Summary
Togoder Security scanned the npm package unstorage@1.17.3 on Oct 4, 2026. An AI review of 78 source files produced 4 high, 13 medium, 23 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 40
Path Traversal
NPS-5E4C559A4743
The key validation regex PATH_TRAVERSE_RE only checks for '..:' or '..' at the end of the key, which is insufficient to prevent path traversal. Keys like '..%2F' or '..\' on Windows or keys containing '..' followed by a path separator (e.g., '../') are not caught. Since the resolved path is constructed via path.join(opts.base, key.replace(/:/g, '/')), an attacker could potentially escape the base directory and read/write/delete arbitrary files outside the intended scope. However, this is a limited warning because the regex does catch some traversal attempts and the driver is intended for use with a trusted base directory.
File system manipulation outside package scope
NPS-8264EE9EDE7C
The driver provides methods to read, write, and delete files based on user-supplied keys. Due to insufficient path validation, these operations can affect files outside the intended base directory.
Path traversal
NPS-51DF318CF4A8
The regex PATH_TRAVERSE_RE only matches '..:' and '..' at the end of the key. It does not block path traversal sequences like '../', '..\', or absolute paths (e.g., '/etc/passwd'). An attacker could provide a key such as '../secret' to escape the base directory and read, write, or delete arbitrary files outside the intended scope.
Path traversal via colon replacement
NPS-9933BC60A865
The key is transformed by replacing all colons ':' with forward slashes '/' before joining with the base path. This could allow an attacker to bypass the weak PATH_TRAVERSE_RE check by using colons to construct traversal sequences (e.g., '..:' becomes '../').
Path traversal potential
NPS-3C7519BC86AE
The key is derived directly from event.path (or a custom resolvePath function) without visible sanitization in this file. The normalizeBaseKey and normalizeKey functions come from an external module and their implementation is not shown. If these functions don't properly sanitize path traversal sequences (e.g., ../), an attacker could potentially access or modify storage keys outside the intended namespace.
Authorization bypass potential
NPS-0683C47A01FA
The authorize option is optional. If a developer creates a storage server without providing an authorize function, all read/write/delete operations are completely unauthenticated. While this may be intentional for some use cases, it represents a significant security risk if deployed publicly without additional protections.
Unvalidated User Input
NPS-5E7E64485579
The container name and account name are taken directly from options and used to construct Azure Blob Storage URLs and credentials without validation or sanitization. An attacker controlling the options could potentially redirect requests to a malicious server or access unintended resources.
No Input Validation for Keys
NPS-97332B565D89
The key parameter used in various blob operations is passed directly without validation, potentially allowing path traversal or other injection attacks depending on Azure Blob Storage behavior.
Potential SSRF
NPS-6F1F88D257CE
The endpointSuffix is configurable, allowing an attacker to specify a custom domain. Combined with accountName, this could be used to make requests to internal or attacker-controlled services (SSRF).
Potential SQL Injection via Table Name Interpolation
NPS-A27A5E3C62BD
The table name is interpolated directly into SQL queries using template literal syntax {${opts.tableName}} without validation or sanitization. If an attacker can control the tableName option, they could inject arbitrary SQL. While the default is fixed, user-provided options may be untrusted.
Insufficient Input Validation
NPS-07721AEDCF74
The key sanitization only replaces colons with slashes and checks a narrow regex. It does not validate for null bytes, absolute paths (e.g., '/etc/passwd' after resolving), or other dangerous characters. This could lead to unintended file system access if the driver is used with untrusted keys.
File system manipulation outside package scope
NPS-0E47D8BA93F1
The driver accepts a user-provided base directory and performs read, write, delete, and recursive remove operations on paths joined to that base. While base is resolved via path.resolve, there is no sandboxing to ensure operations cannot escape the intended root if traversal protection is bypassed. clear() calls rmRecursive on r('.'), which deletes the entire base directory recursively.
Path traversal protection weakness
NPS-F55F550D3CF1
The r() function attempts to prevent path traversal by checking for ..: and ..$ patterns, but this regex does not catch all traversal attempts. Keys like 'foo/../../' or 'foo/..' followed by more segments may still traverse if the regex isn't comprehensive. Additionally, the replacement of ':' with '/' could be abused in certain scenarios depending on key formatting.
