Summary
Togoder Security scanned the npm package v8-compile-cache-lib@3.0.1 on Oct 4, 2026. An AI review of 1 source file produced 3 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 5
Module.prototype._compile override
NPS-A408030AC9E7
The install() function overrides Module.prototype._compile, which is a core Node.js function responsible for compiling modules. This is a powerful hook that allows interception and modification of all module loading in the process. While this is the intended mechanism for v8-compile-cache, such overrides can be abused for malicious purposes (e.g., injecting code into every module loaded).
Dynamic code execution via vm.Script
NPS-34E72CDC08D7
The code uses vm.Script to compile and run JavaScript code from files. While this is the intended purpose of v8-compile-cache (to cache compiled module code), the use of vm.Script with runInThisContext can execute arbitrary code. The cached data is validated via SHA-1 hash of the content, but if an attacker can write to the cache directory, they could potentially inject malicious cached data. The cache directory is located in the system temp directory (os.tmpdir()) and may have predictable names, potentially allowing cache poisoning attacks.
File system manipulation outside package scope
NPS-AAAD6015CB1D
The code writes cache files (BLOB, MAP, LOCK) to a directory in the system temp folder (os.tmpdir()) or to a directory specified by the V8_COMPILE_CACHE_CACHE_DIR environment variable. This is outside the package's own scope but is expected behavior for a compile cache. The cache directory is created with 0o777 permissions (world-writable), which could allow other users on the system to tamper with the cache files, leading to potential code execution if the cache is poisoned.
Lock file creation with 'wx' flag
NPS-094ADE170B11
The code creates a lock file using fs.writeFileSync with the 'wx' flag (exclusive creation). If the file already exists, the operation fails and the function returns false, swallowing the error. This could be a denial-of-service vector if an attacker pre-creates the lock file, preventing cache saves. However, this is not a malicious pattern per se.
Environment variable usage
NPS-FDCFFD60F63B
The code reads the V8_COMPILE_CACHE_CACHE_DIR environment variable to determine the cache directory. This is not credential harvesting but could be used to redirect cache writes to arbitrary locations. Additionally, DISABLE_V8_COMPILE_CACHE is checked. No sensitive credentials or environment variables are harvested or exfiltrated.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| v8-compile-cache.js | medium | The code is a legitimate v8 compile cache implementation (v8-compile-cache) that overrides module compilation and writes cache files to the system temp directory; while it uses dynamic code execution via vm.Script and overrides Module._compile, these are core to its functionality and no overtly malicious patterns (exfiltration, credential harvesting, backdoors) were found, though cache poisoning and permission issues pose medium risks. |
Frequently asked questions
Is v8-compile-cache-lib safe to use?
No confirmed malware was found in v8-compile-cache-lib@3.0.1, but the review flagged 3 medium, 2 low severity findings for risky patterns worth checking before you rely on it.
Does v8-compile-cache-lib contain malware?
No malware was identified in v8-compile-cache-lib@3.0.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was v8-compile-cache-lib checked?
Togoder Security downloaded the published npm package and had an AI model read its 1 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan v8-compile-cache-lib together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in v8-compile-cache-lib@3.0.1, cost nothing.