Togoder security

npm package security report

undici@8.11.2 security report

Risky patterns found that deserve a look.

Needs review Version 8.11.2 Files reviewed 112 Size 1.3 MB Scanned

Summary

Togoder Security scanned the npm package undici@8.11.2 on Oct 6, 2026. An AI review of 112 source files produced 1 medium, 25 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
25
low

Findings 26

medium

Potential path traversal / unsafe filename handling

NPS-A0549B5C7452

The parser extracts filename values from Content-Disposition headers, including extended RFC 5987 values via decodeURIComponent, and passes them directly into File objects (new File([body], filename, ...)) and form entries. Downstream consumers writing these files to disk without sanitization could be vulnerable to path traversal (e.g., '../../etc/passwd'), though this file itself does not perform file writes.

lib/web/fetch/formdata-parser.js:268
low

Dynamic function composition

NPS-48073504749D

Interceptors are invoked dynamically at runtime (dispatch = interceptor(dispatch, interceptorOrigin)). If an attacker controls interceptor values, arbitrary code execution within the dispatch chain is possible. However, interceptors are supplied by the caller, not from external input, so risk is limited.

lib/dispatcher/dispatcher.js:33
low

Proxy-based monkey-patching / interception

NPS-25108EDD9126

The compose() method wraps the dispatcher instance in a Proxy that intercepts property access and substitutes a custom dispatch function. While common in HTTP client libraries (e.g., undici) for interceptor support, this pattern could be abused to silently alter request behavior if the source were malicious. No evidence of exfiltration or credential access in this file.

lib/dispatcher/dispatcher.js:48
low

Environment variable harvesting

NPS-9B0AD1BB8609

The code reads HTTP_PROXY, HTTPS_PROXY, http_proxy, https_proxy, NO_PROXY, and no_proxy environment variables. While this is standard behavior for proxy agents (the 'Env' prefix implies environment-based configuration), it does grant the module visibility into the host's proxy configuration, which could be exfiltrated if the module were compromised elsewhere.

lib/dispatcher/env-http-proxy-agent.js:25
low

Network routing behavior

NPS-299F96F5A538

The dispatcher constructs ProxyAgent instances pointing at URIs derived from environment variables (HTTP_PROXY/HTTPS_PROXY) and routes outbound requests through them. This is the intended, documented purpose of an EnvHttpProxyAgent, but it does mean all traffic from callers using this agent can be redirected to an attacker-controlled proxy if the environment is compromised.

lib/dispatcher/env-http-proxy-agent.js:30
low

Suspicious reference to undefined property

NPS-4F7B0B02ADF8

In #shouldProxy, the code references this.#noProxyChanged (line 87 in the file), but the class only defines a getter named #noProxyChanged. Reading this.#noProxyChanged invokes the getter, which is fine, but the naming (a getter used as a boolean flag) is confusing and may indicate an intended caching mechanism that isn't actually implemented. Not malicious, but worth noting for correctness.

lib/dispatcher/env-http-proxy-agent.js:87
low

Regex-based hostname parsing

NPS-76FC1072E56E

The NO_PROXY parser uses regexes on untrusted environment input. The patterns are anchored and bounded, so catastrophic backtracking is unlikely, but parsing environment-controlled data with regexes is a minor robustness concern.

lib/dispatcher/env-http-proxy-agent.js:120
low

Network connections to user-specified endpoints only

NPS-76D529519115

All network activity (Client/Pool/Agent/Socks5ProxyAgent, buildConnector) is directed at the proxy URI or origin supplied by the caller. No hardcoded external hosts, telemetry, or unexpected endpoints are present.

lib/dispatcher/proxy-agent.js
low

Intended proxy credential handling

NPS-CB1D46A06A87

The code reads proxy credentials from constructor options (opts.auth, opts.token, URL username/password) and forwards them as Proxy-Authorization headers to the configured proxy. This is expected behavior for a ProxyAgent and does not constitute credential harvesting or exfiltration.

