22

medium

Obfuscated code / encoded payload

NPS-6A12F7BF1AF0

The file embeds a large base64-encoded WebAssembly binary ('wasmBase64') that is decoded and exported via a getter on module.exports. This is a common pattern for shipping binary payloads without source review, and the embedded WASM is not human-readable in this context. While this is expected for llhttp (a legitimate HTTP parser used by Node.js), the pattern matches obfuscation heuristics and warrants manual WASM disassembly/verification to confirm it only implements the documented llhttp parser.

lib/llhttp/llhttp_simd-wasm.js:4
medium

Potential path traversal / unsafe filename handling

NPS-A0549B5C7452

The parser extracts filename values from Content-Disposition headers, including extended RFC 5987 values via decodeURIComponent, and passes them directly into File objects (new File([body], filename, ...)) and form entries. Downstream consumers writing these files to disk without sanitization could be vulnerable to path traversal (e.g., '../../etc/passwd'), though this file itself does not perform file writes.

lib/web/fetch/formdata-parser.js:268
medium

Weak cryptographic fallback

NPS-8E2DF35F2006

When the 'crypto' runtime feature is unavailable, the code falls back to using Math.random() for generating WebSocket mask keys. Math.random() is not cryptographically secure and could allow prediction of mask keys, potentially weakening WebSocket protocol security. While this is explicitly noted as 'not full compatibility, but minimum', it represents a security degradation compared to the cryptographic implementation.

lib/web/websocket/frame.js:12
low

Module structure / proxy agent support

NPS-8C699AA39159

The package exports several proxy-related dispatchers (ProxyAgent, Socks5ProxyAgent, EnvHttpProxyAgent) and proxy interceptors. While proxies are legitimate networking features, the presence of these modules means consumers can route traffic through third-party servers. No hardcoded external endpoints, credentials, or exfiltration logic are present in this entry file.

index.js:8
low

Stack trace manipulation

NPS-FCA33715C95D

appendFetchStackTrace() rewrites the stack property of errors to append additional frames. This is used for debugging purposes and does not execute code or hide malicious activity, but it does modify error objects.

index.js:157
low

Global namespace pollution

NPS-FC291E3FD03A

The install() function assigns fetch, Headers, Response, Request, FormData, WebSocket, and related classes to globalThis. This is an opt-in function exported by the module and is not invoked automatically at import time, so it is not a malicious pattern by itself, but users should be aware it modifies the global environment when called.

index.js:228
low

filesystem access

NPS-574152808172

The constructor accepts an optional 'location' option passed to new DatabaseSync(), which could open a user-supplied SQLite file. However this is an expected, documented cache-store configuration and is not used to access sensitive paths.

lib/cache/sqlite-cache-store.js:97
low

experimental warning

NPS-EB95C384A82B

Emits an ExperimentalWarning once per process. Benign informational behavior.

lib/dispatcher/socks5-proxy-agent.js:33
low

credential handling

NPS-F41F5D34189C

Proxy authentication credentials are extracted from the proxy URL or options and passed to Socks5Client. This is expected and necessary for SOCKS5 proxy authentication, not credential harvesting.

lib/dispatcher/socks5-proxy-agent.js:63
low

conditional module loading

NPS-45B803BBCE46

Uses require('node:tls') lazily inside a function for HTTPS upgrades. This is a standard optimization pattern, not dynamic code execution from external input.

lib/dispatcher/socks5-proxy-agent.js:178
low

Host header manipulation

NPS-2993FAE2C0D2

The code modifies the Host header when dispatching requests to resolved IP addresses. This is standard behavior for DNS-based connection interceptor to preserve the original hostname for virtual hosting. It does not send data to attacker-controlled servers.

lib/interceptor/dns.js:25
low

DNS lookup behavior

NPS-0637FA324412

This module performs DNS lookups using node:dns lookup() to resolve hostnames to IP addresses. This is a normal, expected part of a DNS interceptor in an HTTP client library (like undici). It does not exfiltrate data to external servers; it only resolves the origin hostname provided by the caller.