SQL Injection via table name interpolation
NPS-501D81C8A1FB
The opts.table value is directly interpolated into SQL queries without validation or sanitization. While the key and value are parameterized, the table name is not. An attacker who can control the table option (e.g., through configuration or environment variables) could inject arbitrary SQL. This is a security vulnerability in the package itself, though it requires attacker control over driver options.
Network requests with user-controlled URLs
NPS-A4F9B98B28AC
The getItem, getItemRaw, and getMeta functions perform fetch and head requests to blob URLs returned by the list API. If an attacker can control the list response (e.g., via a compromised token or API), this could lead to SSRF or data exfiltration. However, the URLs are from the trusted Vercel Blob service.
Dynamic module loading via computed specifier
NPS-F1594D0AAB79
The function tryRequireVCFunctions dynamically requires the module '@vercel/functions' using createRequire with a computed path and a hard-coded external package name. While this is a legitimate pattern for optional peer dependencies, it constitutes dynamic module loading that could be abused in a modified package to load arbitrary code or circumvent static analysis.
Dynamic module loading
NPS-5F74F2967274
Uses createRequire(import.meta.url)('@vercel/functions') to load an external module named '@vercel/functions' via Node's module resolution. This is a dynamic require of an externally named package. While it uses a hardcoded string and appears legitimate for Vercel's runtime cache integration, it introduces a supply chain dependency where a malicious or compromised '@vercel/functions' package could execute arbitrary code at import time.
Dynamic import / module loading with computed or external input
NPS-F051DB1B5FE8
The builtinDrivers object maps driver names to module specifiers (e.g., 'unstorage/drivers/fs', 'unstorage/drivers/http'). These strings are later used in dynamic require() calls by the package's resolver logic (not shown in this file). While the driver names are not directly attacker-controlled in this file, the pattern of mapping user-provided driver names to dynamic imports is a common vector if the resolver does not validate the driver string. This is a design-level concern rather than a confirmed vulnerability in the provided code.
Potential DoS via unbounded key listing
NPS-02246AF9EA9D
The GET handler for base keys calls storage.getKeys(key) and maps over all results without pagination or limits. For large storage backends, this could lead to memory exhaustion or excessive response sizes.
Debug mode enabled
NPS-53373ED2F66B
The H3 app is created with debug: true, which may leak sensitive error details, stack traces, or internal information to clients in production environments.
Credential handling
NPS-0BC177F2CB77
The driver accepts an accountKey option and passes it to the CosmosClient. This is expected behavior for authentication, not exfiltration. Credentials are not harvested from environment files or sent to external servers.
Dynamic queries
NPS-0513053C3868
The getKeys and clear methods use static SQL queries with no user input, so no injection risk.
Credential Handling
NPS-2793D35C4021
The driver accepts multiple credential types (account key, SAS URL, SAS key, connection string, DefaultAzureCredential) and stores them in options. While this is expected for a storage driver, improper handling could lead to credential leakage if options are logged or exposed.
Missing Error Handling
NPS-A58675F743E8
The getItem and getItemRaw methods catch all errors and return null, potentially hiding failures that could indicate security issues or misconfigurations.
Use of Experimental Warning Global State
NPS-E62D4AC78DCC
The code sets a global flag globalThis[kExperimentalWarning] to avoid repeated warnings. This is not malicious but modifies global state, which could be considered poor practice.
SQL Injection via tagged template/table name interpolation
NPS-95B8A50B82B4
The table name is interpolated directly into SQL strings using template literal syntax (e.g., INSERT INTO {${opts.tableName}}). While the {...} syntax is likely transformed by the database driver into a safe identifier, if opts.tableName is attacker-controlled and the driver does not properly quote it, this could allow identifier injection. However, the values themselves use parameterized placeholders (${key}, ${value}), and the table name is typically controlled by the application developer, not end users.
Experimental warning logging
NPS-EF12E47D7932
The code logs a warning to the console once when the driver is first used. This is benign and not a security concern.
Dynamic code execution / module loading
NPS-AF210CF48F1D
The code requires 'chokidar' and 'anymatch', which are external dependencies. If these packages are compromised or substituted, they could introduce malicious behavior. However, this is standard dependency usage, not an inherent flaw in this file.
