Summary
Togoder Security scanned the npm package zod@3.25.76 on Oct 4, 2026. An AI review of 271 source files produced 1 high, 2 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 11
Dynamic code execution
NPS-EB9A0FECE2ED
The compile() method retrieves the Function constructor indirectly via const F = Function; and invokes it via new F(...args, lines.join("\n")). This builds a new function from dynamically assembled source code (args and content), which is functionally equivalent to eval/new Function. If args or content can ever be influenced by untrusted input (e.g., user data, remote config, environment-derived strings), this becomes an arbitrary code execution sink. The indirect assignment is a mild obfuscation pattern that can evade naive static scanners looking only for the literal new Function(...).
Dynamic code execution via Function constructor
NPS-5CD1785B0ABA
The compile() method uses new Function(...args, ...) to dynamically construct a JavaScript function from strings. While this appears to be a legitimate code-generation utility (similar to the tsup/esbuild/esrap Doc pattern used by tools like dedent/magic-string), the ability to compile arbitrary strings into executable functions is inherently dangerous if args or content ever derive from untrusted input. It is not obfuscated and no encoded payload is present, but it is a dynamic-code-execution primitive that should be flagged.
Dynamic code execution
NPS-1E85D0FE4531
The compile() method uses the Function constructor to dynamically compile and execute arbitrary code from the args and content properties. This can lead to code injection if untrusted input reaches these fields, effectively behaving like eval.
Dual sync/async execution of caller-supplied function
NPS-E949D5582ADD
In write(arg), if arg is a function it is invoked twice: once with { execution: "sync" } and once with { execution: "async" }. This pattern mirrors documented magicast/ast-types-style code generation usage, but invoking a callback twice with the same Doc instance and different flags is a control-flow oddity worth reviewing: a callback that mutates this.content non-idempotently can duplicate or corrupt generated code, and the async pass suggests execution paths not fully visible in this file.
Dynamic Code Execution
NPS-C84285437DA7
The code uses doc.compile() which invokes new Function() internally to generate optimized parsing functions for Zod object schemas (JIT compilation). This is a legitimate performance optimization feature of Zod, guarded by allowsEval.value which checks if eval is permitted. The generated code is constructed from internally controlled schema definitions, not from user input.
Potential Prototype Pollution Protection
NPS-45FCBDA0E101
The $ZodRecord parser explicitly skips the __proto__ key (if (key === "__proto__") continue;), demonstrating defensive coding against prototype pollution. No malicious exploitation patterns present.
dynamic code generation
NPS-54A33C3EAADC
The code uses doc.compile() in generateFastpass to generate and execute JavaScript code dynamically at runtime for performance optimization. While this is part of Zod's JIT compilation feature and not inherently malicious, it is a form of dynamic code execution that could be abused if inputs were attacker-controlled. The generated code is based on schema shape keys and uses util.esc() for escaping, reducing risk.
use of eval-like behavior
NPS-6FDDA83DBFF7
The Doc class from ./doc.js is used to compile a function from a string. This is effectively an eval-like mechanism. In this context it is used for performance optimization of object parsing, and the generated code is derived from schema definitions rather than user input. However, it still represents a dynamic code execution surface.
eval usage
NPS-5F38D0CC7BAA
The allowsEval function uses new Function("") to test if eval is allowed. This is a common pattern in libraries to feature-detect CSP restrictions rather than to execute malicious code. No user-controlled input is passed to the Function constructor.
Static locale/error message definitions
NPS-42407B8B68AE
The file only contains Hebrew translation strings for validation library error messages. There is no network access, file system access, environment variable reading, or process spawning.