lib/interceptor/dns.js:235
low

Error handling

NPS-F96DB04153A6

On ENOTFOUND errors, the code deletes cached records. On ETIMEDOUT/ECONNREFUSED with dualStack, it attempts the other IP family. These are normal retry/failover mechanisms.

lib/interceptor/dns.js:390
low

Top-level code executing on import

NPS-5D11A1DA8859

The Object.defineProperty(module, 'exports', { get: () => ... }) block executes at module load time and lazily decodes/allocates the WASM buffer on first access. This is lazy initialization rather than side-effectful execution (no network, filesystem, or process calls), but it is still top-level behavior on import.

lib/llhttp/llhttp_simd-wasm.js:6
low

File system access

NPS-B9C96F278DFC

The agent reads/writes snapshot files at user-provided paths (via SnapshotRecorder). This is expected functionality for a record/replay testing tool, and paths are validated/constrained by user configuration.

lib/mock/snapshot-agent.js
low

Network requests

NPS-FFCB4FA0A4E3

The agent dispatches real HTTP requests via an Agent instance in record/update mode. This is core, intended behavior for a snapshot recorder that captures live HTTP responses.

lib/mock/snapshot-agent.js
low

Unbounded resource consumption / DoS potential

NPS-B23CF90B0AFC

The multipart parser uses input.indexOf to scan for boundaries and processes arbitrarily large bodies without size limits or iteration caps. A maliciously crafted multipart body could cause excessive memory or CPU usage. This is a robustness concern rather than an intentional backdoor.

lib/web/fetch/formdata-parser.js:120
low

Decoding ambiguity in content-disposition attributes

NPS-2CE9F5B6C8F0

parseContentDispositionAttribute applies decodeURIComponent to extended (RFC 5987) values and performs ad-hoc percent-decoding replacements (%0A, %0D, %22) on quoted strings. Malformed percent sequences could throw, and the transformation is non-standard, but this is a correctness/robustness issue rather than an exploit vector in this module.

lib/web/fetch/formdata-parser.js:260
low

Potential buffer reuse issue

NPS-5D374564DE77

The global buffer used for mask generation is reused across multiple calls without clearing between uses. While the buffer is refilled after exhaustion, this shared state could potentially lead to mask key reuse patterns if not properly managed, though the impact is limited given the buffer size and refill mechanism.

lib/web/websocket/frame.js:6
low

File system manipulation

NPS-4B1646C3655C

The script reads and overwrites './undici-fetch.js' using readFileSync and writeFileSync. While this is likely a build-time script for encoding conversion (UTF-8 to Latin-1), it modifies a source file in place and could be abused to alter package contents.

scripts/strip-comments.js:5
low

Top-level execution

NPS-75095FB9BF35

The script executes file I/O operations at import time (top-level code), which can have side effects when the module is required.

scripts/strip-comments.js:5
low

Encoding conversion

NPS-B5073923CCF6

The script uses buffer transcode to convert a file from UTF-8 to Latin-1. This is a legitimate but unusual operation that could theoretically be used to obfuscate or alter code content.

