Togoder security

npm package security report

v8-compile-cache-lib@3.0.1 security report

Risky patterns found that deserve a look.

Needs review Version 3.0.1 Files reviewed 1 Size 11.3 KB Scanned

Summary

Togoder Security scanned the npm package v8-compile-cache-lib@3.0.1 on Oct 4, 2026. An AI review of 1 source file produced 3 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
3
medium
2
low

Findings 5

medium

Module.prototype._compile override

NPS-A408030AC9E7

The install() function overrides Module.prototype._compile, which is a core Node.js function responsible for compiling modules. This is a powerful hook that allows interception and modification of all module loading in the process. While this is the intended mechanism for v8-compile-cache, such overrides can be abused for malicious purposes (e.g., injecting code into every module loaded).

v8-compile-cache.js:133
medium

Dynamic code execution via vm.Script

NPS-34E72CDC08D7

The code uses vm.Script to compile and run JavaScript code from files. While this is the intended purpose of v8-compile-cache (to cache compiled module code), the use of vm.Script with runInThisContext can execute arbitrary code. The cached data is validated via SHA-1 hash of the content, but if an attacker can write to the cache directory, they could potentially inject malicious cached data. The cache directory is located in the system temp directory (os.tmpdir()) and may have predictable names, potentially allowing cache poisoning attacks.

v8-compile-cache.js:231
medium

File system manipulation outside package scope

NPS-AAAD6015CB1D

The code writes cache files (BLOB, MAP, LOCK) to a directory in the system temp folder (os.tmpdir()) or to a directory specified by the V8_COMPILE_CACHE_CACHE_DIR environment variable. This is outside the package's own scope but is expected behavior for a compile cache. The cache directory is created with 0o777 permissions (world-writable), which could allow other users on the system to tamper with the cache files, leading to potential code execution if the cache is poisoned.

v8-compile-cache.js:279
low

Lock file creation with 'wx' flag

NPS-094ADE170B11

The code creates a lock file using fs.writeFileSync with the 'wx' flag (exclusive creation). If the file already exists, the operation fails and the function returns false, swallowing the error. This could be a denial-of-service vector if an attacker pre-creates the lock file, preventing cache saves. However, this is not a malicious pattern per se.

v8-compile-cache.js:73
low

Environment variable usage

NPS-FDCFFD60F63B

The code reads the V8_COMPILE_CACHE_CACHE_DIR environment variable to determine the cache directory. This is not credential harvesting but could be used to redirect cache writes to arbitrary locations. Additionally, DISABLE_V8_COMPILE_CACHE is checked. No sensitive credentials or environment variables are harvested or exfiltrated.

v8-compile-cache.js:313

Files reviewed

FileVerdictWhat the reviewer saw
v8-compile-cache.js medium The code is a legitimate v8 compile cache implementation (v8-compile-cache) that overrides module compilation and writes cache files to the system temp directory; while it uses dynamic code execution via vm.Script and overrides Module._compile, these are core to its functionality and no overtly malicious patterns (exfiltration, credential harvesting, backdoors) were found, though cache poisoning and permission issues pose medium risks.

Frequently asked questions

Is v8-compile-cache-lib safe to use?

No confirmed malware was found in v8-compile-cache-lib@3.0.1, but the review flagged 3 medium, 2 low severity findings for risky patterns worth checking before you rely on it.

Does v8-compile-cache-lib contain malware?

No malware was identified in v8-compile-cache-lib@3.0.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was v8-compile-cache-lib checked?

Togoder Security downloaded the published npm package and had an AI model read its 1 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan v8-compile-cache-lib together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in v8-compile-cache-lib@3.0.1, cost nothing.

Related security reports