Summary
Togoder Security scanned the npm package use-sync-external-store@1.2.0 on Oct 4, 2026. An AI review of 10 source files produced 4 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings 4
environment variable usage
NPS-B4DCCE038CD9
The code checks process.env.NODE_ENV to determine development vs production mode, which is a standard practice in React packages.
devtools hook access
NPS-8434CF299D25
Accesses __REACT_DEVTOOLS_GLOBAL_HOOK__ for integration with React DevTools, a standard debugging interface, not a security concern.
internal React API access
NPS-46A0989B6A57
Uses React.__SECRET_INTERNALS_DO_NOT_USE_OR_YOU_WILL_BE_FIRED for accessing ReactDebugCurrentFrame for stack traces in warnings, which is an internal React API but not malicious.
console output
NPS-FD763111ADCA
Uses console.error/warning for development warnings via Function.prototype.apply.call, which is standard for React warnings.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| cjs/use-sync-external-store-shim.development.js | safe | The code is the official React use-sync-external-store shim for development, containing only standard React development warnings and no malicious patterns. |
| cjs/use-sync-external-store-shim.native.development.js | safe | This is the official React use-sync-external-store shim library for React Native; it contains no malicious patterns, network calls, or dynamic code execution. |
| cjs/use-sync-external-store-shim/with-selector.development.js | safe | Cleared by Jev triage; no further analysis needed |
| cjs/use-sync-external-store-with-selector.development.js | safe | No malicious patterns detected |
| cjs/use-sync-external-store.development.js | safe | No malicious patterns detected; the code is a legitimate React development build for use-sync-external-store with only console warnings and safe module-level hooks. |
| index.js | safe | Standard conditional module export based on NODE_ENV with no malicious patterns detected |
| shim/index.js | safe | No malicious patterns detected |
| shim/index.native.js | safe | No malicious patterns detected; the file is a standard conditional module export for React's use-sync-external-store shim. |
| shim/with-selector.js | safe | No malicious patterns detected; the file is a standard environment-based module re-export shim for a well-known React use-sync-external-store package. |
| with-selector.js | safe | The wrapper file simply re-exports a production or development build based on NODE_ENV, with no malicious patterns. |
Affected version ranges
None of the 3 scanned versions of use-sync-external-store are flagged high or critical. The latest scanned version, 1.6.0, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of use-sync-external-store
Frequently asked questions
Is use-sync-external-store safe to use?
Our AI source review of use-sync-external-store@1.2.0 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does use-sync-external-store contain malware?
No malware was identified in use-sync-external-store@1.2.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was use-sync-external-store checked?
Togoder Security downloaded the published npm package and had an AI model read its 10 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan use-sync-external-store together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in use-sync-external-store@1.2.0, cost nothing.