Standard TypeScript/CommonJS interop boilerplate
NPS-4D52083301E7
The __createBinding, __setModuleDefault, and __importStar helpers are standard TypeScript compiler-generated code for interop. No obfuscation, eval, or dynamic code execution is present.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| src/v4/core/doc.ts | medium | A code-generation helper that uses new Function to compile generated source strings; no exfiltration, credential harvesting, network calls, process spawning, or install-time execution was found, but the dynamic-eval primitive warrants a warning. |
| v4/core/doc.cjs | medium | File contains dynamic function construction via the Function constructor with assembled source and an unusual dual sync/async callback invocation, but no network, filesystem, environment harvesting, or process-spawning behavior was observed. |
| v4/core/doc.js | medium | The file uses dynamic code generation via the Function constructor, which is a potential code injection risk, but no other malicious patterns were detected. |
| v4/core/schemas.js | medium | The code is legitimate Zod schema validation logic with a JIT compilation feature that dynamically generates functions; no malicious patterns such as data exfiltration, credential harvesting, or backdoors were detected. |
| index.cjs | safe | No malicious patterns detected; the file contains only standard TypeScript/CommonJS interoperability helpers and re-exports from a local module. |
| index.js | safe | Cleared by Jev triage; no further analysis needed |
| src/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/ZodError.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/benchmarks/datetime.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/benchmarks/discriminatedUnion.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/benchmarks/index.ts | safe | No malicious patterns detected; the file is a standard benchmark runner that reads CLI arguments and runs in-memory benchmarks without network, filesystem, or process-spawning operations. |
| src/v3/benchmarks/ipv4.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/benchmarks/object.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/benchmarks/primitives.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/benchmarks/realworld.ts | safe | No malicious patterns detected; the code is a standard Zod validation benchmark with no network, filesystem, process, or obfuscated behavior. |
| src/v3/benchmarks/string.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/benchmarks/union.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/errors.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/external.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/helpers/enumUtil.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/helpers/errorUtil.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/helpers/parseUtil.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/helpers/partialUtil.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/helpers/typeAliases.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/helpers/util.ts | safe | Cleared by Jev triage; no further analysis needed |
Show 246 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| src/v3/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/locales/en.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v3/standard-schema.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4-mini/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/classic/checks.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/classic/coerce.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/classic/compat.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/classic/errors.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/classic/external.ts | safe | This is a standard Zod v4 re-export module that only re-exports types and functions from internal modules; no malicious patterns detected. |
| src/v4/classic/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/classic/iso.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/classic/parse.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/classic/schemas.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/core/api.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/core/checks.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/core/config.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/core/core.ts | safe | No malicious patterns detected; the code is a legitimate Zod schema constructor utility with no network, filesystem, process, or dynamic code execution concerns. |
| src/v4/core/errors.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/core/function.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/core/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/core/json-schema.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/core/parse.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/core/regexes.ts | safe | No malicious patterns detected |
| src/v4/core/registries.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/core/standard-schema.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/core/to-json-schema.ts | safe | No malicious patterns detected; the code is a legitimate JSON Schema generator for Zod with no network, filesystem, process execution, or obfuscation concerns. |
| src/v4/core/util.ts | safe | No malicious patterns detected |
