Togoder security

npm package security report

valtio@1.13.2 security report

Risky patterns found that deserve a look.

Needs review Version 1.13.2 Files reviewed 56 Size 221.6 KB Scanned

Summary

Togoder Security scanned the npm package valtio@1.13.2 on Oct 4, 2026. An AI review of 56 source files produced 2 medium, 16 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
16
low

Findings 18

medium

Devtools extension communication

NPS-F5AC79ACCC11

The devtools function connects to the Redux DevTools browser extension and processes messages including ACTION and DISPATCH types. It parses JSON payloads from the extension (JSON.parse) and applies them to the proxy object via Object.assign. While this is intended for debugging, it could allow arbitrary state manipulation if the extension or its messages are compromised. However, this is a known and documented feature of Valtio and not a malicious pattern per se.

esm/vanilla/utils.mjs:128
medium

Suspicious package name pattern (typosquatting/lookalike)

NPS-EB53F411846D

The dependency 'aslemammad-vite-plugin-macro' appears to be a personal-scoped or lookalike package name resembling 'vite-plugin-macro'. Such naming patterns are frequently used in dependency confusion or typosquatting attacks and warrant manual verification of the package's provenance.

system/macro/vite.development.js:1
low

Deprecated package warning

NPS-001D3B9ED853

The code warns that 'useProxy' is deprecated and suggests using 'useSnapshot' instead, indicating potential maintenance concerns but not malicious behavior.

esm/macro/vite.js
low

Babel macro manipulation

NPS-2AA92AB0BC6D

The code uses Babel macros to transform code at build time, which is a legitimate but powerful capability that could be misused. However, the transformation is limited to replacing 'useProxy' calls with 'useSnapshot' from 'valtio'.

esm/macro/vite.js
low

Dynamic code transform (Babel macro)

NPS-573C08E1B841

The macro performs AST transformations using Babel, replacing identifiers and generating code. While legitimate for a macro library, this mechanism could be abused to inject code if the input is attacker-controlled, though no such input handling is present here.

esm/macro/vite.mjs:10
low

Development-only warning

NPS-03BCF5528471

Accesses import.meta.env.MODE to conditionally warn about deprecation. Environment variable access here is limited to build mode detection and does not exfiltrate or harvest sensitive data.

esm/macro/vite.mjs:36
low

Import-time side effect

NPS-32B8633467E8

The module instantiates the macro plugin and calls provideValtioMacro() at import time, which emits a console.warn message. This is a benign side effect but still executes code upon import.

esm/macro/vite.mjs:41
low

Dynamic code execution

NPS-C766353DA2C5

The code does not use eval, Function constructor, or similar dynamic code execution mechanisms. The only parsing is JSON.parse on devtools messages and JSON.stringify in devtools send; these are data serialization, not code execution.

esm/vanilla/utils.mjs
low

Network and filesystem access

NPS-13C745FC4703

There are no outbound network requests, filesystem operations, or process spawning. The code operates entirely on in-memory proxy objects and interacts with the optional Redux DevTools extension via window.__REDUX_DEVTOOLS_EXTENSION__.

esm/vanilla/utils.mjs
low

Deprecated code warning

NPS-EB618B9E52D9

The macro logs a deprecation warning suggesting to use a different hook. This is not malicious, but indicates outdated code.

system/macro.development.js
low

AST manipulation

NPS-107D2A02FEBC

The macro uses Babel's AST manipulation to transform code, including injecting a snapshot variable and replacing identifiers. While this is expected for a Babel macro, it modifies code structure at compile time. No malicious patterns are present.

system/macro.development.js
low

AST transformation of identifiers

NPS-476A3DFA6E04

The macro rewrites Identifier nodes in the parent function scope when their name matches the proxy object, renaming them to the generated snapshot variable. While this is the intended functionality of the macro, it performs code transformation on the consumer's source tree and could be abused to silently alter behavior in ways the developer may not expect.

system/macro/vite.development.js
low

Top-level execution on import

NPS-C0265989185C

Module-level code executes at import time, including defineMacro, defineMacroProvider, createMacroPlugin, and createMacroPlugin({}).use(provideValtioMacro()). Although this is consistent with a Babel macro plugin, it demonstrates that importing the module triggers immediate execution of third-party plugin code.

