Summary
Togoder Security scanned the npm package xmlhttprequest-ssl@2.1.2 on Oct 4, 2026. An AI review of 1 source file produced 1 high, 3 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 5
Synchronous file read/write via child process spawn
NPS-DC3D79D22FC8
In the synchronous branch of send(), the code builds a JavaScript string with user-controlled data and options and executes it via child_process.spawn with the '-e' flag. Untrusted input in settings.url, headers, or data could break out of the string and lead to arbitrary code execution in the spawned Node process.
File system read outside package scope
NPS-EE4C60DDDAA5
The file:// protocol handler allows reading arbitrary local files via fs.readFile/fs.readFileSync based on the supplied URL, without any path restriction.
Insecure temp file handling
NPS-1FC1B866CF17
The synchronous path writes to predictable filenames (.node-xmlhttprequest-content-<pid> and .node-xmlhttprequest-sync-<pid>) in the current working directory. This can allow symlink attacks or races where another process reads/tampers with content or blocks the busy-wait loop.
Credential handling in spawned process
NPS-E82786EEA9F8
Basic auth credentials (settings.user, settings.password) are serialized into the execString passed to spawn via JSON.stringify(options), exposing credentials in the process command line where they may be visible to other users on the system.
Custom header check bypass
NPS-89EA8F5E15B4
setDisableHeaderCheck() allows callers to disable the forbidden request header check, potentially enabling header injection into requests (e.g., Host, Cookie).
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/XMLHttpRequest.js | medium | This XMLHttpRequest polyfill contains legitimate functionality but includes risky patterns: it spawns a Node child process with dynamically constructed code containing user-influenced data, uses predictable temp files, and exposes a bypass for header restrictions, creating potential for local code execution and credential leakage. |
Frequently asked questions
Is xmlhttprequest-ssl safe to use?
No confirmed malware was found in xmlhttprequest-ssl@2.1.2, but the review flagged 1 high, 3 medium, 1 low severity findings for risky patterns worth checking before you rely on it.
Does xmlhttprequest-ssl contain malware?
No malware was identified in xmlhttprequest-ssl@2.1.2 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was xmlhttprequest-ssl checked?
Togoder Security downloaded the published npm package and had an AI model read its 1 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan xmlhttprequest-ssl together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in xmlhttprequest-ssl@2.1.2, cost nothing.