# web-worker@1.2.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:25:20.000Z
- Files reviewed: 4
- Findings: 5 medium, 3 low severity findings
- Report: https://security.togoder.click/npm/web-worker
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package web-worker@1.2.0 on Oct 6, 2026. An AI review of 4 source files produced 5 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic module loading with computed input

Finding ID: `NPS-8A1A4D6BCB08`

File: `cjs/node.js:198`

The workerThread function calls import(mod) and require(mod) where 'mod' comes from threads.workerData. If an attacker can influence the worker URL passed to the Worker constructor, they could load arbitrary modules or execute code from external locations.

### [medium] Dynamic code execution

Finding ID: `NPS-25B9555A330B`

File: `cjs/node.js:214`

The evaluateDataUrl function uses VM.runInThisContext to execute arbitrary JavaScript from data: URLs. While intended for Web Worker compatibility, this pattern allows code execution if an attacker can control the worker URL, and data: URLs are treated as trusted input without sandboxing.

### [medium] Dynamic module loading with computed input

Finding ID: `NPS-D1CCEFFBCFF8`

File: `node.js:185`

The workerThread function uses dynamic import(mod) and require(mod) where mod is derived from workerData. If an attacker can influence the worker URL, they could load and execute arbitrary modules or code.

### [medium] Dynamic code execution

Finding ID: `NPS-866FBD08E55D`

File: `node.js:222`

The evaluateDataUrl function uses VM.runInThisContext to execute arbitrary JavaScript code from a data URL. This allows execution of any code supplied in a data: URL, which can be abused if an attacker can control the worker URL. While this is part of the intended Web Worker polyfill, it still represents a dynamic code execution surface.

### [medium] Potential data URL code execution

Finding ID: `NPS-994D477545B9`

File: `node.js:222`

The parseDataUrl and evaluateDataUrl functions decode and execute base64-encoded JavaScript from a data URL. This could be used to run obfuscated payloads if the URL is attacker-controlled.

### [low] File system path resolution

Finding ID: `NPS-FEB1A700638C`

File: `cjs/node.js:108`

The baseUrl is derived from process.cwd() and used to resolve worker module paths. Depending on the working directory, this could allow loading modules from unintended locations if relative paths are used.

### [low] Environment/global object manipulation

Finding ID: `NPS-33CCE63985E5`

File: `cjs/node.js:176`

The code modifies the global object prototype and binds core functions (postMessage, addEventListener, etc.) to the global scope. This could interfere with other modules and potentially be exploited if combined with other vulnerabilities.

### [low] Top-level code execution on import

Finding ID: `NPS-A95E3209F44F`

File: `node.js:92`

The module executes code at import time, including determining whether it is the main thread or worker thread and constructing the base URL from process.cwd(). This is typical for this polyfill but still means side effects occur upon import.

## Files reviewed

- `cjs/node.js` (medium): This is a legitimate Google Web Worker polyfill for Node.js, but it contains dynamic code execution via VM.runInThisContext and dynamic module loading that could be risky if worker URLs are attacker-controlled.
- `node.js` (medium): The code is a legitimate Web Worker polyfill for Node.js that uses dynamic code execution and module loading, which are inherent to its functionality but could pose security risks if worker URLs are attacker-controlled.
- `browser.js` (safe): Cleared by Jev triage; no further analysis needed
- `cjs/browser.js` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