| src/v4/core/versions.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/core/zsf.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/ar.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/az.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/be.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/ca.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/cs.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/de.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/en.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/eo.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/es.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/fa.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/fi.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/fr-CA.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/fr.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/he.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/hu.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/id.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/it.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/ja.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/kh.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/ko.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/mk.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/ms.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/nl.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/no.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/ota.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/pl.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/ps.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/pt.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/ru.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/sl.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/sv.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/ta.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/th.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/tr.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/ua.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/ur.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/vi.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/zh-CN.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/locales/zh-TW.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/mini/checks.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/mini/coerce.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/mini/external.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/mini/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/mini/iso.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/mini/parse.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/v4/mini/schemas.ts | safe | Cleared by Jev triage; no further analysis needed |
| v3/ZodError.cjs | safe | No malicious patterns detected; the file is a standard Zod error handling module with no network, file system, or code execution activity. |
| v3/ZodError.js | safe | Cleared by Jev triage; no further analysis needed |
| v3/errors.cjs | safe | No malicious patterns detected; the file only manages error message localization maps without network, filesystem, or process operations. |
| v3/errors.js | safe | Cleared by Jev triage; no further analysis needed |
| v3/external.cjs | safe | No malicious patterns detected; this file only contains standard TypeScript CommonJS re-export boilerplate. |
| v3/external.js | safe | Cleared by Jev triage; no further analysis needed |
| v3/helpers/enumUtil.cjs | safe | No malicious patterns detected |
| v3/helpers/enumUtil.js | safe | Cleared by Jev triage; no further analysis needed |
| v3/helpers/errorUtil.cjs | safe | No malicious patterns detected |
| v3/helpers/errorUtil.js | safe | No malicious patterns detected; the code is a simple utility for converting error messages to objects or strings. |
| v3/helpers/parseUtil.cjs | safe | No malicious patterns detected; the file contains only standard validation and error-handling utilities from a Zod-like library. |
| v3/helpers/parseUtil.js | safe | Cleared by Jev triage; no further analysis needed |
| v3/helpers/partialUtil.cjs | safe | No malicious patterns detected |
| v3/helpers/partialUtil.js | safe | Cleared by Jev triage; no further analysis needed |
| v3/helpers/typeAliases.cjs | safe | No malicious patterns detected |
| v3/helpers/typeAliases.js | safe | Cleared by Jev triage; no further analysis needed |
| v3/helpers/util.cjs | safe | The code is a utility module for the Zod validation library and contains no malicious patterns, network calls, file system access, or dynamic code execution. |
| v3/helpers/util.js | safe | No malicious patterns detected |
| v3/index.cjs | safe | No malicious patterns detected |
| v3/index.js | safe | Cleared by Jev triage; no further analysis needed |
| v3/locales/en.cjs | safe | Cleared by Jev triage; no further analysis needed |
| v3/locales/en.js | safe | Cleared by Jev triage; no further analysis needed |
| v3/standard-schema.cjs | safe | No malicious patterns detected |
| v3/standard-schema.js | safe | Cleared by Jev triage; no further analysis needed |
| v4-mini/index.cjs | safe | No malicious patterns detected; the file is a standard TypeScript-generated CommonJS re-export shim. |
| v4-mini/index.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/classic/checks.cjs | safe | This module is a simple re-export shim that exclusively re-exports validation check functions from a sibling core module with no dynamic execution, network, filesystem, or process activity. |
| v4/classic/checks.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/classic/coerce.cjs | safe | No malicious patterns detected; the code is standard TypeScript-compiled helper functions for Zod schema coercion with no suspicious behavior. |
| v4/classic/coerce.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/classic/compat.cjs | safe | This is a standard TypeScript-generated Zod v3 compatibility layer with no malicious patterns detected. |
