# v8-compile-cache-lib@3.0.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:42:25.000Z
- Files reviewed: 1
- Findings: 3 medium, 2 low severity findings
- Report: https://security.togoder.click/npm/v8-compile-cache-lib
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package v8-compile-cache-lib@3.0.1 on Oct 4, 2026. An AI review of 1 source file produced 3 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Module.prototype._compile override

Finding ID: `NPS-A408030AC9E7`

File: `v8-compile-cache.js:133`

The install() function overrides Module.prototype._compile, which is a core Node.js function responsible for compiling modules. This is a powerful hook that allows interception and modification of all module loading in the process. While this is the intended mechanism for v8-compile-cache, such overrides can be abused for malicious purposes (e.g., injecting code into every module loaded).

### [medium] Dynamic code execution via vm.Script

Finding ID: `NPS-34E72CDC08D7`

File: `v8-compile-cache.js:231`

The code uses vm.Script to compile and run JavaScript code from files. While this is the intended purpose of v8-compile-cache (to cache compiled module code), the use of vm.Script with runInThisContext can execute arbitrary code. The cached data is validated via SHA-1 hash of the content, but if an attacker can write to the cache directory, they could potentially inject malicious cached data. The cache directory is located in the system temp directory (os.tmpdir()) and may have predictable names, potentially allowing cache poisoning attacks.

### [medium] File system manipulation outside package scope

Finding ID: `NPS-AAAD6015CB1D`

File: `v8-compile-cache.js:279`

The code writes cache files (BLOB, MAP, LOCK) to a directory in the system temp folder (os.tmpdir()) or to a directory specified by the V8_COMPILE_CACHE_CACHE_DIR environment variable. This is outside the package's own scope but is expected behavior for a compile cache. The cache directory is created with 0o777 permissions (world-writable), which could allow other users on the system to tamper with the cache files, leading to potential code execution if the cache is poisoned.

### [low] Lock file creation with 'wx' flag

Finding ID: `NPS-094ADE170B11`

File: `v8-compile-cache.js:73`

The code creates a lock file using fs.writeFileSync with the 'wx' flag (exclusive creation). If the file already exists, the operation fails and the function returns false, swallowing the error. This could be a denial-of-service vector if an attacker pre-creates the lock file, preventing cache saves. However, this is not a malicious pattern per se.

### [low] Environment variable usage

Finding ID: `NPS-FDCFFD60F63B`

File: `v8-compile-cache.js:313`

The code reads the V8_COMPILE_CACHE_CACHE_DIR environment variable to determine the cache directory. This is not credential harvesting but could be used to redirect cache writes to arbitrary locations. Additionally, DISABLE_V8_COMPILE_CACHE is checked. No sensitive credentials or environment variables are harvested or exfiltrated.

## Files reviewed

- `v8-compile-cache.js` (medium): The code is a legitimate v8 compile cache implementation (v8-compile-cache) that overrides module compilation and writes cache files to the system temp directory; while it uses dynamic code execution via vm.Script and overrides Module._compile, these are core to its functionality and no overtly malicious patterns (exfiltration, credential harvesting, backdoors) were found, though cache poisoning and permission issues pose medium risks.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
