Summary
Togoder Security scanned the npm package valtio@1.13.2 on Oct 4, 2026. An AI review of 56 source files produced 2 medium, 16 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 18
Devtools extension communication
NPS-F5AC79ACCC11
The devtools function connects to the Redux DevTools browser extension and processes messages including ACTION and DISPATCH types. It parses JSON payloads from the extension (JSON.parse) and applies them to the proxy object via Object.assign. While this is intended for debugging, it could allow arbitrary state manipulation if the extension or its messages are compromised. However, this is a known and documented feature of Valtio and not a malicious pattern per se.
Suspicious package name pattern (typosquatting/lookalike)
NPS-EB53F411846D
The dependency 'aslemammad-vite-plugin-macro' appears to be a personal-scoped or lookalike package name resembling 'vite-plugin-macro'. Such naming patterns are frequently used in dependency confusion or typosquatting attacks and warrant manual verification of the package's provenance.
Deprecated package warning
NPS-001D3B9ED853
The code warns that 'useProxy' is deprecated and suggests using 'useSnapshot' instead, indicating potential maintenance concerns but not malicious behavior.
Babel macro manipulation
NPS-2AA92AB0BC6D
The code uses Babel macros to transform code at build time, which is a legitimate but powerful capability that could be misused. However, the transformation is limited to replacing 'useProxy' calls with 'useSnapshot' from 'valtio'.
Dynamic code transform (Babel macro)
NPS-573C08E1B841
The macro performs AST transformations using Babel, replacing identifiers and generating code. While legitimate for a macro library, this mechanism could be abused to inject code if the input is attacker-controlled, though no such input handling is present here.
Development-only warning
NPS-03BCF5528471
Accesses import.meta.env.MODE to conditionally warn about deprecation. Environment variable access here is limited to build mode detection and does not exfiltrate or harvest sensitive data.
Import-time side effect
NPS-32B8633467E8
The module instantiates the macro plugin and calls provideValtioMacro() at import time, which emits a console.warn message. This is a benign side effect but still executes code upon import.
Dynamic code execution
NPS-C766353DA2C5
The code does not use eval, Function constructor, or similar dynamic code execution mechanisms. The only parsing is JSON.parse on devtools messages and JSON.stringify in devtools send; these are data serialization, not code execution.
Network and filesystem access
NPS-13C745FC4703
There are no outbound network requests, filesystem operations, or process spawning. The code operates entirely on in-memory proxy objects and interacts with the optional Redux DevTools extension via window.__REDUX_DEVTOOLS_EXTENSION__.
Deprecated code warning
NPS-EB618B9E52D9
The macro logs a deprecation warning suggesting to use a different hook. This is not malicious, but indicates outdated code.
AST manipulation
NPS-107D2A02FEBC
The macro uses Babel's AST manipulation to transform code, including injecting a snapshot variable and replacing identifiers. While this is expected for a Babel macro, it modifies code structure at compile time. No malicious patterns are present.
AST transformation of identifiers
NPS-476A3DFA6E04
The macro rewrites Identifier nodes in the parent function scope when their name matches the proxy object, renaming them to the generated snapshot variable. While this is the intended functionality of the macro, it performs code transformation on the consumer's source tree and could be abused to silently alter behavior in ways the developer may not expect.
Top-level execution on import
NPS-C0265989185C
Module-level code executes at import time, including defineMacro, defineMacroProvider, createMacroPlugin, and createMacroPlugin({}).use(provideValtioMacro()). Although this is consistent with a Babel macro plugin, it demonstrates that importing the module triggers immediate execution of third-party plugin code.
Redux DevTools Extension Integration with External Message Handling
NPS-6795FFBDB7BC
The devtools() function connects to the browser's Redux DevTools extension (window.__REDUX_DEVTOOLS_EXTENSION__) and accepts external messages to modify proxy state via Object.assign(proxyObject, JSON.parse(message.payload)) and Object.assign(proxyObject, state). While this is standard Redux DevTools protocol behavior for state time-travel debugging, it allows any code/extension with access to the DevTools channel to inject arbitrary state into the proxy object, which could be used for prototype pollution or state manipulation in applications that trust proxied state.