File system operations
NPS-70A7F5E30395
The driver performs file system operations (read/write/delete) within the configured base directory. This is expected functionality for a file system driver and does not constitute malicious behavior.
Path traversal protection
NPS-CB68463E35EF
The code includes explicit checks (PATH_TRAVERSE_RE) to prevent directory traversal via '..' segments in keys, which is a security measure.
Dynamic URL construction
NPS-5406D4D7BDA6
URLs are built from user-provided repo, branch, dir, apiURL, and cdnURL options. If an attacker can control these options, they could redirect requests to arbitrary servers. However, this is inherent to the driver's configurable design and not a malicious pattern in itself.
Network access with credentials
NPS-B0FFE8F53A89
The driver sends HTTP requests to GitHub's API and raw content endpoints, optionally including an Authorization token from the driver options. This is expected for a GitHub storage driver and does not constitute exfiltration; the token is only sent to the configured GitHub URLs.
Suspicious SQL execution at connection time
NPS-DFA1A0B070E3
The code executes SET @@boost_cached_queries = true; when opts.boostCache is set. This is a legitimate PlanetScale feature to enable query caching, but it demonstrates that the driver can execute arbitrary SQL statements at initialization. This is not inherently malicious but worth noting as it shows the driver executes SQL beyond standard CRUD operations.
Environment variable usage
NPS-DC2B40D2B6D7
The driver reads credentials (UPSTASH_REDIS_REST_URL and UPSTASH_REDIS_REST_TOKEN) from environment variables. This is standard practice for configuring clients and not inherently malicious, but it should be noted that the code accesses process.env.
Network communication
NPS-30D246FDEC2F
The driver creates a Redis client that communicates with an external Upstash Redis instance. This is expected behavior for a storage driver, but it does involve external network requests.
Environment variable credential access
NPS-41FA293E67C4
The code reads a token from an environment variable (e.g., BLOB_READ_WRITE_TOKEN) and uses it for API authentication. While this is standard for legitimate drivers, it could be a vector for credential harvesting if the package is malicious or compromised. The token is used to access Vercel Blob storage.
Potential regex injection
NPS-775E1E1D222C
In getKeys, a RegExp is constructed using optsBase without escaping special characters. If optsBase contains regex metacharacters, it could cause unexpected behavior or errors. This is a minor robustness issue, not a direct security vulnerability.
Use of globalThis process.getBuiltinModule
NPS-292787737799
The code uses globalThis.process?.getBuiltinModule?.('node:module') to obtain createRequire, a relatively new API. This allows constructing require functions at runtime, which can be a vector for loading modules in a non-standard way. Not inherently malicious, but worth monitoring.
Potential code execution at import time via getCache
NPS-2158FA5B5DDE
The module exports a driver factory, but importing the file defines getCache/tryRequireVCFunctions. The tryRequireVCFunctions function lazily loads '@vercel/functions', which if malicious could execute arbitrary code on first cache access. The overall purpose (Vercel runtime cache driver) is consistent with a legitimate cache driver.
