Summary
Togoder Security scanned the npm package zustand@5.0.0 on Oct 4, 2026. An AI review of 18 source files produced 5 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings 5
Environment-based conditional logging
NPS-16C77D51089F
Uses process.env.NODE_ENV to conditionally enable devtools and warning messages. This is standard Node.js practice, not credential harvesting.
Legitimate Redux DevTools browser extension integration
NPS-F0FFE251D4D0
The code accesses window.__REDUX_DEVTOOLS_EXTENSION__ to connect to the Redux DevTools browser extension, a standard development tool. This is expected functionality for the zustand devtools middleware and does not constitute data exfiltration.
Dynamic property assignment for dispatch wrapping
NPS-C1AC7EE019D4
The code overrides api.dispatch with a wrapper function. This is part of the devtools middleware functionality for intercepting actions, not a backdoor.
JSON parsing of DevTools messages
NPS-4A70A04F42BC
parseJsonThen uses JSON.parse on messages received from the Redux DevTools browser extension. This is expected behavior for the integration, though it processes external input. No dynamic code execution (eval/new Function) is involved.
localStorage usage for state persistence
NPS-E495FA15735E
createJSONStorage defaults to using localStorage for persisting state. This is client-side browser storage within the same origin, not exfiltration.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| esm/index.mjs | safe | Cleared by Jev triage; no further analysis needed |
| esm/middleware.mjs | safe | No malicious patterns detected; the code implements standard Zustand middleware (redux, devtools, subscribeWithSelector, persist) with expected Redux DevTools integration and localStorage persistence, without exfiltration, obfuscation, process spawning, or install-time execution. |
| esm/middleware/immer.mjs | safe | Cleared by Jev triage; no further analysis needed |
| esm/react.mjs | safe | Cleared by Jev triage; no further analysis needed |
| esm/react/shallow.mjs | safe | Cleared by Jev triage; no further analysis needed |
| esm/shallow.mjs | safe | Cleared by Jev triage; no further analysis needed |
| esm/traditional.mjs | safe | Cleared by Jev triage; no further analysis needed |
| esm/vanilla.mjs | safe | No malicious patterns detected; this is a standard Zustand-like state management store implementation with no external I/O, obfuscation, or system access. |
| esm/vanilla/shallow.mjs | safe | Cleared by Jev triage; no further analysis needed |
| index.js | safe | No malicious patterns detected |
| middleware.js | safe | This appears to be a legitimate copy of the zustand state management library middleware (devtools, persist, subscribeWithSelector, redux, combine) with no malicious patterns; the observed behaviors are all expected for Redux DevTools integration and browser storage persistence. |
| middleware/immer.js | safe | The code is a legitimate Zustand middleware integration for Immer with no malicious patterns detected. |
| react.js | safe | No malicious patterns detected; the code is a standard Zustand React binding with no exfiltration, obfuscation, or dangerous operations. |
| react/shallow.js | safe | Cleared by Jev triage; no further analysis needed |
| shallow.js | safe | No malicious patterns detected; the file only re-exports shallow and useShallow from zustand submodules. |
| traditional.js | safe | Cleared by Jev triage; no further analysis needed |
| vanilla.js | safe | No malicious patterns detected; this is a standard Zustand-style vanilla store implementation with no network, filesystem, or dynamic execution activity. |
| vanilla/shallow.js | safe | Cleared by Jev triage; no further analysis needed |
Affected version ranges
None of the 2 scanned versions of zustand are flagged high or critical. The latest scanned version, 5.0.3, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of zustand
Frequently asked questions
Is zustand safe to use?
Our AI source review of zustand@5.0.0 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does zustand contain malware?
No malware was identified in zustand@5.0.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was zustand checked?
Togoder Security downloaded the published npm package and had an AI model read its 18 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan zustand together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in zustand@5.0.0, cost nothing.