Summary
Togoder Security scanned the npm package update-browserslist-db@1.3.3 on Oct 6, 2026. An AI review of 4 source files produced 4 medium, 7 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 11
Spawning processes or shell commands
NPS-6E8F4F5D9CEB
The script uses child_process.execSync to run the 'npm -v' command, which spawns a shell process. While this specific usage appears legitimate for checking the npm version, the pattern of executing shell commands at import/execution time is a potential security concern if the code were modified or if the command were influenced by external input.
File system manipulation outside package scope
NPS-E8C7B2014B4F
The code writes to and deletes files in the user's project directory, including package.json, pnpm-workspace.yaml, and lockfiles (package-lock.json, yarn.lock, pnpm-lock.yaml, bun.lock, deno.lock). It temporarily modifies package.json and workspace configuration to inject overrides, then restores them. While scoped to the invoking project, this is significant side-effectful behavior.
Temporary security control bypass
NPS-C216005296EA
updatePnpmStrict temporarily sets overrides and removes the pnpm workspace file to bypass pnpm's minimumReleaseAge security gate, installing versions chosen by the tool instead of the configured policy. It restores the files afterward, but during execution it disables a user-configured supply-chain safeguard.
Spawning processes / shell commands
NPS-620FE0BEE848
The module extensively uses child_process execSync/execFileSync to run package manager commands (yarn, npm, pnpm, bun, deno) in the current working directory. While this is the intended functionality of the update-browserslist-db tool, it constitutes arbitrary command execution surfaces if any of the invoked commands or the resolved binaries are attacker-controlled.
Code that runs at import time
NPS-34F332998A19
The script executes top-level code that checks for the existence of 'deno.lock' and runs npm version checks immediately upon import. This means any package that requires this module will trigger process spawning and version checks as a side effect, which could be unexpected behavior in a library context.
Dynamic module loading with computed path
NPS-6349AF17CD71
The code uses require('./') to load a local module and require('./check-npm-version'). While these are relative paths within the package, the require('./') resolves to the package's main entry point which could execute arbitrary code from the package if it is compromised. However, no external input is used for module resolution.
File system read of package.json
NPS-19F0C78B08D7
The code reads package.json from the package root directory to extract name, version, and description. This is a common pattern for CLI tools and does not access sensitive files outside the package scope.
Top-level execution of package code
NPS-335FA3486F07
The CLI invokes updateDb() which is imported from the package's main module. This is expected behavior for a CLI tool named update-browserslist-db. However, it executes at runtime when the CLI is invoked, not at install/import time.
Environment variable inspection
NPS-DD84630C1FAE
Reads process.env.HADOOP_HOME to conditionally select 'yarnpkg' instead of 'yarn'. This is not credential harvesting, but it does alter command execution based on environment, which could be abused if an attacker can set HADOOP_HOME to force use of a different binary name that resolves elsewhere in PATH.
Dynamic command construction
NPS-AC7770F7B794
Command strings such as install + ' caniuse-lite baseline-browser-mapping' are constructed dynamically and passed to execSync. While inputs are derived from constants and lockfile mode, the pattern of building shell command strings from variables is a code-smell that increases risk if any variable becomes attacker-influenced.
Network access via package managers
NPS-8CDC4F049593
The module causes network requests indirectly by invoking npm/yarn/pnpm/bun/deno to fetch caniuse-lite and baseline-browser-mapping metadata and packages. This is expected for a dependency-update tool, but represents network egress initiated by the code.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| check-npm-version.js | medium | The code appears to be a legitimate npm version check utility, but it uses child process execution and runs side-effect code at import time, which are potential security concerns if the script were compromised or misused. |
| cli.js | medium | This CLI script appears to be a legitimate utility for updating browserslist database, with no clear malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning detected. |
| index.js | medium | This appears to be the legitimate update-browserslist-db utility that intentionally spawns package managers and modifies lockfiles; no clear exfiltration, obfuscation, backdoor, or credential-harvesting patterns were found, but its extensive process spawning and file rewriting warrant caution. |
| utils.js | safe | Cleared by Jev triage; no further analysis needed |
Frequently asked questions
Is update-browserslist-db safe to use?
No confirmed malware was found in update-browserslist-db@1.3.3, but the review flagged 4 medium, 7 low severity findings for risky patterns worth checking before you rely on it.
Does update-browserslist-db contain malware?
No malware was identified in update-browserslist-db@1.3.3 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was update-browserslist-db checked?
Togoder Security downloaded the published npm package and had an AI model read its 4 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan update-browserslist-db together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in update-browserslist-db@1.3.3, cost nothing.