scripts/strip-comments.js:6

Files reviewed

FileVerdictWhat the reviewer saw
lib/llhttp/llhttp_simd-wasm.js medium The file embeds a base64-encoded WebAssembly binary (consistent with the legitimate llhttp parser) and lazily exposes it via a module.exports getter; no exfiltration, credential theft, shell execution, or other malicious patterns are present, but the opaque embedded payload warrants verifying the WASM contents.
lib/web/fetch/formdata-parser.js medium No malicious patterns (exfiltration, credential harvesting, obfuscation, process spawning) were found; the file is a standard multipart/form-data parser with minor robustness and downstream filename-safety concerns.
lib/web/websocket/frame.js medium While no obvious malicious patterns are present, the code contains a weak cryptographic fallback using Math.random() for WebSocket mask generation when crypto is unavailable, which could weaken protocol security.
scripts/strip-comments.js medium Script performs in-place encoding conversion on a local file, which is suspicious but likely benign build tooling; no exfiltration, credential harvesting, or code execution detected.
index-fetch.js safe This file is a standard entry point that re-exports undici's fetch/WebSocket/EventSource APIs and only augments stack traces on fetch errors, with no suspicious behavior.
index.js safe The file is a standard entry point for the undici HTTP client library; no malicious patterns, exfiltration, credential harvesting, obfuscated code, dynamic execution, or install-time side effects were detected.
lib/api/abort-signal.js safe Cleared by Jev triage; no further analysis needed
lib/api/api-connect.js safe No malicious patterns detected; the file is a legitimate HTTP CONNECT handler implementation for the undici library with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior.
lib/api/api-pipeline.js safe No malicious patterns detected
lib/api/api-request.js safe No malicious patterns detected; the code is a standard HTTP request handler implementation with no exfiltration, credential harvesting, obfuscation, or backdoor behavior.
lib/api/api-stream.js safe No malicious patterns detected; this file is a standard stream handler implementation for the undici HTTP client library with no exfiltration, process spawning, dynamic code execution, or credential access.
lib/api/api-upgrade.js safe No malicious patterns detected; this is legitimate undici HTTP upgrade handling code with no security red flags.
lib/api/index.js safe Cleared by Jev triage; no further analysis needed
lib/api/readable.js safe No malicious patterns detected; this is a legitimate undici HTTP body stream implementation with no exfiltration, credential harvesting, code execution, or other red flags.
lib/cache/memory-cache-store.js safe No malicious patterns detected; the code implements an in-memory cache store with no network, filesystem, process, or dynamic code execution behavior.
lib/cache/sqlite-cache-store.js safe This file implements a normal SQLite-backed cache store using parameterized queries and node:sqlite; no exfiltration, credential harvesting, obfuscation, process spawning, or other malicious patterns were found.
lib/core/connect.js safe The code is a standard TCP/TLS connection connector with session caching and no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or unauthorized process execution.
lib/core/constants.js safe This file defines a static list of well-known HTTP header names and helper utilities with no malicious behavior, network activity, filesystem access, or dynamic code execution.
lib/core/diagnostics.js safe No malicious patterns detected
lib/core/errors.js safe Cleared by Jev triage; no further analysis needed
lib/core/request.js safe This is a legitimate HTTP request construction module from the undici library with input validation and no malicious patterns.
lib/core/socks5-client.js safe This is a straightforward SOCKS5 client implementation with no malicious patterns, no external calls beyond the provided socket, and no credential harvesting or code execution concerns.
lib/core/socks5-utils.js safe No malicious patterns detected
lib/core/symbols.js safe Cleared by Jev triage; no further analysis needed
lib/core/tree.js safe No malicious patterns detected; the code implements a ternary search tree for header name lookups with no network, filesystem, process, or dynamic code execution behavior.
Show 89 more files
FileVerdictWhat the reviewer saw
lib/core/util.js safe No malicious patterns detected in this utility module, which contains standard HTTP client helper functions with no network exfiltration, credential harvesting, dynamic code execution, or install-time hooks.
lib/dispatcher/agent.js safe The code is a legitimate HTTP agent dispatcher implementation with no malicious patterns, data exfiltration, credential harvesting, or dynamic code execution.
lib/dispatcher/balanced-pool.js safe No malicious patterns detected; the file implements a legitimate load-balancing dispatcher for upstream HTTP pools without any exfiltration, credential harvesting, obfuscation, or unauthorized code execution.
lib/dispatcher/client-h1.js safe No malicious patterns detected; this is a legitimate HTTP/1.1 parser/dispatcher from undici with no exfiltration, credential harvesting, obfuscation, or backdoor behavior.
lib/dispatcher/client-h2.js safe This HTTP/2 client dispatcher implementation from undici contains no malicious patterns, data exfiltration, credential harvesting, or backdoor code.
lib/dispatcher/client.js safe No malicious patterns detected; this is the standard undici HTTP client dispatcher implementation.
lib/dispatcher/dispatcher-base.js safe No malicious patterns detected
lib/dispatcher/dispatcher.js safe No malicious patterns detected