| v4/classic/compat.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/classic/errors.cjs | safe | No malicious patterns detected; the code is standard TypeScript/CommonJS interop and Zod error class definition with no exfiltration, obfuscation, or process spawning. |
| v4/classic/errors.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/classic/external.cjs | safe | This is standard TypeScript/CommonJS interop boilerplate from the Zod validation library, with no malicious patterns detected. |
| v4/classic/external.js | safe | This file is a standard module export aggregator for the Zod validation library; no malicious patterns, dynamic execution, network calls, or install-time behavior were detected. |
| v4/classic/index.cjs | safe | No malicious patterns detected |
| v4/classic/index.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/classic/iso.cjs | safe | No malicious patterns detected; the code is a standard TypeScript-compiled Zod library module for ISO date/time schemas with only benign module import/export logic. |
| v4/classic/iso.js | safe | No malicious patterns detected |
| v4/classic/parse.cjs | safe | No malicious patterns detected |
| v4/classic/parse.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/classic/schemas.cjs | safe | No malicious patterns detected; this is a legitimate Zod schema definition module with standard TypeScript compilation helpers and no suspicious behavior. |
| v4/classic/schemas.js | safe | No malicious patterns detected |
| v4/core/api.cjs | safe | No malicious patterns detected; the file is a standard Zod v4 validation API module with only internal schema/check construction and no network, filesystem, process, or dynamic execution behavior. |
| v4/core/api.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/core/checks.cjs | safe | No malicious patterns detected; this is standard Zod validation check implementation code with no exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| v4/core/checks.js | safe | No malicious patterns detected; the code is a standard Zod validation library implementation with no exfiltration, obfuscation, or suspicious behavior. |
| v4/core/core.cjs | safe | No malicious patterns detected |
| v4/core/core.js | safe | No malicious patterns detected |
| v4/core/errors.cjs | safe | No malicious patterns detected; the file contains standard TypeScript/JavaScript module interop helpers and Zod error formatting utilities. |
| v4/core/errors.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/core/function.cjs | safe | No malicious patterns detected |
| v4/core/function.js | safe | No malicious patterns detected; the code is a legitimate Zod schema function implementation with no external I/O, dynamic code execution, or credential harvesting. |
| v4/core/index.cjs | safe | No malicious patterns detected |
| v4/core/index.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/core/json-schema.cjs | safe | No malicious patterns detected |
| v4/core/json-schema.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/core/parse.cjs | safe | No malicious patterns detected; the file is standard Zod validation logic with TypeScript interop helpers. |
| v4/core/parse.js | safe | No malicious patterns detected |
| v4/core/regexes.cjs | safe | No malicious patterns detected; the file only exports regular expressions and helper functions for data validation. |
| v4/core/regexes.js | safe | No malicious patterns detected; the file contains only regular expression definitions and a UUID regex factory function. |
| v4/core/registries.cjs | safe | No malicious patterns detected |
| v4/core/registries.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/core/schemas.cjs | safe | This is a legitimate Zod v4 validation library source file with no malicious patterns; the only noteworthy use of dynamic function generation is a documented performance optimization for object schema parsing, controlled entirely by internal schema definitions. |
| v4/core/standard-schema.cjs | safe | No malicious patterns detected |
| v4/core/standard-schema.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/core/to-json-schema.cjs | safe | No malicious patterns detected; the code is a legitimate JSON Schema generator for Zod schema definitions with no network, filesystem, process, or obfuscation concerns. |
| v4/core/to-json-schema.js | safe | No malicious patterns detected; the code is a legitimate JSON Schema generator with no network, filesystem, credential, or code-execution red flags. |
| v4/core/util.cjs | safe | No malicious patterns detected; the only dynamic code execution is a benign feature-detection use of new Function. |
| v4/core/util.js | safe | No malicious patterns detected; the code contains standard utility functions from Zod library with no security concerns. |
| v4/core/versions.cjs | safe | No malicious patterns detected |
| v4/core/versions.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/index.cjs | safe | No malicious patterns detected |
| v4/index.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/ar.cjs | safe | This file is a standard TypeScript-compiled localization module containing only Arabic translation strings and error message formatting utilities, with no malicious patterns detected. |
| v4/locales/ar.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/az.cjs | safe | This is a standard Zod library locale file for Azerbaijani translations containing only error message formatting logic with no malicious patterns. |