Dynamic code execution via JSON.parse on external input
NPS-429055373CC4
The devtools() function calls JSON.parse(message.payload) and JSON.parse(message.state) on data received from the Redux DevTools extension, then applies the parsed result directly to the proxy object. This is not eval/Function but is dynamic input handling from an external source; malformed or malicious DevTools messages could cause unexpected behavior in the consuming application.
Unsupported use of process.env at runtime
NPS-5784D26636FB
The code references process.env.NODE_ENV only for development warnings; no environment variable harvesting or external data exfiltration occurs.
devtools extension integration
NPS-D7A36912B48A
devtools() connects to the Redux DevTools browser extension via window.__REDUX_DEVTOOLS_EXTENSION__ if present. This is intentional Valtio functionality, not exfiltration.
deprecated API usage
NPS-E7C23F56869E
Uses deprecated Valtio APIs (addComputed, proxyWithComputed, proxyWithHistory) that log console warnings but are not malicious.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| esm/macro/vite.js | medium | The code is a legitimate Vite plugin macro for Valtio state management, with no malicious patterns detected. |
| esm/macro/vite.mjs | medium | The code appears to be a legitimate Babel macro plugin with no malicious patterns such as data exfiltration, credential harvesting, or shell execution, though it does run code at import time. |
| esm/vanilla/utils.mjs | medium | This is standard Valtio utility code with no malicious patterns; the only concern is the optional Redux DevTools integration that accepts JSON messages from a browser extension, which is expected behavior for debugging tools. |
| system/macro/vite.development.js | medium | No explicit exfiltration, shell execution, or credential harvesting is present, but the code relies on an untrusted, oddly named third-party package and performs AST rewriting at import time, warranting caution. |
| system/vanilla/utils.development.js | medium | This is the legitimate Valtio state management library with no malicious patterns; only standard Redux DevTools integration for state debugging is present, which involves external message handling but is expected behavior for this library. |
| esm/index.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/index.mjs | safe | Cleared by Jev triage; no further analysis needed |
| esm/macro.js | safe | This is a legitimate babel-plugin-macros macro from the Valtio state management library that performs AST transformations and does not contain any malicious patterns. |
| esm/macro.mjs | safe | No malicious patterns detected; this is a legitimate babel-plugin-macros macro for the valtio library that transforms useProxy calls to useSnapshot at build time. |
| esm/react.js | safe | No malicious patterns detected; the code is a legitimate React integration for Valtio state management. |
| esm/react.mjs | safe | No malicious patterns detected; the code is a standard React hook implementation for valtio state management with no suspicious behavior. |
| esm/react/utils.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/react/utils.mjs | safe | Cleared by Jev triage; no further analysis needed |
| esm/utils.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/utils.mjs | safe | Cleared by Jev triage; no further analysis needed |
| esm/vanilla.js | safe | No malicious patterns detected; this is the legitimate proxy-compare/valtio library implementing reactive proxy state management without any security concerns. |
| esm/vanilla.mjs | safe | No malicious patterns detected; the code is a legitimate proxy state management library with no data exfiltration, credential harvesting, obfuscation, or unauthorized network/file/process operations. |
| esm/vanilla/utils.js | safe | No malicious patterns detected in the provided Valtio utilities code; it contains standard state management helpers with no exfiltration, obfuscation, process spawning, or dynamic code execution. |
| index.js | safe | No malicious patterns detected |
| macro.js | safe | No malicious patterns detected; this is a legitimate Babel macro for Valtio's useProxy hook with standard AST transformation logic and no exfiltration, credential harvesting, or dynamic execution. |
| macro/vite.js | safe | No malicious patterns detected |
| react.js | safe | No malicious patterns detected |
| react/utils.js | safe | No malicious patterns detected |
| system/index.development.js | safe | No malicious patterns detected; the code is a standard SystemJS module wrapper that re-exports members from 'valtio/vanilla' and 'valtio/react' without any suspicious behavior. |
| system/index.production.js | safe | The file is a standard System.register module wrapper for re-exporting valtio/vanilla and valtio/react; it contains no network, filesystem, process, or dynamic code execution behavior. |
Show 31 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| system/macro.development.js | safe | The code is a legitimate Babel macro for Valtio that performs AST transformations and logs a deprecation warning; no malicious patterns were detected. |
| system/macro.production.js | safe | The code is a legitimate Babel macro that transforms useProxy calls for Valtio, with no malicious patterns such as data exfiltration, credential harvesting, or dynamic code execution. |