lib/dispatcher/env-http-proxy-agent.js safe No malicious patterns detected; the code is a standard HTTP proxy agent dispatcher that reads environment variables for proxy configuration as intended.
lib/dispatcher/fixed-queue.js safe Cleared by Jev triage; no further analysis needed
lib/dispatcher/h2c-client.js safe No malicious patterns detected; the code is a straightforward HTTP/2 cleartext client configuration class with only local validation and no suspicious behaviors.
lib/dispatcher/pool-base.js safe No malicious patterns detected; the code is a legitimate connection pool dispatcher implementation without exfiltration, credential harvesting, obfuscation, or process execution.
lib/dispatcher/pool.js safe No malicious patterns detected; the code is a standard connection pool implementation for the undici HTTP client library with no exfiltration, credential harvesting, obfuscation, or process spawning.
lib/dispatcher/proxy-agent.js safe No malicious patterns detected
lib/dispatcher/retry-agent.js safe No malicious patterns detected; the code implements a standard retry dispatcher for HTTP requests without suspicious behavior.
lib/dispatcher/round-robin-pool.js safe No malicious patterns detected
lib/dispatcher/socks5-proxy-agent.js safe The code is a legitimate SOCKS5 proxy agent implementation with no malicious patterns such as exfiltration, credential harvesting, obfuscation, shell execution, or install-time hooks.
lib/encoding/index.js safe Cleared by Jev triage; no further analysis needed
lib/global.js safe No malicious patterns detected; the file only manages Undici's global dispatcher and exports related functions.
lib/handler/cache-handler.js safe No malicious patterns detected; the file implements HTTP cache handling logic consistent with the undici cache interceptor.
lib/handler/cache-revalidation-handler.js safe No malicious patterns detected; the code is a legitimate HTTP cache revalidation handler with no network, filesystem, credential, or code-execution red flags.
lib/handler/decorator-handler.js safe Cleared by Jev triage; no further analysis needed
lib/handler/deduplication-handler.js safe No malicious patterns detected; the code is a legitimate request deduplication handler with no network, credential, obfuscation, or process execution concerns.
lib/handler/redirect-handler.js safe This is a standard HTTP redirect handler from undici with no malicious patterns, obfuscation, exfiltration, or suspicious behavior detected.
lib/handler/retry-handler.js safe No malicious patterns detected; the code implements HTTP request retry logic with partial content resume handling.
lib/handler/unwrap-handler.js safe No malicious patterns detected; the code is a legitimate handler wrapper for managing request lifecycle events.
lib/handler/wrap-handler.js safe No malicious patterns detected; the file is a legitimate handler wrapper class with no exfiltration, obfuscation, process spawning, or suspicious behavior.
lib/interceptor/cache.js safe No malicious patterns detected; the code implements HTTP cache interceptor logic with no data exfiltration, credential harvesting, obfuscation, dynamic code execution, or suspicious network/file/process operations.
lib/interceptor/decompress.js safe The code implements a legitimate HTTP response decompression interceptor using Node.js zlib with no malicious patterns detected.
lib/interceptor/deduplicate.js safe No malicious patterns detected; the code implements a legitimate HTTP request deduplication interceptor with proper input validation and no external data transmission or dangerous operations.
lib/interceptor/dns.js safe The code is a legitimate DNS interceptor for an HTTP client library; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning were found.
lib/interceptor/dump.js safe No malicious patterns detected
lib/interceptor/redirect.js safe No malicious patterns detected; the code is a standard HTTP redirect interceptor with no exfiltration, obfuscation, or suspicious behavior.
lib/interceptor/response-error.js safe No malicious patterns detected; the code is a legitimate undici response error interceptor that parses HTTP error bodies with no external communication, credential access, or dynamic execution.
lib/interceptor/retry.js safe No malicious patterns detected
lib/llhttp/constants.js safe No malicious patterns detected; the file contains only static HTTP parsing constants and maps with no dynamic execution, network, filesystem, or credential access.
lib/llhttp/llhttp-wasm.js safe The file is a standard llhttp WebAssembly wrapper that decodes an embedded base64 WASM module; no malicious patterns such as exfiltration, credential harvesting, dynamic code execution, or process spawning were detected.
lib/llhttp/utils.js safe Cleared by Jev triage; no further analysis needed
lib/mock/mock-agent.js safe This is a legitimate mock agent implementation for HTTP request interception and testing; no malicious patterns were detected.
lib/mock/mock-call-history.js safe Cleared by Jev triage; no further analysis needed
lib/mock/mock-client.js safe Cleared by Jev triage; no further analysis needed
lib/mock/mock-errors.js safe Cleared by Jev triage; no further analysis needed
lib/mock/mock-interceptor.js safe Cleared by Jev triage; no further analysis needed
lib/mock/mock-pool.js safe Cleared by Jev triage; no further analysis needed
lib/mock/mock-symbols.js safe Cleared by Jev triage; no further analysis needed
lib/mock/mock-utils.js safe No malicious patterns detected
lib/mock/pending-interceptors-formatter.js safe No malicious patterns detected; the code is a benign utility for formatting pending interceptor data using Node.js streams and console.
lib/mock/snapshot-agent.js safe The code is a legitimate snapshot/record-replay HTTP testing agent with no signs of exfiltration, credential harvesting, obfuscation, dynamic code execution, or other malicious patterns.