| v4/locales/az.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/be.cjs | safe | No malicious patterns detected; the file is a standard localization module for Belarusian error messages with no network, filesystem, process, or dynamic code execution activity. |
| v4/locales/be.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/ca.cjs | safe | No malicious patterns detected; the file is a standard localization module for validation error messages in Catalan with no network, filesystem, process, or dynamic code execution activity. |
| v4/locales/ca.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/cs.cjs | safe | No malicious patterns detected |
| v4/locales/cs.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/de.cjs | safe | No malicious patterns detected; this is a German locale translation file for the Zod validation library with only static error message strings and standard TypeScript helper functions. |
| v4/locales/de.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/en.cjs | safe | No malicious patterns detected |
| v4/locales/en.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/eo.cjs | safe | No malicious patterns detected |
| v4/locales/eo.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/es.cjs | safe | This file is a Spanish locale error message definition for a validation library, containing only static string tables and pure translation logic with no network, filesystem, process, or dynamic execution activity. |
| v4/locales/es.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/fa.cjs | safe | This file is a standard internationalization (i18n) locale definition for error messages in Persian; it contains no malicious patterns, network activity, file system access, or dynamic code execution. |
| v4/locales/fa.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/fi.cjs | safe | No malicious patterns detected; the file is a standard localization module for the Zod validation library containing only Finnish error message translations and harmless utility imports. |
| v4/locales/fi.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/fr-CA.cjs | safe | This is a standard TypeScript/CommonJS locale translation file for a validation library, containing only static error message strings and no malicious patterns. |
| v4/locales/fr-CA.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/fr.cjs | safe | This is a localization file for French error messages with standard TypeScript helper functions and no malicious patterns. |
| v4/locales/fr.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/he.cjs | safe | No malicious patterns detected; this is a benign localization file for Zod validation error messages. |
| v4/locales/he.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/hu.cjs | safe | No malicious patterns detected |
| v4/locales/hu.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/id.cjs | safe | No malicious patterns detected; the file is a localization module for error messages in Indonesian with no network, filesystem, or dynamic code execution concerns. |
| v4/locales/id.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/index.cjs | safe | No malicious patterns detected; the file is a standard locale export index with only static requires and property definitions. |
| v4/locales/index.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/it.cjs | safe | No malicious patterns detected; this is a legitimate Italian localization file for the Zod validation library containing only TypeScript helper boilerplate and error message translations. |
| v4/locales/it.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/ja.cjs | safe | No malicious patterns detected; the file is a standard localization module for Japanese error messages with only benign TypeScript-to-CommonJS helper boilerplate. |
| v4/locales/ja.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/kh.cjs | safe | No malicious patterns detected |
| v4/locales/kh.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/ko.cjs | safe | No malicious patterns detected; the file is a standard localization module for Zod error messages in Korean with no network, filesystem, or dynamic execution behavior. |
| v4/locales/ko.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/mk.cjs | safe | This file is a standard TypeScript-generated locale translation module for validation error messages, with no network, filesystem, process, or dynamic code execution activity. |
| v4/locales/mk.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/ms.cjs | safe | No malicious patterns detected; the file contains only standard TypeScript-compiled localization error messages with no network, filesystem, process, or dynamic code execution activity. |
| v4/locales/ms.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/nl.cjs | safe | No malicious patterns detected |
| v4/locales/nl.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/no.cjs | safe | No malicious patterns detected |
| v4/locales/no.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/ota.cjs | safe | No malicious patterns detected |
| v4/locales/ota.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/pl.cjs | safe | No malicious patterns detected; this is a standard Zod locale translation file with only TypeScript helper boilerplate and static error message definitions. |
| v4/locales/pl.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/ps.cjs | safe | No malicious patterns detected; this is a legitimate Zod locale file containing only localization strings and error formatting logic. |
| v4/locales/ps.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/pt.cjs | safe | No malicious patterns detected; the file is a standard localized error message module with no network, filesystem, or dynamic code execution activity. |
