Togoder security

npm package security report

yargs@15.4.1 security report

Risky patterns found that deserve a look.

Needs review Version 15.4.1 Files reviewed 18 Size 121.3 KB Scanned

Summary

Togoder Security scanned the npm package yargs@15.4.1 on Oct 4, 2026. An AI review of 18 source files produced 2 medium, 5 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
5
low

Findings 7

medium

Dynamic module loading from user-controlled input

NPS-A35BC1EE7308

The function calls require.resolve(config.extends) and require(config.extends) where config.extends is taken from an arbitrary configuration object. If the input is attacker-controlled, this can load arbitrary Node.js modules or execute code from unintended locations. While typical for config extend features (yargs), it represents a code execution surface.

build/lib/apply-extends.js:42
medium

Dynamic module loading

NPS-F180227B97EE

The addDirectory function uses require-directory to dynamically require modules from a directory at runtime. While this is a legitimate yargs feature for loading command modules, it can be abused to load malicious modules if the directory path is attacker-controlled or if the package is installed in an untrusted environment.

build/lib/command.js:110
low

File system read outside package scope

NPS-D20D42E832BA

Uses fs.readFileSync(pathToDefault, 'utf8') to read arbitrary JSON/rc files resolved from config.extends. Path traversal or malicious configs could read sensitive files if the path is attacker-controlled, though JSON.parse limits impact.

build/lib/apply-extends.js:63
low

Path manipulation

NPS-3DAC2526899F

The commandFromFilename function uses path.basename and path.extname to derive command names from filenames. This is standard behavior but could be used to infer module locations when combined with whichModule.

build/lib/command.js:122
low

Dynamic code execution

NPS-6899A29E60BA

The builder callback is invoked with a yargs instance, allowing arbitrary code execution when a command is run. This is expected behavior for a command-line parser library, but the callback could contain malicious code if the package is compromised.

build/lib/command.js:213
low

environment variable access

NPS-BE3DDF6C9574

Reads process.env.SHELL and process.env.ZSH_NAME to detect the user's shell for completion script generation. This is a benign, common pattern in CLI completion libraries and does not involve credential harvesting or exfiltration.

build/lib/completion.js:26
low

dynamic function invocation

NPS-E4FC518D1708

Calls a user-supplied completionFunction with parsed argv/current input. The function is registered via registerFunction by the consuming application, not evaluated from strings or external input. No eval, new Function, or dynamic code execution present.

build/lib/completion.js:39

Files reviewed

FileVerdictWhat the reviewer saw
build/lib/apply-extends.js medium Legitimate configuration extension logic, but uses dynamic require/require.resolve and file reads driven by configuration input, which could enable code execution or file disclosure if untrusted configs are supplied.
build/lib/command.js medium The code appears to be a legitimate implementation of yargs command parsing with standard dynamic module loading and callback execution patterns, but the dynamic require-directory usage and builder callbacks could pose a risk if the package is compromised.
build/lib/argsert.js safe No malicious patterns detected; the code is a straightforward argument validation utility for yargs with no network, filesystem, process, or dynamic execution activity.
build/lib/common-types.js safe No malicious patterns detected
build/lib/completion-templates.js safe Static shell completion template strings for yargs with no executable, network, or exfiltration behavior.
build/lib/completion.js safe This is a legitimate yargs shell-completion module with no malicious patterns; environment reads and callback invocations are standard and benign.
build/lib/is-promise.js safe No malicious patterns detected
build/lib/levenshtein.js safe Cleared by Jev triage; no further analysis needed
build/lib/middleware.js safe No malicious patterns detected
build/lib/obj-filter.js safe No malicious patterns detected
build/lib/parse-command.js safe No malicious patterns detected; the code is a simple command-line argument parser with no network, filesystem, process, or dynamic execution behavior.
build/lib/process-argv.js safe Cleared by Jev triage; no further analysis needed
build/lib/usage.js safe No malicious patterns detected; the file is a legitimate yargs usage/help rendering module with no network, credential, obfuscation, or process-spawning behavior.
build/lib/validation.js safe No malicious patterns detected; the code is a standard argument validation module from the yargs library with no exfiltration, credential harvesting, obfuscation, or unauthorized execution.
build/lib/yargs.js safe This is the legitimate yargs CLI argument parsing library; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or backdoors were detected.
build/lib/yerror.js safe No malicious patterns detected
index.js safe No malicious patterns detected; the code is a standard yargs singleton wrapper with no suspicious behavior.
yargs.js safe No malicious patterns detected

Affected version ranges

None of the 3 scanned versions of yargs are flagged high or critical. The latest scanned version, 18.0.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

7.1.218.0.0
VersionsVerdictCountRangeTop findings
18.0.0 Needs review 1 18.0.0 Dynamic module loading with external input; File system access
17.7.2 – 17.7.3 Not scanned 2 >=17.7.2 <=17.7.3
15.4.1 – 16.2.0 Needs review 2 >=15.4.1 <=16.2.0 dynamic module loading from external URL; Dynamic module loading from user-controlled input
7.1.2 Not scanned 1 7.1.2

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of yargs

VersionVerdictFilesScanned
18.0.0 Needs review 25 Oct 6, 2026
16.2.0 Needs review 26 Oct 6, 2026
15.4.1 Needs review 18 Oct 4, 2026

Frequently asked questions

Is yargs safe to use?

No confirmed malware was found in yargs@15.4.1, but the review flagged 2 medium, 5 low severity findings for risky patterns worth checking before you rely on it.

Does yargs contain malware?

No malware was identified in yargs@15.4.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was yargs checked?

Togoder Security downloaded the published npm package and had an AI model read its 18 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan yargs together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in yargs@15.4.1, cost nothing.

Related security reports