T08 · Insecure Dependencies
- Location
scripts/install.sh:10- Finding
Unpinned npm Package Is Installed Globally
- Content
View full analysis
/dev/null; then echo "Installing summarize CLI..." npm install -g @steipete/summarize fi ``` ### Technical Analysis The installation script installs `@steipete/summarize` without specifying an exact version, lockfile, or integrity hash. Consequently, npm resolves the package version available under the registry's current distribution tag when installation occurs. npm packages can execute lifecycle scripts during installation. Therefore, the effective code executed by this command is not fully represented by the audited project and may change after the audit. The `-g` option also installs the package globally, increasing its visibility and potentially the scope of filesystem modifications. Although no evidence shows that the named package is currently malicious, this pattern exposes users to package-account compromise, malicious future releases, registry compromise, and unexpected upstream changes. ### Attack Path 1. An attacker compromises the npm package, its publisher account, or the package distribution process. 2. The attacker publishes a malicious release and assigns it to the tag resolved by an unversioned npm installation. 3. A user runs `scripts/install.sh` on a system where `summarize` is not already available. 4. `npm install -g @steipete/summarize` downloads the attacker-controlled release. 5. npm executes any package lifecycle scripts and installs the resulting command globally. 6. The malicious package executes with the permissions of the account running the installer. ### Impact Assessment Successful exploitation permits arbitrary code execution with the installer's privileges. Depending on those privileges, the malicious package could access user files and environment credentials, mod ...[truncated 217 chars]- Remediation
View remediation
``` - Verify the package's expected integrity and provenance before installation. - Use a lockfile and an installation workflow that enforces integrity metadata where feasible. - Prefer a project-local installation over `-g` to reduce the modification scope. - Disable npm lifecycle scripts if the package does not require them: ```bash npm install --ignore-scripts @steipete/summarize@ ``` - Do not run the installation as root or through `sudo`. - Establish a controlled dependency-update process in which new versions are reviewed and tested before changing the pinned version. ]]>