Access to process/getBuiltinModule and global state
NPS-7D43F4E51AC1
Accesses globalThis.process.getBuiltinModule('node:module') and Symbol.for('@vercel/request-context') on globalThis. This is used to obtain the runtime cache context from Vercel's serverless environment. It does not harvest environment variables or credentials, but relies on globals that could be manipulated by other code running in the same process.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/server.cjs | medium | This is a legitimate storage server handler for unstorage/h3, but it has security considerations around optional authorization, potential path traversal, and debug mode enabled. |
| drivers/azure-storage-blob.mjs | medium | The code is a legitimate Azure Blob Storage driver but lacks input validation and has potential SSRF and credential handling concerns. |
| drivers/db0.cjs | medium | The driver uses parameterized queries for user data but interpolates the table name into SQL, posing a potential SQL injection risk if the table name is attacker-controlled; no other malicious patterns were found. |
| drivers/fs-lite.cjs | medium | The code is a file system driver with weak path traversal protection that may allow access outside the base directory. |
| drivers/fs-lite.mjs | medium | The fs-lite driver has a path traversal vulnerability due to an insufficient regex and colon replacement, allowing escape from the base directory and arbitrary file access. |
| drivers/fs.cjs | medium | The fs driver contains path traversal protection that may be insufficient and performs file system operations based on user-supplied keys, but no explicit malicious code, exfiltration, or shell execution was found. |
| drivers/planetscale.mjs | medium | The code is a legitimate unstorage driver for PlanetScale with no malicious patterns, but contains a medium-severity SQL injection risk due to unvalidated table name interpolation in queries. |
| drivers/upstash.mjs | medium | The code appears to be a legitimate Upstash Redis driver for Unstorage, with no clear malicious patterns; it only uses environment variables for credentials and performs expected network operations. |
| drivers/vercel-blob.mjs | medium | The code appears to be a legitimate Vercel Blob storage driver with no obvious malicious patterns, but it accesses environment variables for credentials and makes network requests to external services. |
| drivers/vercel-runtime-cache.cjs | medium | No clear malicious intent detected; the code implements a Vercel runtime cache driver with dynamic module loading for an optional peer dependency, which is unusual but consistent with legitimate library patterns. |
| drivers/vercel-runtime-cache.mjs | medium | The file appears to be a legitimate Vercel runtime cache driver with a dynamic require of '@vercel/functions', posing only a mild supply-chain risk; no clear malicious data exfiltration, credential harvesting, obfuscation, mining, or process spawning was found. |
| dist/index.cjs | safe | No malicious patterns such as data exfiltration, credential harvesting, obfuscated code, backdoors, or suspicious process execution were detected; the code is a standard storage abstraction library. |
| dist/index.mjs | safe | No malicious patterns detected; the code implements a legitimate unstorage abstraction with in-memory driver, storage mounting, and built-in driver routing, with no data exfiltration, credential harvesting, obfuscation, or process spawning. |
| dist/server.mjs | safe | This is a legitimate h3/unstorage HTTP storage server handler with no malicious patterns such as exfiltration, credential harvesting, dynamic code execution, or process spawning. |
| dist/shared/unstorage.DD6EOqvC.cjs | safe | No malicious patterns detected; the code is a standard storage utility from the unstorage package with no data exfiltration, credential harvesting, or other security concerns. |
| dist/shared/unstorage.zVDD2mZo.mjs | safe | No malicious patterns detected; the code is a legitimate unstorage utility module for serialization, key normalization, and storage prefixing without any network, filesystem, process, or dynamic code execution concerns. |
| drivers/azure-app-configuration.cjs | safe | No malicious patterns detected; the file is a legitimate Azure App Configuration driver using standard Azure SDK clients with no obfuscation, exfiltration, credential harvesting, or suspicious execution. |
| drivers/azure-app-configuration.mjs | safe | No malicious patterns detected; the code is a legitimate Azure App Configuration driver using standard SDK calls and credential handling. |
| drivers/azure-cosmos.cjs | safe | No malicious patterns detected; the code is a legitimate Azure Cosmos DB driver using standard SDKs without obfuscation, exfiltration, or process execution. |
| drivers/azure-cosmos.mjs | safe | The code is a legitimate Azure Cosmos DB storage driver for unstorage with no malicious patterns; it only uses expected Azure SDK APIs and static queries. |