lib/dispatcher/proxy-agent.js:145
low

Explicit security hardening against credential leakage

NPS-9FD922F79C68

Contains throwIfProxyAuthIsSent/buildHeaders logic that explicitly prevents users from passing Proxy-Authorization headers per-request (fixes GHSA-6cv7-626c-qhqw), which is a defensive measure rather than a vulnerability.

lib/dispatcher/proxy-agent.js:336
low

Global state manipulation

NPS-EF7971667F46

This module sets and retrieves a global Dispatcher object on globalThis using Symbol.for. This is intentional API design for undici, a widely-used official HTTP client. It does not exfiltrate data, harvest credentials, or execute dynamic code.

lib/global.js:10
low

Import-time side effect

NPS-04A92083F664

The module creates and installs a default Agent at import time if no global dispatcher exists. This is a benign initialization side effect consistent with the library's purpose.

lib/global.js:10
low

Embedded WebAssembly binary

NPS-128E14EE48D9

The file embeds a large base64-encoded WebAssembly blob (llhttp parser) and lazily decodes it via Buffer.from on first access to module.exports. This is a legitimate pattern used by llhttp (the HTTP parser used by Node.js). The WASM imports only env callbacks typical of llhttp (wasm_on_headers_complete, wasm_on_message_begin, wasm_on_body, etc.), and exports llhttp_* APIs. No suspicious host bindings for file, network, or process access are present in the imports.

lib/llhttp/llhttp-wasm.js:5
low

Top-level module execution

NPS-AE58BF134E57

Top-level code defines a getter for module.exports that base64-decodes the embedded blob on demand. There is no eval, no child_process, no network calls, no filesystem access, and no environment/credential harvesting. Execution at import time is limited to defining the property; the decode happens only when exports are accessed.

lib/llhttp/llhttp-wasm.js:7
low

base64-encoded WASM binary

NPS-EBED6DEE6307

The file contains a large base64-encoded WebAssembly binary for llhttp (HTTP parser). This is a standard technique used by llhttp to ship a WASM build. The binary exposes only HTTP-parsing callbacks (on_headers_complete, on_message_begin, on_url, on_status, on_header_field, on_header_value, on_body, on_message_complete) and llhttp API functions. No network, filesystem, process-spawning, or credential-harvesting functionality is present.

lib/llhttp/llhttp_simd-wasm.js
low

lazy module.exports getter

NPS-CB03BAB7B6B2

module.exports is redefined with a getter that lazily decodes the base64 WASM payload once. This is a benign pattern to defer the cost of base64 decoding until first use. It executes at import time but performs no I/O or code execution beyond a Buffer.from base64 decode.

lib/llhttp/llhttp_simd-wasm.js
low

no_malicious_patterns

NPS-14CB65F5C4CB

The code is a mock agent implementation for Undici. It only uses local module imports, standard JavaScript constructs, and does not perform any network requests, file I/O, process spawning, dynamic code execution, or credential harvesting. All operations are confined to in-memory dispatcher management and call history tracking.

lib/mock/mock-agent.js
low

file system write

NPS-FBBDBBF2889D

The snapshot recorder writes request/response data to disk at user-controlled paths via saveSnapshots(), which is expected for a testing/mocking library but does represent persistent file system writes outside the immediate package directory depending on the snapshotPath provided.

lib/mock/snapshot-recorder.js:339
low

silent error swallowing in flush

NPS-CB0D94380496

Flush failures are silently ignored via empty catch handlers, which could mask write failures and diagnostics; not malicious but a quality concern.

lib/mock/snapshot-recorder.js:396
low

auto-flush timer writing data unconditionally

NPS-3F30C096794B

When autoFlush is enabled, the scheduler periodically writes snapshot contents (which may include request headers, bodies, and responses) to the configured snapshotPath. If snapshotPath points outside the project or sensitive headers are not excluded, this can persist sensitive data to disk.