lib/mock/snapshot-recorder.js safe This is a legitimate HTTP snapshot recorder utility with no malicious patterns such as exfiltration, credential harvesting, obfuscation, or dynamic code execution.
lib/mock/snapshot-utils.js safe Cleared by Jev triage; no further analysis needed
lib/util/cache.js safe Cleared by Jev triage; no further analysis needed
lib/util/date.js safe Cleared by Jev triage; no further analysis needed
lib/util/promise.js safe Cleared by Jev triage; no further analysis needed
lib/util/runtime-features.js safe No malicious patterns detected; the code performs lazy loading of Node.js built-in modules for runtime feature detection without any exfiltration, obfuscation, or unauthorized operations.
lib/util/stats.js safe Cleared by Jev triage; no further analysis needed
lib/util/timers.js safe Cleared by Jev triage; no further analysis needed
lib/web/cache/cache.js safe No malicious patterns detected; the code implements a standard Service Worker Cache API without exfiltration, obfuscation, dynamic code execution, or file system/network abuse.
lib/web/cache/cachestorage.js safe No malicious patterns detected; this is a standard CacheStorage implementation using internal module imports and Web IDL validation without network, filesystem, process, or dynamic code execution concerns.
lib/web/cache/util.js safe Cleared by Jev triage; no further analysis needed
lib/web/cookies/constants.js safe Cleared by Jev triage; no further analysis needed
lib/web/cookies/index.js safe No malicious patterns detected; code implements standard cookie parsing/serialization using WebIDL converters.
lib/web/cookies/parse.js safe This is a standard RFC 6265 cookie parsing implementation with no malicious patterns, network calls, process spawning, or obfuscation detected.
lib/web/cookies/util.js safe Cleared by Jev triage; no further analysis needed
lib/web/eventsource/eventsource-stream.js safe No malicious patterns detected
lib/web/eventsource/eventsource.js safe No malicious patterns detected; this is a standard EventSource implementation with no data exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
lib/web/eventsource/util.js safe Cleared by Jev triage; no further analysis needed
lib/web/fetch/body.js safe No malicious patterns detected in this standard Fetch API body handling implementation.
lib/web/fetch/constants.js safe Cleared by Jev triage; no further analysis needed
lib/web/fetch/data-url.js safe No malicious patterns detected
lib/web/fetch/formdata.js safe The code is a standard WHATWG-compliant FormData implementation and contains no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or backdoor installation.
lib/web/fetch/global.js safe No malicious patterns detected; the code simply manages a global origin URL symbol with proper validation.
lib/web/fetch/headers.js safe No malicious patterns detected; the code implements WHATWG Fetch Headers API with no exfiltration, credential harvesting, obfuscation, or dynamic execution.
lib/web/fetch/index.js safe This is the standard undici/fetch implementation from Node.js with no malicious patterns detected.
lib/web/fetch/request.js safe No malicious patterns detected
lib/web/fetch/response.js safe No malicious patterns detected; the code is a standard implementation of the WHATWG Fetch API Response class without any data exfiltration, environment variable harvesting, obfuscation, or suspicious network/file system activity.
lib/web/fetch/util.js safe No malicious patterns detected in this fetch utility module; all logic aligns with WHATWG fetch specification implementation.
lib/web/infra/index.js safe Cleared by Jev triage; no further analysis needed
lib/web/subresource-integrity/subresource-integrity.js safe The code is a legitimate Subresource Integrity (SRI) implementation using Node.js crypto module with no malicious patterns detected.
lib/web/webidl/index.js safe Cleared by Jev triage; no further analysis needed
lib/web/websocket/connection.js safe No malicious patterns detected
lib/web/websocket/constants.js safe Cleared by Jev triage; no further analysis needed
lib/web/websocket/events.js safe Cleared by Jev triage; no further analysis needed
lib/web/websocket/permessage-deflate.js safe No malicious patterns detected; the code implements standard per-message deflate decompression for WebSocket with payload size limits and no external calls, obfuscation, or process execution.
lib/web/websocket/receiver.js safe No malicious patterns detected; this is a standard WebSocket frame parser implementing RFC 6455 with proper validation, size limits, and extension handling.
lib/web/websocket/sender.js safe This code is part of the legitimate undici HTTP client library and contains no malicious patterns; it implements WebSocket frame sending with a queue, using only the provided socket.
lib/web/websocket/stream/websocketerror.js safe This file implements a WebSocketError class with DOMException inheritance and validation logic; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, mining, backdoors, or dynamic code execution were detected.
lib/web/websocket/stream/websocketstream.js safe The code is a standard WebSocketStream implementation from the undici HTTP client library, with no malicious patterns, data exfiltration, obfuscation, or unauthorized system access.
lib/web/websocket/util.js safe No malicious patterns detected; the code implements standard WebSocket utility functions without data exfiltration, obfuscation, or suspicious behavior.
lib/web/websocket/websocket.js safe No malicious patterns detected; this is a standard WHATWG WebSocket implementation for Node.js without data exfiltration, credential harvesting, obfuscation, or unauthorized system access.