| drivers/azure-key-vault.cjs | safe | No malicious patterns detected; the code is a legitimate Azure Key Vault driver using standard Azure SDKs with no exfiltration, obfuscation, or suspicious behavior. |
| drivers/azure-key-vault.mjs | safe | The Azure Key Vault driver uses standard Azure SDK patterns with no malicious or suspicious behavior detected. |
| drivers/azure-storage-blob.cjs | safe | No malicious patterns detected; the code is a standard Azure Blob Storage driver that uses only official Azure SDKs and no suspicious behaviors. |
| drivers/azure-storage-table.cjs | safe | No malicious patterns detected; the code is a legitimate Azure Storage Table driver for unstorage with standard authentication and CRUD operations. |
| drivers/azure-storage-table.mjs | safe | No malicious patterns detected; the driver implements standard Azure Table Storage operations with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior. |
Show 53 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| drivers/capacitor-preferences.cjs | safe | No malicious patterns detected; the code is a straightforward Capacitor Preferences storage driver using only its declared dependency. |
| drivers/capacitor-preferences.mjs | safe | No malicious patterns detected |
| drivers/cloudflare-kv-binding.cjs | safe | No malicious patterns detected; the file is a standard Cloudflare KV binding storage driver that only interacts with a user-supplied KV binding via documented get/put/list/delete operations. |
| drivers/cloudflare-kv-binding.mjs | safe | No malicious patterns detected; the code is a legitimate Cloudflare KV binding driver for unstorage with no exfiltration, obfuscation, or unauthorized system access. |
| drivers/cloudflare-kv-http.cjs | safe | The code is a legitimate Cloudflare KV HTTP driver with no malicious patterns, backdoors, exfiltration, or other security concerns. |
| drivers/cloudflare-kv-http.mjs | safe | No malicious patterns detected; the code is a legitimate Cloudflare KV HTTP driver that sends credentials only to the configured Cloudflare API endpoint. |
| drivers/cloudflare-r2-binding.cjs | safe | No malicious patterns detected; the code is a legitimate Cloudflare R2 binding storage driver with standard CRUD operations and no suspicious network, filesystem, execution, or credential-harvesting behavior. |
| drivers/cloudflare-r2-binding.mjs | safe | No malicious patterns detected |
| drivers/db0.mjs | safe | The code is a database storage driver for unstorage with no malicious patterns; it uses parameterized queries and only performs expected database operations. |
| drivers/deno-kv-node.cjs | safe | No malicious patterns detected; the code is a straightforward Deno KV driver wrapper that passes options to openKv without any suspicious behavior. |
| drivers/deno-kv-node.mjs | safe | No malicious patterns detected |
| drivers/deno-kv.cjs | safe | No malicious patterns detected; the code implements a Deno KV storage driver with no exfiltration, credential harvesting, dynamic execution, or other suspicious behavior. |
| drivers/deno-kv.mjs | safe | No malicious patterns detected; the code is a straightforward Deno KV storage driver with no exfiltration, obfuscation, or unsafe execution. |
| drivers/fs.mjs | safe | The code is a legitimate file system driver with built-in path traversal protection and no suspicious or malicious patterns. |
| drivers/github.cjs | safe | No malicious patterns detected; the code is a legitimate unstorage GitHub driver that fetches repository file trees and raw file content from configured GitHub APIs with optional token authentication. |
| drivers/github.mjs | safe | No malicious patterns detected; the code is a legitimate GitHub storage driver that makes expected network requests to GitHub APIs using optional user-supplied tokens. |
| drivers/http.cjs | safe | The code is a standard HTTP storage driver implementation using ofetch and ufo, with no malicious patterns, credential harvesting, exfiltration, or unsafe execution detected. |
| drivers/http.mjs | safe | No malicious patterns detected; the code is a standard HTTP-based Unstorage driver that performs user-configured network requests without exfiltration, code execution, or filesystem access outside its scope. |
| drivers/indexedb.cjs | safe | No malicious patterns detected; the code is a straightforward IndexedDB storage driver using idb-keyval with no exfiltration, credential harvesting, dynamic execution, or other red flags. |
| drivers/indexedb.mjs | safe | Cleared by Jev triage; no further analysis needed |
| drivers/localstorage.cjs | safe | No malicious patterns detected; the code is a standard localStorage driver with no exfiltration, dynamic execution, or process spawning. |
| drivers/localstorage.mjs | safe | The file is a standard localStorage driver wrapper with no malicious patterns, network calls, process spawning, or credential harvesting. |
| drivers/lru-cache.cjs | safe | No malicious patterns detected; the code is a legitimate LRU cache driver implementation. |
| drivers/lru-cache.mjs | safe | Cleared by Jev triage; no further analysis needed |