lib/mock/snapshot-recorder.js:408
low

Unbounded resource consumption / DoS potential

NPS-B23CF90B0AFC

The multipart parser uses input.indexOf to scan for boundaries and processes arbitrarily large bodies without size limits or iteration caps. A maliciously crafted multipart body could cause excessive memory or CPU usage. This is a robustness concern rather than an intentional backdoor.

lib/web/fetch/formdata-parser.js:120
low

Decoding ambiguity in content-disposition attributes

NPS-2CE9F5B6C8F0

parseContentDispositionAttribute applies decodeURIComponent to extended (RFC 5987) values and performs ad-hoc percent-decoding replacements (%0A, %0D, %22) on quoted strings. Malformed percent sequences could throw, and the transformation is non-standard, but this is a correctness/robustness issue rather than an exploit vector in this module.

lib/web/fetch/formdata-parser.js:260
low

potentially unsafe decompression logic

NPS-EFC4742BFBB7

The InflateStream class wraps zlib inflate with caller-provided options. While it doesn't expose dynamic code execution or network access, decompressing untrusted streams without size limits could be used for resource exhaustion if callers pass attacker-controlled data. This is normal fetch/undici behavior rather than a malicious pattern.

lib/web/fetch/util.js:756
low

File system manipulation

NPS-4B1646C3655C

The script reads and overwrites './undici-fetch.js' using readFileSync and writeFileSync. While this is likely a build-time script for encoding conversion (UTF-8 to Latin-1), it modifies a source file in place and could be abused to alter package contents.

scripts/strip-comments.js:5
low

Top-level execution

NPS-75095FB9BF35

The script executes file I/O operations at import time (top-level code), which can have side effects when the module is required.

scripts/strip-comments.js:5
low

Encoding conversion

NPS-B5073923CCF6

The script uses buffer transcode to convert a file from UTF-8 to Latin-1. This is a legitimate but unusual operation that could theoretically be used to obfuscate or alter code content.

