Togoder security

npm package security report

yargs@16.2.0 security report

Risky patterns found that deserve a look.

Needs review Version 16.2.0 Files reviewed 26 Size 215.8 KB Scanned

Summary

Togoder Security scanned the npm package yargs@16.2.0 on Oct 6, 2026. An AI review of 26 source files produced 1 high, 4 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
1
high
4
medium
1
low

Findings 6

high

dynamic module loading from external URL

NPS-DD5FE9F9BBD7

The file imports modules directly from 'https://unpkg.com/...' (cliui and yargs-parser). This bypasses the package registry and relies on a third-party CDN at runtime. If the CDN is compromised or the URL is tampered with, arbitrary malicious code could be injected. This is a supply chain risk and also violates typical package integrity expectations.

lib/platform-shims/browser.mjs:3
medium

Dynamic require with computed input

NPS-DE8B7F7C6CCC

The code calls require.resolve(config.extends) and require(config.extends) where config.extends comes from an external configuration file. If an attacker can control the config file contents, they could load arbitrary modules. While this is a legitimate feature of the 'extends' mechanism, it represents a dynamic module loading path that could be abused if untrusted configuration is processed.

build/lib/utils/apply-extends.js:12
medium

File system read outside package scope

NPS-8ADE78B0E880

The function reads configuration files from arbitrary paths resolved relative to cwd via shim.readFileSync(pathToDefault, 'utf8'). An attacker controlling the 'extends' value could read arbitrary JSON/rc files on the filesystem.

build/lib/utils/apply-extends.js:22
medium

top-level import execution

NPS-1ACA70913B85

Imports from external URLs execute code at module load time. This code runs on import without explicit user action, which could be leveraged for malicious purposes if the remote content is malicious or altered.

lib/platform-shims/browser.mjs:3
medium

external dependency version pinning via URL

NPS-6B360ABD1A64

The imports use unpinned or CDN-hosted versions (e.g., unpkg.com/cliui@7.0.1). While versioned, the CDN could serve different content than the original npm package, and there is no integrity verification (e.g., SRI hash). This increases risk of tampering.

lib/platform-shims/browser.mjs:3
low

Dynamic command execution via callback

NPS-613632492F83

The code invokes user-provided completion functions and command builders via completionFunction(current, argv) and builder(y). This is expected behavior for a CLI completion library and does not represent a vulnerability, as the callbacks are supplied by the application using yargs, not from attacker-controlled input.

build/lib/completion.js

Files reviewed

FileVerdictWhat the reviewer saw
build/lib/utils/apply-extends.js medium The code implements a legitimate config 'extends' feature but uses dynamic require and arbitrary file reads that could be abused if untrusted configuration input is processed.
lib/platform-shims/browser.mjs medium The file contains no overt malicious behavior but uses dynamic imports from an external CDN at runtime, introducing supply chain and code integrity risks.
browser.mjs safe No malicious patterns detected; the file is a standard yargs browser bootstrap with static imports and no dynamic or external code execution.
build/lib/argsert.js safe Cleared by Jev triage; no further analysis needed
build/lib/command.js safe No malicious patterns detected; the file contains standard command handling logic for the yargs argument parser library.
build/lib/completion-templates.js safe The file contains only template strings for generating shell completion scripts for yargs, with no executable code, network calls, or credential access.
build/lib/completion.js safe The file is part of the yargs CLI parsing library and implements shell completion logic without any data exfiltration, credential harvesting, obfuscated payloads, or other malicious patterns.
build/lib/middleware.js safe No malicious patterns detected
build/lib/parse-command.js safe No malicious patterns detected
build/lib/typings/common-types.js safe Cleared by Jev triage; no further analysis needed
build/lib/typings/yargs-parser-types.js safe Cleared by Jev triage; no further analysis needed
build/lib/usage.js safe No malicious patterns detected; this is the standard yargs usage/help formatting module with no exfiltration, credential harvesting, obfuscation, or process/network activity.
build/lib/utils/is-promise.js safe Cleared by Jev triage; no further analysis needed
build/lib/utils/levenshtein.js safe Cleared by Jev triage; no further analysis needed
build/lib/utils/obj-filter.js safe Cleared by Jev triage; no further analysis needed
build/lib/utils/process-argv.js safe Cleared by Jev triage; no further analysis needed
build/lib/utils/set-blocking.js safe No malicious patterns detected
build/lib/utils/which-module.js safe Cleared by Jev triage; no further analysis needed
build/lib/validation.js safe No malicious patterns detected; the file contains standard yargs argument validation logic without exfiltration, code execution, or suspicious behavior.
build/lib/yargs-factory.js safe No malicious patterns detected; the code is the standard yargs command-line parser factory with expected option handling and no exfiltration, credential harvesting, or dynamic code execution.
build/lib/yerror.js safe Cleared by Jev triage; no further analysis needed
helpers/helpers.mjs safe Cleared by Jev triage; no further analysis needed
helpers/index.js safe Cleared by Jev triage; no further analysis needed
index.cjs safe The code is a standard yargs entry point that initializes the CLI parser, exposes a singleton API, and contains no obfuscation, exfiltration, credential harvesting, or other malicious patterns.
index.mjs safe No malicious patterns detected
Show 1 more file
FileVerdictWhat the reviewer saw
lib/platform-shims/esm.mjs safe No malicious patterns detected; the file is a legitimate ESM platform shim for yargs with no suspicious network, filesystem, or execution behavior.

Affected version ranges

None of the 3 scanned versions of yargs are flagged high or critical. The latest scanned version, 18.0.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

7.1.218.0.0
VersionsVerdictCountRangeTop findings
18.0.0 Needs review 1 18.0.0 Dynamic module loading with external input; File system access
17.7.2 – 17.7.3 Not scanned 2 >=17.7.2 <=17.7.3
15.4.1 – 16.2.0 Needs review 2 >=15.4.1 <=16.2.0 dynamic module loading from external URL; Dynamic module loading from user-controlled input
7.1.2 Not scanned 1 7.1.2

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of yargs

VersionVerdictFilesScanned
18.0.0 Needs review 25 Oct 6, 2026
16.2.0 Needs review 26 Oct 6, 2026
15.4.1 Needs review 18 Oct 4, 2026

Frequently asked questions

Is yargs safe to use?

No confirmed malware was found in yargs@16.2.0, but the review flagged 1 high, 4 medium, 1 low severity findings for risky patterns worth checking before you rely on it.

Does yargs contain malware?

No malware was identified in yargs@16.2.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was yargs checked?

Togoder Security downloaded the published npm package and had an AI model read its 26 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan yargs together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in yargs@16.2.0, cost nothing.

Related security reports