Togoder security

npm package security report

xmlhttprequest-ssl npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 2.1.2 Files reviewed 1 Size 20.0 KB Scanned

Summary

Togoder Security scanned the npm package xmlhttprequest-ssl@2.1.2 on Oct 4, 2026. An AI review of 1 source file produced 1 high, 3 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
1
high
3
medium
1
low

Findings 5

high

Synchronous file read/write via child process spawn

NPS-DC3D79D22FC8

In the synchronous branch of send(), the code builds a JavaScript string with user-controlled data and options and executes it via child_process.spawn with the '-e' flag. Untrusted input in settings.url, headers, or data could break out of the string and lead to arbitrary code execution in the spawned Node process.

lib/XMLHttpRequest.js:478
medium

File system read outside package scope

NPS-EE4C60DDDAA5

The file:// protocol handler allows reading arbitrary local files via fs.readFile/fs.readFileSync based on the supplied URL, without any path restriction.

lib/XMLHttpRequest.js:260
medium

Insecure temp file handling

NPS-1FC1B866CF17

The synchronous path writes to predictable filenames (.node-xmlhttprequest-content-<pid> and .node-xmlhttprequest-sync-<pid>) in the current working directory. This can allow symlink attacks or races where another process reads/tampers with content or blocks the busy-wait loop.

lib/XMLHttpRequest.js:472
medium

Credential handling in spawned process

NPS-E82786EEA9F8

Basic auth credentials (settings.user, settings.password) are serialized into the execString passed to spawn via JSON.stringify(options), exposing credentials in the process command line where they may be visible to other users on the system.

lib/XMLHttpRequest.js:478
low

Custom header check bypass

NPS-89EA8F5E15B4

setDisableHeaderCheck() allows callers to disable the forbidden request header check, potentially enabling header injection into requests (e.g., Host, Cookie).

lib/XMLHttpRequest.js:168

Files reviewed

FileVerdictWhat the reviewer saw
lib/XMLHttpRequest.js medium This XMLHttpRequest polyfill contains legitimate functionality but includes risky patterns: it spawns a Node child process with dynamically constructed code containing user-influenced data, uses predictable temp files, and exposes a bypass for header restrictions, creating potential for local code execution and credential leakage.

Scanned versions of xmlhttprequest-ssl

VersionVerdictFilesScanned
2.1.2 Needs review 1 Oct 4, 2026

Frequently asked questions

Is xmlhttprequest-ssl safe to use?

No confirmed malware was found in xmlhttprequest-ssl@2.1.2, but the review flagged 1 high, 3 medium, 1 low severity findings for risky patterns worth checking before you rely on it.

Does xmlhttprequest-ssl contain malware?

No malware was identified in xmlhttprequest-ssl@2.1.2 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was xmlhttprequest-ssl checked?

Togoder Security downloaded the published npm package and had an AI model read its 1 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan xmlhttprequest-ssl together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in xmlhttprequest-ssl@2.1.2, cost nothing.

Related security reports