scripts/strip-comments.js:6

Files reviewed

FileVerdictWhat the reviewer saw
lib/dispatcher/dispatcher.js medium The file is a standard Dispatcher base class with interceptor composition; no malicious patterns, credential harvesting, network exfiltration, or dynamic code execution were detected.
lib/dispatcher/env-http-proxy-agent.js medium The file is a legitimate proxy agent implementation that reads standard proxy environment variables; no exfiltration, credential theft, code execution, or other malicious patterns were found, though it does handle sensitive environment configuration that warrants awareness.
lib/mock/snapshot-recorder.js medium No malicious patterns detected; the module is a standard snapshot recorder that performs expected file I/O for saving/loading mock data, with no network exfiltration, credential harvesting, dynamic code execution, or shell spawning.
lib/web/fetch/formdata-parser.js medium No malicious patterns (exfiltration, credential harvesting, obfuscation, process spawning) were found; the file is a standard multipart/form-data parser with minor robustness and downstream filename-safety concerns.
scripts/strip-comments.js medium Script performs in-place encoding conversion on a local file, which is suspicious but likely benign build tooling; no exfiltration, credential harvesting, or code execution detected.
index-fetch.js safe This file is a standard entry point that re-exports undici's fetch/WebSocket/EventSource APIs and only augments stack traces on fetch errors, with no suspicious behavior.
index.js safe No malicious patterns detected; this is the standard entry point of the undici HTTP client library with only expected module exports and no exfiltration, obfuscation, or suspicious runtime behavior.
lib/api/abort-signal.js safe Cleared by Jev triage; no further analysis needed
lib/api/api-connect.js safe This is a legitimate undici CONNECT handler implementation with no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, dynamic execution, or suspicious network/file operations.
lib/api/api-pipeline.js safe No malicious patterns detected
lib/api/api-request.js safe No malicious patterns detected; this is a standard HTTP request handler implementation from the undici library with proper input validation and no exfiltration, credential harvesting, code execution, or process spawning.
lib/api/api-stream.js safe No malicious patterns detected; the code is a legitimate streaming API handler with no signs of data exfiltration, credential harvesting, dynamic code execution, or other security concerns.
lib/api/api-upgrade.js safe No malicious patterns detected; the code is a standard Undici HTTP upgrade handler with no exfiltration, credential harvesting, obfuscation, process spawning, or dynamic code execution.
lib/api/index.js safe Cleared by Jev triage; no further analysis needed
lib/api/readable.js safe No malicious patterns detected in this readable stream implementation, which appears to be a legitimate HTTP body consumer utility.
lib/cache/memory-cache-store.js safe No malicious patterns detected; the file implements a standard in-memory cache store with no network, filesystem, process, or dynamic code execution concerns.
lib/cache/sqlite-cache-store.js safe No malicious patterns detected; the code is a legitimate SQLite-backed HTTP cache store with no data exfiltration, credential harvesting, code execution, or other suspicious behavior.
lib/core/connect.js safe No malicious patterns detected; the code is a standard TLS/TCP socket connector implementation from undici.
lib/core/constants.js safe Cleared by Jev triage; no further analysis needed
lib/core/diagnostics.js safe No malicious patterns detected
lib/core/errors.js safe Cleared by Jev triage; no further analysis needed
lib/core/request.js safe No malicious patterns detected; the code is a well-structured HTTP request implementation with strict input validation and no signs of exfiltration, credential harvesting, obfuscation, or other security concerns.
lib/core/socks5-client.js safe This is a straightforward SOCKS5 client implementation with no malicious patterns, no external calls beyond the provided socket, and no credential harvesting or code execution concerns.
lib/core/socks5-utils.js safe No malicious patterns detected
lib/core/symbols.js safe Cleared by Jev triage; no further analysis needed
Show 87 more files
FileVerdictWhat the reviewer saw
lib/core/tree.js safe No malicious patterns detected; the code implements a ternary search tree for header name lookups with no network, filesystem, process, or dynamic code execution behavior.
lib/core/util.js safe No malicious patterns detected; the code is a standard utility module from undici with no evidence of exfiltration, credential harvesting, obfuscation, or backdoor behavior.
lib/dispatcher/agent.js safe No malicious patterns detected
lib/dispatcher/balanced-pool.js safe No malicious patterns detected in the BalancedPool dispatcher implementation; the code is a legitimate load-balancing pool from the undici HTTP client library.
lib/dispatcher/client-h1.js safe This is the legitimate HTTP/1.1 dispatcher from the undici package; it contains no malicious patterns, no obfuscation, no credential harvesting, no external data exfiltration, and no install-time execution.
lib/dispatcher/client-h2.js safe No malicious patterns detected; the file is a legitimate undici HTTP/2 client dispatcher with only standard networking, stream, and error-handling logic.
lib/dispatcher/client.js safe No malicious patterns detected; the file is a legitimate HTTP client dispatcher implementation (undici) with standard connection handling and no data exfiltration, credential harvesting, obfuscation, or shell execution.
lib/dispatcher/dispatcher-base.js safe Cleared by Jev triage; no further analysis needed
lib/dispatcher/dispatcher1-wrapper.js safe No malicious patterns detected; the code is a legitimate adapter wrapper for a dispatcher with no exfiltration, credential harvesting, obfuscation, or process spawning.
