Summary
Togoder Security scanned the npm package use-sync-external-store@1.4.0 on Oct 4, 2026. An AI review of 15 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings 1
Environment-based conditional module loading
NPS-3B2ECA9A31BD
The code conditionally loads either a production or development build based on NODE_ENV. This is a standard pattern for shimming React's useSyncExternalStore. Dynamic require() with relative paths is expected here and does not involve external input.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| cjs/use-sync-external-store-shim.development.js | safe | This file is the official React use-sync-external-store development shim from Meta, containing only standard React hook logic and development warnings with no malicious patterns. |
| cjs/use-sync-external-store-shim.native.development.js | safe | No malicious patterns detected; the file is a legitimate React development shim for useSyncExternalStore with no exfiltration, obfuscation, or suspicious behavior. |
| cjs/use-sync-external-store-shim.native.production.js | safe | This is the official React use-sync-external-store shim with no malicious patterns, network activity, credential access, or dynamic code execution. |
| cjs/use-sync-external-store-shim.production.js | safe | This is the official React use-sync-external-store shim with no malicious patterns, external network calls, credential access, or dynamic code execution. |
| cjs/use-sync-external-store-shim/with-selector.development.js | safe | No malicious patterns detected in this standard React shim implementation |
| cjs/use-sync-external-store-shim/with-selector.production.js | safe | No malicious patterns detected; the file is a standard React useSyncExternalStoreWithSelector shim implementation. |
| cjs/use-sync-external-store-with-selector.development.js | safe | No malicious patterns detected; this is a legitimate React development build of the use-sync-external-store-with-selector shim. |
| cjs/use-sync-external-store-with-selector.production.js | safe | This is the official React use-sync-external-store-with-selector shim with no malicious patterns, no network, filesystem, process, or dynamic code execution. |
| cjs/use-sync-external-store.development.js | safe | No malicious patterns detected |
| cjs/use-sync-external-store.production.js | safe | No malicious patterns detected; the file is a trivial production re-export of React's useSyncExternalStore with no suspicious behavior. |
| index.js | safe | Cleared by Jev triage; no further analysis needed |
| shim/index.js | safe | This is a standard shim file that selects between production and development builds based on NODE_ENV; no malicious patterns were detected. |
| shim/index.native.js | safe | No malicious patterns detected |
| shim/with-selector.js | safe | No malicious patterns detected; the file is a standard conditional CommonJS shim that only loads sibling package files based on NODE_ENV. |
| with-selector.js | safe | No malicious patterns detected |
Affected version ranges
None of the 3 scanned versions of use-sync-external-store are flagged high or critical. The latest scanned version, 1.6.0, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of use-sync-external-store
Frequently asked questions
Is use-sync-external-store safe to use?
Our AI source review of use-sync-external-store@1.4.0 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does use-sync-external-store contain malware?
No malware was identified in use-sync-external-store@1.4.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was use-sync-external-store checked?
Togoder Security downloaded the published npm package and had an AI model read its 15 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan use-sync-external-store together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in use-sync-external-store@1.4.0, cost nothing.