| v4/locales/pt.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/ru.cjs | safe | No malicious patterns detected; the file is a standard Russian localization module for a validation library with only benign imports and formatting logic. |
| v4/locales/ru.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/sl.cjs | safe | No malicious patterns detected |
| v4/locales/sl.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/sv.cjs | safe | No malicious patterns detected |
| v4/locales/sv.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/ta.cjs | safe | No malicious patterns detected; the file contains standard localization error messages and module import helpers. |
| v4/locales/ta.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/th.cjs | safe | No malicious patterns detected; this is a legitimate Thai localization file for the Zod validation library. |
| v4/locales/th.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/tr.cjs | safe | No malicious patterns detected |
| v4/locales/tr.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/ua.cjs | safe | No malicious patterns detected; this is a standard localization file for the Zod validation library containing Ukrainian error messages. |
| v4/locales/ua.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/ur.cjs | safe | This is a localization/error message file for the Urdu language in a validation library (likely Zod), containing only static translations and no malicious patterns. |
| v4/locales/ur.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/vi.cjs | safe | No malicious patterns detected; the file is a standard localization module containing only error message strings and helper functions. |
| v4/locales/vi.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/zh-CN.cjs | safe | The file contains only standard TypeScript-generated CommonJS boilerplate and Chinese language localization strings for error messages, with no malicious patterns detected. |
| v4/locales/zh-CN.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/locales/zh-TW.cjs | safe | No malicious patterns detected; this is a standard TypeScript-compiled locale file for a validation library containing only localized error messages. |
| v4/locales/zh-TW.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/mini/checks.cjs | safe | No malicious patterns detected; the file only re-exports validator functions from the core module via safe property getters. |
| v4/mini/checks.js | safe | No malicious patterns detected; the file only re-exports validation functions from the core module. |
| v4/mini/coerce.cjs | safe | The file contains only standard TypeScript-to-CommonJS helpers and Zod schema coercion exports with no malicious patterns. |
| v4/mini/coerce.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/mini/external.cjs | safe | No malicious patterns detected; this is a standard TypeScript-generated CommonJS module re-export file for the Zod library. |
| v4/mini/external.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/mini/index.cjs | safe | The code is a standard TypeScript/CommonJS module re-export helper with no malicious patterns, external calls, or runtime execution beyond normal module loading. |
| v4/mini/index.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/mini/iso.cjs | safe | No malicious patterns detected; the code is a standard TypeScript/CommonJS compilation artifact for the Zod Mini ISO date/time schema module. |
| v4/mini/iso.js | safe | No malicious patterns detected; the file only defines Zod ISO date/time validation constructors using internal core and schema imports. |
| v4/mini/parse.cjs | safe | No malicious patterns detected; the file is a simple re-export module with no dynamic execution, network calls, or filesystem access. |
| v4/mini/parse.js | safe | Cleared by Jev triage; no further analysis needed |
| v4/mini/schemas.cjs | safe | No malicious patterns detected in this Zod schema validation library file; it contains only standard TypeScript/JavaScript module initialization and schema definition code with no exfiltration, credential harvesting, obfuscation, or command execution. |
| v4/mini/schemas.js | safe | No malicious patterns detected; the file is a standard Zod schema definition module with no network, filesystem, process, or dynamic execution behaviors. |
Affected version ranges
1 of 4 scanned versions of zod are flagged: 4.6.5 (critical). The latest scanned version, 4.6.5, is critical risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 4.6.5 | Critical | 1 | 4.6.5 | Dynamic code execution; Dynamic code execution via new Function |
| 3.25.76 โ 4.1.13 | Needs review | 2 | >=3.25.76 <=4.1.13 | Dynamic code execution; Dynamic code execution via Function constructor |
| 3.23.8 | Not scanned | 1 | 3.23.8 | |
| 3.22.4 | No issues | 1 | 3.22.4 |
Flagged files across versions
- critical v4/core/checks.cjs: present in 4.6.5
- critical
v4/core/doc.cjs (Dynamic code execution)
NPS-9534A8F558A8: present in 4.6.5
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of zod
Frequently asked questions
Is zod safe to use?
No confirmed malware was found in zod@3.25.76, but the review flagged 1 high, 2 medium, 8 low severity findings for risky patterns worth checking before you rely on it.
Does zod contain malware?
No malware was identified in zod@3.25.76 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was zod checked?
Togoder Security downloaded the published npm package and had an AI model read its 271 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan zod together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in zod@3.25.76, cost nothing.