lib/dispatcher/fixed-queue.js safe Cleared by Jev triage; no further analysis needed
lib/dispatcher/h2c-client.js safe No malicious patterns detected; the code is a straightforward HTTP/2 cleartext client wrapper with input validation and no exfiltration, obfuscation, or dynamic execution.
lib/dispatcher/pool-base.js safe No malicious patterns detected
lib/dispatcher/pool.js safe No malicious patterns detected; the code implements a standard connection pool dispatcher for undici with no exfiltration, credential harvesting, dynamic execution, or other suspicious behavior.
lib/dispatcher/proxy-agent.js safe This is the legitimate undici ProxyAgent implementation; no data exfiltration, obfuscation, dynamic execution, process spawning, or filesystem abuse patterns were found, and credential handling is limited to user-supplied proxy auth.
lib/dispatcher/retry-agent.js safe No malicious patterns detected
lib/dispatcher/round-robin-pool.js safe This code implements a round-robin connection pool for HTTP clients and contains no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or unauthorized process execution.
lib/dispatcher/socks5-proxy-agent.js safe No malicious patterns detected; the code is a legitimate SOCKS5 proxy agent implementation with no data exfiltration, credential harvesting, obfuscation, or other security red flags.
lib/encoding/index.js safe Cleared by Jev triage; no further analysis needed
lib/global.js safe This file is a legitimate undici global dispatcher module with no malicious patterns; it only manages an in-process global HTTP dispatcher and contains no exfiltration, credential harvesting, dynamic execution, or process spawning.
lib/handler/cache-handler.js safe No malicious patterns detected; the code is a standard HTTP cache handler implementation with no exfiltration, credential harvesting, obfuscation, or process spawning.
lib/handler/cache-revalidation-handler.js safe No malicious patterns detected; this is a standard HTTP cache revalidation handler with no network, filesystem, process, or code-execution red flags.
lib/handler/decorator-handler.js safe Cleared by Jev triage; no further analysis needed
lib/handler/deduplication-handler.js safe No malicious patterns detected; the code is a legitimate request deduplication handler with no network, filesystem, process, or dynamic code execution concerns.
lib/handler/redirect-handler.js safe No malicious patterns detected; the code implements HTTP redirect handling with proper credential stripping on cross-origin redirects.
lib/handler/retry-handler.js safe No malicious patterns detected; this is a legitimate HTTP retry handler implementation from the undici package with no data exfiltration, credential harvesting, obfuscation, or suspicious system-level operations.
lib/interceptor/cache.js safe No malicious patterns detected; the code is a legitimate HTTP cache interceptor implementation with no data exfiltration, credential harvesting, obfuscation, or process spawning.
lib/interceptor/decompress.js safe This is a legitimate HTTP response decompression interceptor for the undici library with no malicious patterns, no external network calls, no credential harvesting, no dynamic code execution, and no install-time code execution.
lib/interceptor/deduplicate.js safe No malicious patterns detected
lib/interceptor/dns.js safe No malicious patterns detected; the code is a legitimate DNS interceptor implementation without exfiltration, credential harvesting, obfuscation, or backdoor behavior.
lib/interceptor/dump.js safe No malicious patterns detected; the code implements a response size limiting interceptor without any exfiltration, obfuscation, or process spawning behaviors.
lib/interceptor/redirect.js safe No malicious patterns detected; the code is a standard redirect interceptor for HTTP client libraries with no data exfiltration, credential harvesting, obfuscation, or process execution.
lib/interceptor/response-error.js safe No malicious patterns detected; the code is a legitimate undici response error interceptor that parses HTTP error bodies with no external communication, credential access, or dynamic execution.
lib/interceptor/retry.js safe No malicious patterns detected
lib/llhttp/constants.js safe No malicious patterns detected; the file contains only static HTTP parsing constants and maps with no dynamic execution, network, filesystem, or credential access.
lib/llhttp/llhttp-wasm.js safe The file is a thin wrapper that lazily base64-decodes the bundled llhttp WebAssembly HTTP parser; no malicious patterns such as exfiltration, credential harvesting, obfuscated execution, backdoors, or process spawning were detected.
lib/llhttp/llhttp_simd-wasm.js safe The file is a benign llhttp WASM shim that lazily base64-decodes an HTTP-parser WebAssembly binary; no exfiltration, credential harvesting, dynamic execution, process spawning, or malicious behavior was found.
lib/llhttp/utils.js safe Cleared by Jev triage; no further analysis needed
lib/mock/mock-agent.js safe No malicious patterns detected; the code is a legitimate mock dispatcher implementation for Undici testing.
lib/mock/mock-call-history.js safe Cleared by Jev triage; no further analysis needed
lib/mock/mock-client.js safe Cleared by Jev triage; no further analysis needed
lib/mock/mock-errors.js safe Cleared by Jev triage; no further analysis needed
lib/mock/mock-interceptor.js safe Cleared by Jev triage; no further analysis needed
lib/mock/mock-pool.js safe Cleared by Jev triage; no further analysis needed
lib/mock/mock-symbols.js safe Cleared by Jev triage; no further analysis needed
lib/mock/mock-utils.js safe This is a legitimate undici mock-agent utility module with no malicious patterns, network exfiltration, credential harvesting, dynamic code execution, or suspicious behavior.
lib/mock/pending-interceptors-formatter.js safe No malicious patterns detected; the code is a benign utility for formatting pending interceptor data using Node.js streams and console.
