# utf-8-validate@5.0.10 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:42:11.000Z
- Files reviewed: 2
- Findings: 2 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/utf-8-validate
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package utf-8-validate@5.0.10 on Oct 4, 2026. An AI review of 2 source files produced 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic module loading with external resolution

Finding ID: `NPS-9052E56E2325`

File: `index.js:4`

The code uses require('node-gyp-build')(__dirname) which resolves and loads a native binding dynamically based on the directory path. node-gyp-build searches for and loads prebuilt binaries or compiled .node files. This is a common and legitimate pattern for native addons, but it introduces a dependency on an external package whose behavior cannot be verified from this file alone. If node-gyp-build or the loaded native module were compromised, arbitrary native code could execute at import time.

### [medium] Silent fallback to unverified module

Finding ID: `NPS-633354E536CD`

File: `index.js:6`

On any error from node-gyp-build, the code falls back to require('./fallback'). The contents of ./fallback are not shown and cannot be audited here. If the fallback module contains malicious code, it would execute transparently whenever the primary load fails.

### [low] Top-level code execution on import

Finding ID: `NPS-FF7985F66EE4`

File: `index.js:4`

The module executes require() calls at the top level, meaning code runs immediately upon import. While this is standard for CommonJS modules, it means any side effects of node-gyp-build or ./fallback occur whenever the package is loaded, including during install/build if imported by lifecycle scripts.

## Files reviewed

- `index.js` (medium): The file is a standard native-addon loader using node-gyp-build with a silent fallback; it is a common legitimate pattern but relies on external and unshown modules that warrant auditing.
- `fallback.js` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
