Summary
Togoder Security scanned the npm package yargs@15.4.1 on Oct 4, 2026. An AI review of 18 source files produced 2 medium, 5 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 7
Dynamic module loading from user-controlled input
NPS-A35BC1EE7308
The function calls require.resolve(config.extends) and require(config.extends) where config.extends is taken from an arbitrary configuration object. If the input is attacker-controlled, this can load arbitrary Node.js modules or execute code from unintended locations. While typical for config extend features (yargs), it represents a code execution surface.
Dynamic module loading
NPS-F180227B97EE
The addDirectory function uses require-directory to dynamically require modules from a directory at runtime. While this is a legitimate yargs feature for loading command modules, it can be abused to load malicious modules if the directory path is attacker-controlled or if the package is installed in an untrusted environment.
File system read outside package scope
NPS-D20D42E832BA
Uses fs.readFileSync(pathToDefault, 'utf8') to read arbitrary JSON/rc files resolved from config.extends. Path traversal or malicious configs could read sensitive files if the path is attacker-controlled, though JSON.parse limits impact.
Path manipulation
NPS-3DAC2526899F
The commandFromFilename function uses path.basename and path.extname to derive command names from filenames. This is standard behavior but could be used to infer module locations when combined with whichModule.
Dynamic code execution
NPS-6899A29E60BA
The builder callback is invoked with a yargs instance, allowing arbitrary code execution when a command is run. This is expected behavior for a command-line parser library, but the callback could contain malicious code if the package is compromised.
environment variable access
NPS-BE3DDF6C9574
Reads process.env.SHELL and process.env.ZSH_NAME to detect the user's shell for completion script generation. This is a benign, common pattern in CLI completion libraries and does not involve credential harvesting or exfiltration.
dynamic function invocation
NPS-E4FC518D1708
Calls a user-supplied completionFunction with parsed argv/current input. The function is registered via registerFunction by the consuming application, not evaluated from strings or external input. No eval, new Function, or dynamic code execution present.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| build/lib/apply-extends.js | medium | Legitimate configuration extension logic, but uses dynamic require/require.resolve and file reads driven by configuration input, which could enable code execution or file disclosure if untrusted configs are supplied. |
| build/lib/command.js | medium | The code appears to be a legitimate implementation of yargs command parsing with standard dynamic module loading and callback execution patterns, but the dynamic require-directory usage and builder callbacks could pose a risk if the package is compromised. |
| build/lib/argsert.js | safe | No malicious patterns detected; the code is a straightforward argument validation utility for yargs with no network, filesystem, process, or dynamic execution activity. |
| build/lib/common-types.js | safe | No malicious patterns detected |
| build/lib/completion-templates.js | safe | Static shell completion template strings for yargs with no executable, network, or exfiltration behavior. |
| build/lib/completion.js | safe | This is a legitimate yargs shell-completion module with no malicious patterns; environment reads and callback invocations are standard and benign. |
| build/lib/is-promise.js | safe | No malicious patterns detected |
| build/lib/levenshtein.js | safe | Cleared by Jev triage; no further analysis needed |
| build/lib/middleware.js | safe | No malicious patterns detected |
| build/lib/obj-filter.js | safe | No malicious patterns detected |
| build/lib/parse-command.js | safe | No malicious patterns detected; the code is a simple command-line argument parser with no network, filesystem, process, or dynamic execution behavior. |
| build/lib/process-argv.js | safe | Cleared by Jev triage; no further analysis needed |
| build/lib/usage.js | safe | No malicious patterns detected; the file is a legitimate yargs usage/help rendering module with no network, credential, obfuscation, or process-spawning behavior. |
| build/lib/validation.js | safe | No malicious patterns detected; the code is a standard argument validation module from the yargs library with no exfiltration, credential harvesting, obfuscation, or unauthorized execution. |
| build/lib/yargs.js | safe | This is the legitimate yargs CLI argument parsing library; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or backdoors were detected. |
| build/lib/yerror.js | safe | No malicious patterns detected |
| index.js | safe | No malicious patterns detected; the code is a standard yargs singleton wrapper with no suspicious behavior. |
| yargs.js | safe | No malicious patterns detected |
Affected version ranges
None of the 3 scanned versions of yargs are flagged high or critical. The latest scanned version, 18.0.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 18.0.0 | Needs review | 1 | 18.0.0 | Dynamic module loading with external input; File system access |
| 17.7.2 – 17.7.3 | Not scanned | 2 | >=17.7.2 <=17.7.3 | |
| 15.4.1 – 16.2.0 | Needs review | 2 | >=15.4.1 <=16.2.0 | dynamic module loading from external URL; Dynamic module loading from user-controlled input |
| 7.1.2 | Not scanned | 1 | 7.1.2 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of yargs
Frequently asked questions
Is yargs safe to use?
No confirmed malware was found in yargs@15.4.1, but the review flagged 2 medium, 5 low severity findings for risky patterns worth checking before you rely on it.
Does yargs contain malware?
No malware was identified in yargs@15.4.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was yargs checked?
Togoder Security downloaded the published npm package and had an AI model read its 18 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan yargs together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in yargs@15.4.1, cost nothing.