lib/mock/snapshot-agent.js safe No malicious patterns detected; the code implements an HTTP snapshot recording/replay agent using standard Node.js APIs without any data exfiltration, credential harvesting, obfuscation, or unauthorized system access.
lib/mock/snapshot-utils.js safe Cleared by Jev triage; no further analysis needed
lib/util/cache.js safe Cleared by Jev triage; no further analysis needed
lib/util/date.js safe Cleared by Jev triage; no further analysis needed
lib/util/runtime-features.js safe No malicious patterns detected
lib/util/stats.js safe Cleared by Jev triage; no further analysis needed
lib/util/timers.js safe Cleared by Jev triage; no further analysis needed
lib/web/cache/cache.js safe No malicious patterns detected; this is a standard implementation of the Cache API for undici with no exfiltration, credential harvesting, obfuscation, or suspicious behavior.
lib/web/cache/cachestorage.js safe No malicious patterns detected
lib/web/cache/util.js safe Cleared by Jev triage; no further analysis needed
lib/web/cookies/constants.js safe Cleared by Jev triage; no further analysis needed
lib/web/cookies/index.js safe No malicious patterns detected; the code is a standard cookie handling utility with proper WebIDL validation and no network, filesystem, process, or obfuscation concerns.
lib/web/cookies/parse.js safe This is a legitimate RFC 6265 cookie parser implementation with no malicious patterns, network activity, file system access, or dynamic code execution.
lib/web/cookies/util.js safe Cleared by Jev triage; no further analysis needed
lib/web/eventsource/eventsource-stream.js safe No malicious patterns detected; the code is a standard EventSource stream parser with no data exfiltration, credential harvesting, dynamic code execution, or other red flags.
lib/web/eventsource/eventsource.js safe No malicious patterns detected; the file implements a standard EventSource (Server-Sent Events) client with expected network behavior and no exfiltration, obfuscation, or process execution.
lib/web/eventsource/util.js safe Cleared by Jev triage; no further analysis needed
lib/web/fetch/body.js safe No malicious patterns detected; the code implements standard Fetch API body extraction logic from the undici HTTP client library.
lib/web/fetch/constants.js safe Cleared by Jev triage; no further analysis needed
lib/web/fetch/data-url.js safe No malicious patterns detected
lib/web/fetch/formdata.js safe This is a standard FormData implementation from the undici HTTP client library with no malicious patterns detected.
lib/web/fetch/global.js safe No malicious patterns detected; the code simply manages a global origin URL symbol with proper validation.
lib/web/fetch/headers.js safe Cleared by Jev triage; no further analysis needed
lib/web/fetch/index.js safe No malicious patterns detected; this is the standard fetch implementation from the undici package with no signs of exfiltration, credential harvesting, obfuscation, or other red flags.
lib/web/fetch/request.js safe The code is a legitimate implementation of the WHATWG Fetch standard's Request class from the undici library, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or unauthorized network/file/process access.
lib/web/fetch/response.js safe This is a standard Fetch API Response implementation (part of undici) with no malicious patterns, data exfiltration, obfuscation, or unauthorized system access.
lib/web/fetch/util.js safe No malicious patterns detected; the file implements standard WHATWG fetch utilities without exfiltration, credential harvesting, obfuscated code, process spawning, or install-time hooks.
lib/web/infra/index.js safe Cleared by Jev triage; no further analysis needed
lib/web/subresource-integrity/subresource-integrity.js safe The code is a legitimate Subresource Integrity (SRI) implementation using Node.js crypto module with no malicious patterns detected.
lib/web/webidl/index.js safe Cleared by Jev triage; no further analysis needed
lib/web/websocket/connection.js safe This code implements standard WebSocket connection establishment and closing per the WHATWG WebSockets specification using Node.js built-ins, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or backdoor installation detected.
lib/web/websocket/constants.js safe Cleared by Jev triage; no further analysis needed
lib/web/websocket/events.js safe Cleared by Jev triage; no further analysis needed
lib/web/websocket/frame.js safe No malicious patterns detected; the code implements WebSocket frame masking and construction using standard crypto and buffer operations without external communication, credential access, or dynamic execution.
lib/web/websocket/permessage-deflate.js safe No malicious patterns detected
lib/web/websocket/receiver.js safe The WebSocket frame parser contains no malicious patterns; it is a standard, well-structured implementation with no data exfiltration, code execution, filesystem access, or process spawning.
lib/web/websocket/sender.js safe This code is part of the legitimate undici HTTP client library and contains no malicious patterns; it implements WebSocket frame sending with a queue, using only the provided socket.
lib/web/websocket/stream/websocketerror.js safe No malicious patterns detected
lib/web/websocket/stream/websocketstream.js safe No malicious patterns detected; the code implements the WebSocketStream API with standard network and stream handling, without any data exfiltration, credential harvesting, obfuscation, or process spawning.
lib/web/websocket/util.js safe No malicious patterns detected; the code implements standard WebSocket utility functions without data exfiltration, obfuscation, or suspicious behavior.
lib/web/websocket/websocket.js safe This is a standard WHATWG-compliant WebSocket client implementation with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or unauthorized process execution.