system/macro/vite.development.js
low

Redux DevTools Extension Integration with External Message Handling

NPS-6795FFBDB7BC

The devtools() function connects to the browser's Redux DevTools extension (window.__REDUX_DEVTOOLS_EXTENSION__) and accepts external messages to modify proxy state via Object.assign(proxyObject, JSON.parse(message.payload)) and Object.assign(proxyObject, state). While this is standard Redux DevTools protocol behavior for state time-travel debugging, it allows any code/extension with access to the DevTools channel to inject arbitrary state into the proxy object, which could be used for prototype pollution or state manipulation in applications that trust proxied state.

system/vanilla/utils.development.js
low

Dynamic code execution via JSON.parse on external input

NPS-429055373CC4

The devtools() function calls JSON.parse(message.payload) and JSON.parse(message.state) on data received from the Redux DevTools extension, then applies the parsed result directly to the proxy object. This is not eval/Function but is dynamic input handling from an external source; malformed or malicious DevTools messages could cause unexpected behavior in the consuming application.

system/vanilla/utils.development.js
low

Unsupported use of process.env at runtime

NPS-5784D26636FB

The code references process.env.NODE_ENV only for development warnings; no environment variable harvesting or external data exfiltration occurs.

vanilla.js
low

devtools extension integration

NPS-D7A36912B48A

devtools() connects to the Redux DevTools browser extension via window.__REDUX_DEVTOOLS_EXTENSION__ if present. This is intentional Valtio functionality, not exfiltration.

vanilla/utils.js:353
low

deprecated API usage

NPS-E7C23F56869E

Uses deprecated Valtio APIs (addComputed, proxyWithComputed, proxyWithHistory) that log console warnings but are not malicious.