Affected version ranges

None of the 4 scanned versions of undici are flagged high or critical. The latest scanned version, 8.11.2, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

6.21.38.11.2
VersionsVerdictCountRangeTop findings
8.11.2 Needs review 1 8.11.2 Potential path traversal / unsafe filename handling
7.30.0 Not scanned 1 7.30.0
7.29.0 Needs review 1 7.29.0 Potential path traversal / unsafe filename handling; Obfuscated code / encoded payload
7.18.2 Not scanned 1 7.18.2
6.27.0 โ€“ 6.28.0 Needs review 2 >=6.27.0 <=6.28.0 Potential denial of service; Weak Cryptographic Fallback
6.21.3 Not scanned 1 6.21.3

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of undici

VersionVerdictFilesScanned
8.11.2 Needs review 112 Oct 6, 2026
7.29.0 Needs review 114 Oct 6, 2026
6.28.0 Needs review 99 Oct 6, 2026
6.27.0 Needs review 99 Oct 6, 2026

Frequently asked questions

Is undici safe to use?

No confirmed malware was found in undici@7.29.0, but the review flagged 3 medium, 19 low severity findings for risky patterns worth checking before you rely on it.

Does undici contain malware?

No malware was identified in undici@7.29.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was undici checked?

Togoder Security downloaded the published npm package and had an AI model read its 114 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan undici together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in undici@7.29.0, cost nothing.

Related security reports