| system/macro/vite.production.js | safe | No malicious patterns detected |
| system/react.development.js | safe | No malicious patterns detected; the code is a legitimate React hook implementation for Valtio state management. |
| system/react.production.js | safe | No malicious patterns detected; the code is a legitimate React hook (useSnapshot) for Valtio state management using proxy-compare and useSyncExternalStore. |
| system/react/utils.development.js | safe | No malicious patterns detected |
| system/react/utils.production.js | safe | No malicious patterns detected; the code is a minified React hook for Valtio proxy state access without any exfiltration, obfuscation, or system-level operations. |
| system/utils.development.js | safe | No malicious patterns detected |
| system/utils.production.js | safe | No malicious patterns detected; the code is a standard SystemJS module re-exporting valtio utilities without suspicious behavior. |
| system/vanilla.development.js | safe | No malicious patterns detected; the code is a legitimate proxy state management library with no data exfiltration, credential harvesting, obfuscation, or suspicious runtime behavior. |
| system/vanilla.production.js | safe | No malicious patterns detected; the code is a minified JavaScript proxy/snapshot utility using standard reactivity patterns without network, filesystem, or process manipulation. |
| system/vanilla/utils.production.js | safe | No malicious patterns detected; this is a minified but legitimate Valtio state-management library utility file. |
| umd/index.development.js | safe | No malicious patterns detected |
| umd/index.production.js | safe | No malicious patterns detected; the file is a standard UMD wrapper re-exporting valtio modules without any suspicious behavior. |
| umd/macro.development.js | safe | No malicious patterns detected; code is a standard Babel macro for Valtio state management. |
| umd/macro.production.js | safe | The file is a legitimate Babel macro for Valtio that transforms useProxy references into useSnapshot calls without any malicious patterns. |
| umd/macro/vite.development.js | safe | No malicious patterns detected |
| umd/macro/vite.production.js | safe | This is a legitimate Vite plugin macro for valtio that transforms useProxy calls at build time without any malicious patterns. |
| umd/react.development.js | safe | No malicious patterns detected; the code is a standard UMD build of the valtio/react integration library with no data exfiltration, credential harvesting, dynamic code execution, or other red flags. |
| umd/react.production.js | safe | No malicious patterns detected; the code is a standard React integration for Valtio state management. |
| umd/react/utils.development.js | safe | No malicious patterns detected |
| umd/react/utils.production.js | safe | No malicious patterns detected |
| umd/utils.development.js | safe | No malicious patterns detected; the file is a standard UMD wrapper that re-exports utilities from valtio submodules. |
| umd/utils.production.js | safe | The UMD wrapper only re-exports utility modules from valtio without any malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or system manipulation. |
| umd/vanilla.development.js | safe | No malicious patterns detected; the code is a legitimate reactive state management library (Valtio vanilla) with no data exfiltration, credential harvesting, dynamic code execution, or suspicious behavior. |
| umd/vanilla.production.js | safe | No malicious patterns detected; the code is a legitimate state management library (valtio/vanilla) with no suspicious behavior. |
| umd/vanilla/utils.development.js | safe | No malicious patterns detected; the code is a standard UMD bundle of the valtio utility library with no data exfiltration, credential harvesting, obfuscated payloads, process spawning, or suspicious network activity. |
| umd/vanilla/utils.production.js | safe | No malicious patterns detected; the code is a standard UMD bundle of valtio/vanilla utilities with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior. |
| utils.js | safe | The file is a standard re-export barrel module that aggregates utilities from valtio packages; no malicious patterns detected. |
| vanilla.js | safe | The code implements a proxy-based state management library with no malicious patterns, credential access, dynamic code execution, or network/file system abuse. |
| vanilla/utils.js | safe | Standard Valtio vanilla utility code; no malicious patterns, exfiltration, obfuscation, or dynamic code execution detected. |
Frequently asked questions
Is valtio safe to use?
No confirmed malware was found in valtio@1.13.2, but the review flagged 2 medium, 16 low severity findings for risky patterns worth checking before you rely on it.
Does valtio contain malware?
No malware was identified in valtio@1.13.2 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was valtio checked?
Togoder Security downloaded the published npm package and had an AI model read its 56 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan valtio together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in valtio@1.13.2, cost nothing.