vanilla/utils.js:437

Files reviewed

FileVerdictWhat the reviewer saw
esm/macro/vite.js medium The code is a legitimate Vite plugin macro for Valtio state management, with no malicious patterns detected.
esm/macro/vite.mjs medium The code appears to be a legitimate Babel macro plugin with no malicious patterns such as data exfiltration, credential harvesting, or shell execution, though it does run code at import time.
esm/vanilla/utils.mjs medium This is standard Valtio utility code with no malicious patterns; the only concern is the optional Redux DevTools integration that accepts JSON messages from a browser extension, which is expected behavior for debugging tools.
system/macro/vite.development.js medium No explicit exfiltration, shell execution, or credential harvesting is present, but the code relies on an untrusted, oddly named third-party package and performs AST rewriting at import time, warranting caution.
system/vanilla/utils.development.js medium This is the legitimate Valtio state management library with no malicious patterns; only standard Redux DevTools integration for state debugging is present, which involves external message handling but is expected behavior for this library.
esm/index.js safe Cleared by Jev triage; no further analysis needed
esm/index.mjs safe Cleared by Jev triage; no further analysis needed
esm/macro.js safe This is a legitimate babel-plugin-macros macro from the Valtio state management library that performs AST transformations and does not contain any malicious patterns.
esm/macro.mjs safe No malicious patterns detected; this is a legitimate babel-plugin-macros macro for the valtio library that transforms useProxy calls to useSnapshot at build time.
esm/react.js safe No malicious patterns detected; the code is a legitimate React integration for Valtio state management.
esm/react.mjs safe No malicious patterns detected; the code is a standard React hook implementation for valtio state management with no suspicious behavior.
esm/react/utils.js safe Cleared by Jev triage; no further analysis needed
esm/react/utils.mjs safe Cleared by Jev triage; no further analysis needed
esm/utils.js safe Cleared by Jev triage; no further analysis needed
esm/utils.mjs safe Cleared by Jev triage; no further analysis needed
esm/vanilla.js safe No malicious patterns detected; this is the legitimate proxy-compare/valtio library implementing reactive proxy state management without any security concerns.
esm/vanilla.mjs safe No malicious patterns detected; the code is a legitimate proxy state management library with no data exfiltration, credential harvesting, obfuscation, or unauthorized network/file/process operations.
esm/vanilla/utils.js safe No malicious patterns detected in the provided Valtio utilities code; it contains standard state management helpers with no exfiltration, obfuscation, process spawning, or dynamic code execution.
index.js safe No malicious patterns detected
macro.js safe No malicious patterns detected; this is a legitimate Babel macro for Valtio's useProxy hook with standard AST transformation logic and no exfiltration, credential harvesting, or dynamic execution.
macro/vite.js safe No malicious patterns detected
react.js safe No malicious patterns detected
react/utils.js safe No malicious patterns detected
system/index.development.js safe No malicious patterns detected; the code is a standard SystemJS module wrapper that re-exports members from 'valtio/vanilla' and 'valtio/react' without any suspicious behavior.
system/index.production.js safe The file is a standard System.register module wrapper for re-exporting valtio/vanilla and valtio/react; it contains no network, filesystem, process, or dynamic code execution behavior.
Show 31 more files
FileVerdictWhat the reviewer saw
system/macro.development.js safe The code is a legitimate Babel macro for Valtio that performs AST transformations and logs a deprecation warning; no malicious patterns were detected.
system/macro.production.js safe The code is a legitimate Babel macro that transforms useProxy calls for Valtio, with no malicious patterns such as data exfiltration, credential harvesting, or dynamic code execution.
system/macro/vite.production.js safe No malicious patterns detected
system/react.development.js safe No malicious patterns detected; the code is a legitimate React hook implementation for Valtio state management.
system/react.production.js safe No malicious patterns detected; the code is a legitimate React hook (useSnapshot) for Valtio state management using proxy-compare and useSyncExternalStore.
system/react/utils.development.js safe No malicious patterns detected
system/react/utils.production.js safe No malicious patterns detected; the code is a minified React hook for Valtio proxy state access without any exfiltration, obfuscation, or system-level operations.
system/utils.development.js safe No malicious patterns detected
system/utils.production.js safe No malicious patterns detected; the code is a standard SystemJS module re-exporting valtio utilities without suspicious behavior.
system/vanilla.development.js safe No malicious patterns detected; the code is a legitimate proxy state management library with no data exfiltration, credential harvesting, obfuscation, or suspicious runtime behavior.
system/vanilla.production.js safe No malicious patterns detected; the code is a minified JavaScript proxy/snapshot utility using standard reactivity patterns without network, filesystem, or process manipulation.
system/vanilla/utils.production.js safe No malicious patterns detected; this is a minified but legitimate Valtio state-management library utility file.
umd/index.development.js safe No malicious patterns detected
umd/index.production.js safe No malicious patterns detected; the file is a standard UMD wrapper re-exporting valtio modules without any suspicious behavior.
umd/macro.development.js safe No malicious patterns detected; code is a standard Babel macro for Valtio state management.
umd/macro.production.js safe The file is a legitimate Babel macro for Valtio that transforms useProxy references into useSnapshot calls without any malicious patterns.
umd/macro/vite.development.js safe No malicious patterns detected
umd/macro/vite.production.js safe This is a legitimate Vite plugin macro for valtio that transforms useProxy calls at build time without any malicious patterns.
umd/react.development.js safe No malicious patterns detected; the code is a standard UMD build of the valtio/react integration library with no data exfiltration, credential harvesting, dynamic code execution, or other red flags.
umd/react.production.js safe No malicious patterns detected; the code is a standard React integration for Valtio state management.
umd/react/utils.development.js safe No malicious patterns detected
umd/react/utils.production.js safe No malicious patterns detected
umd/utils.development.js safe No malicious patterns detected; the file is a standard UMD wrapper that re-exports utilities from valtio submodules.
umd/utils.production.js safe The UMD wrapper only re-exports utility modules from valtio without any malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or system manipulation.
umd/vanilla.development.js safe No malicious patterns detected; the code is a legitimate reactive state management library (Valtio vanilla) with no data exfiltration, credential harvesting, dynamic code execution, or suspicious behavior.
umd/vanilla.production.js safe No malicious patterns detected; the code is a legitimate state management library (valtio/vanilla) with no suspicious behavior.
umd/vanilla/utils.development.js safe No malicious patterns detected; the code is a standard UMD bundle of the valtio utility library with no data exfiltration, credential harvesting, obfuscated payloads, process spawning, or suspicious network activity.
umd/vanilla/utils.production.js safe No malicious patterns detected; the code is a standard UMD bundle of valtio/vanilla utilities with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior.
utils.js safe The file is a standard re-export barrel module that aggregates utilities from valtio packages; no malicious patterns detected.
vanilla.js safe The code implements a proxy-based state management library with no malicious patterns, credential access, dynamic code execution, or network/file system abuse.
vanilla/utils.js safe Standard Valtio vanilla utility code; no malicious patterns, exfiltration, obfuscation, or dynamic code execution detected.

Frequently asked questions

Is valtio safe to use?

No confirmed malware was found in valtio@1.13.2, but the review flagged 2 medium, 16 low severity findings for risky patterns worth checking before you rely on it.

Does valtio contain malware?

No malware was identified in valtio@1.13.2 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was valtio checked?

Togoder Security downloaded the published npm package and had an AI model read its 56 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan valtio together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in valtio@1.13.2, cost nothing.

Related security reports