| drivers/memory.cjs | safe | This is a simple in-memory key-value storage driver using a Map, with no network, file system, process, or dynamic code execution behavior. |
| drivers/memory.mjs | safe | Cleared by Jev triage; no further analysis needed |
| drivers/mongodb.cjs | safe | No malicious patterns detected; this is a standard MongoDB storage driver implementing expected CRUD operations without data exfiltration, credential harvesting, obfuscation, or suspicious network/process activity. |
| drivers/mongodb.mjs | safe | No malicious patterns detected; the code is a legitimate MongoDB storage driver for unstorage. |
| drivers/netlify-blobs.cjs | safe | No malicious patterns detected; the code is a standard Netlify Blobs storage driver with no exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| drivers/netlify-blobs.mjs | safe | No malicious patterns detected; code is a standard Netlify Blobs storage driver with no exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| drivers/null.cjs | safe | No malicious patterns detected |
| drivers/null.mjs | safe | Cleared by Jev triage; no further analysis needed |
| drivers/overlay.cjs | safe | No malicious patterns detected |
| drivers/overlay.mjs | safe | No malicious patterns detected; this is a legitimate unstorage overlay storage driver with no network, filesystem, process, or dynamic execution concerns. |
| drivers/planetscale.cjs | safe | No malicious patterns detected; the code is a legitimate PlanetScale storage driver with parameterized queries and no exfiltration, obfuscation, or credential harvesting. |
| drivers/redis.cjs | safe | No malicious patterns detected |
| drivers/redis.mjs | safe | This is a legitimate Redis storage driver implementation with no malicious patterns detected. |
| drivers/s3.cjs | safe | No malicious patterns detected; the code is a standard S3 driver implementation using aws4fetch for signing requests. |
| drivers/s3.mjs | safe | No malicious patterns detected; the code is a standard S3 driver implementation with expected AWS SDK usage and no suspicious behavior. |
| drivers/session-storage.cjs | safe | No malicious patterns detected; the file is a simple sessionStorage driver wrapper with no network, filesystem, or code execution activity. |
| drivers/session-storage.mjs | safe | Cleared by Jev triage; no further analysis needed |
| drivers/uploadthing.cjs | safe | No malicious patterns detected; the code is a legitimate storage driver for UploadThing. |
| drivers/uploadthing.mjs | safe | No malicious patterns detected; the code is a legitimate UploadThing storage driver with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| drivers/upstash.cjs | safe | No malicious patterns detected; the code is a legitimate Upstash Redis driver with expected credential handling via environment variables and options. |
| drivers/utils/cloudflare.cjs | safe | No malicious patterns detected; the code only retrieves and validates Cloudflare bindings from globalThis or __env__ with no exfiltration, process execution, or other suspicious behavior. |
| drivers/utils/cloudflare.mjs | safe | No malicious patterns detected |
| drivers/utils/index.cjs | safe | No malicious patterns detected; the code only provides utility functions for key normalization, error creation, and driver definition. |
| drivers/utils/index.mjs | safe | Cleared by Jev triage; no further analysis needed |
| drivers/utils/node-fs.cjs | safe | No malicious patterns detected; the code is a straightforward filesystem utility wrapper with no network, credential, or process execution activity. |
| drivers/utils/node-fs.mjs | safe | No malicious patterns detected |
| drivers/vercel-blob.cjs | safe | No malicious patterns detected; code is a legitimate Vercel Blob storage driver using the official @vercel/blob SDK. |
| drivers/vercel-kv.cjs | safe | No malicious patterns detected; the code is a legitimate Vercel KV storage driver that reads credentials from environment variables for its intended API client. |
| drivers/vercel-kv.mjs | safe | No malicious patterns detected |
Affected version ranges
None of the 2 scanned versions of unstorage are flagged high or critical. The latest scanned version, 1.17.5, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 1.17.3 โ 1.17.5 | Needs review | 2 | >=1.17.3 <=1.17.5 | Path Traversal; Path traversal via colon replacement |
| 1.16.0 | Not scanned | 1 | 1.16.0 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of unstorage
Frequently asked questions
Is unstorage safe to use?
No confirmed malware was found in unstorage@1.17.3, but the review flagged 4 high, 13 medium, 23 low severity findings for risky patterns worth checking before you rely on it.
Does unstorage contain malware?
No malware was identified in unstorage@1.17.3 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was unstorage checked?
Togoder Security downloaded the published npm package and had an AI model read its 78 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan unstorage together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in unstorage@1.17.3, cost nothing.