Affected version ranges

None of the 4 scanned versions of undici are flagged high or critical. The latest scanned version, 8.11.2, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

6.21.38.11.2
VersionsVerdictCountRangeTop findings
8.11.2 Needs review 1 8.11.2 Potential path traversal / unsafe filename handling
7.30.0 Not scanned 1 7.30.0
7.29.0 Needs review 1 7.29.0 Potential path traversal / unsafe filename handling; Obfuscated code / encoded payload
7.18.2 Not scanned 1 7.18.2
6.27.0 โ€“ 6.28.0 Needs review 2 >=6.27.0 <=6.28.0 Potential denial of service; Weak Cryptographic Fallback
6.21.3 Not scanned 1 6.21.3

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of undici

VersionVerdictFilesScanned
8.11.2 Needs review 112 Oct 6, 2026
7.29.0 Needs review 114 Oct 6, 2026
6.28.0 Needs review 99 Oct 6, 2026
6.27.0 Needs review 99 Oct 6, 2026

Frequently asked questions

Is undici safe to use?

No confirmed malware was found in undici@8.11.2, but the review flagged 1 medium, 25 low severity findings for risky patterns worth checking before you rely on it.

Does undici contain malware?

No malware was identified in undici@8.11.2 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was undici checked?

Togoder Security downloaded the published npm package and had an AI model read its 112 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan undici together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in undici@8.11.2, cost nothing.

Related security reports