# update-browserslist-db@1.3.3 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:25:06.000Z
- Files reviewed: 4
- Findings: 4 medium, 7 low severity findings
- Report: https://security.togoder.click/npm/update-browserslist-db
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package update-browserslist-db@1.3.3 on Oct 6, 2026. An AI review of 4 source files produced 4 medium, 7 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Spawning processes or shell commands

Finding ID: `NPS-6E8F4F5D9CEB`

File: `check-npm-version.js:6`

The script uses child_process.execSync to run the 'npm -v' command, which spawns a shell process. While this specific usage appears legitimate for checking the npm version, the pattern of executing shell commands at import/execution time is a potential security concern if the code were modified or if the command were influenced by external input.

### [medium] File system manipulation outside package scope

Finding ID: `NPS-E8C7B2014B4F`

File: `index.js`

The code writes to and deletes files in the user's project directory, including package.json, pnpm-workspace.yaml, and lockfiles (package-lock.json, yarn.lock, pnpm-lock.yaml, bun.lock, deno.lock). It temporarily modifies package.json and workspace configuration to inject overrides, then restores them. While scoped to the invoking project, this is significant side-effectful behavior.

### [medium] Temporary security control bypass

Finding ID: `NPS-C216005296EA`

File: `index.js`

updatePnpmStrict temporarily sets overrides and removes the pnpm workspace file to bypass pnpm's minimumReleaseAge security gate, installing versions chosen by the tool instead of the configured policy. It restores the files afterward, but during execution it disables a user-configured supply-chain safeguard.

### [medium] Spawning processes / shell commands

Finding ID: `NPS-620FE0BEE848`

File: `index.js:1`

The module extensively uses child_process execSync/execFileSync to run package manager commands (yarn, npm, pnpm, bun, deno) in the current working directory. While this is the intended functionality of the update-browserslist-db tool, it constitutes arbitrary command execution surfaces if any of the invoked commands or the resolved binaries are attacker-controlled.

### [low] Code that runs at import time

Finding ID: `NPS-34F332998A19`

File: `check-npm-version.js:4`

The script executes top-level code that checks for the existence of 'deno.lock' and runs npm version checks immediately upon import. This means any package that requires this module will trigger process spawning and version checks as a side effect, which could be unexpected behavior in a library context.

### [low] Dynamic module loading with computed path

Finding ID: `NPS-6349AF17CD71`

File: `cli.js:6`

The code uses require('./') to load a local module and require('./check-npm-version'). While these are relative paths within the package, the require('./') resolves to the package's main entry point which could execute arbitrary code from the package if it is compromised. However, no external input is used for module resolution.

### [low] File system read of package.json

Finding ID: `NPS-19F0C78B08D7`

File: `cli.js:11`

The code reads package.json from the package root directory to extract name, version, and description. This is a common pattern for CLI tools and does not access sensitive files outside the package scope.

### [low] Top-level execution of package code

Finding ID: `NPS-335FA3486F07`

File: `cli.js:36`

The CLI invokes updateDb() which is imported from the package's main module. This is expected behavior for a CLI tool named update-browserslist-db. However, it executes at runtime when the CLI is invoked, not at install/import time.

### [low] Environment variable inspection

Finding ID: `NPS-DD84630C1FAE`

File: `index.js`

Reads process.env.HADOOP_HOME to conditionally select 'yarnpkg' instead of 'yarn'. This is not credential harvesting, but it does alter command execution based on environment, which could be abused if an attacker can set HADOOP_HOME to force use of a different binary name that resolves elsewhere in PATH.

### [low] Dynamic command construction

Finding ID: `NPS-AC7770F7B794`

File: `index.js`

Command strings such as `install + ' caniuse-lite baseline-browser-mapping'` are constructed dynamically and passed to execSync. While inputs are derived from constants and lockfile mode, the pattern of building shell command strings from variables is a code-smell that increases risk if any variable becomes attacker-influenced.

### [low] Network access via package managers

Finding ID: `NPS-8CDC4F049593`

File: `index.js`

The module causes network requests indirectly by invoking npm/yarn/pnpm/bun/deno to fetch caniuse-lite and baseline-browser-mapping metadata and packages. This is expected for a dependency-update tool, but represents network egress initiated by the code.

## Files reviewed

- `check-npm-version.js` (medium): The code appears to be a legitimate npm version check utility, but it uses child process execution and runs side-effect code at import time, which are potential security concerns if the script were compromised or misused.
- `cli.js` (medium): This CLI script appears to be a legitimate utility for updating browserslist database, with no clear malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning detected.
- `index.js` (medium): This appears to be the legitimate update-browserslist-db utility that intentionally spawns package managers and modifies lockfiles; no clear exfiltration, obfuscation, backdoor, or credential-harvesting patterns were found, but its extensive process spawning and file rewriting warrant caution.
- `utils.js` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
