T08 · Insecure Dependencies
- Location
scripts/depcheck.sh:20- Finding
Unpinned Packages May Be Downloaded and Executed During Quality Scans
- Content
View full analysis
/dev/null; then echo "Installing depcheck..." npm install -g depcheck fi ``` Related commands: ```bash if npx tsc --noEmit 2>&1; then ``` ```bash if npx eslint . --ext .ts,.tsx,.js,.jsx --quiet 2>&1; then ``` ### Technical Analysis The dependency scanner installs the latest registry version of `depcheck` globally without a version constraint or lockfile verification. The aggregate scanner also invokes `npx` without disabling package installation. When an appropriate local executable is unavailable, `npx` may retrieve and execute a package from the configured npm registry. In particular, the command name `tsc` does not by itself guarantee that the executable originated from the intended lockfile-managed `typescript` package. This creates a supply-chain trust boundary in a tool advertised as a local quality scanner. Its behavior can vary over time according to mutable registry content, registry configuration, and the packages already installed on the host. ### Attack Path 1. A user runs `depcheck.sh` or `quality-scan.sh` as documented. 2. The expected executable is missing from the local environment. 3. The script contacts the configured npm registry and downloads an unpinned package. 4. Package lifecycle scripts or the downloaded executable run with the user's permissions. 5. If the package, registry, or package-resolution path is compromised, attacker-controlled code can access files and resources available to that user. ### Impact Assessment Successful exploitation permits arbitrary code execution with the privileges of the user running the scan. The accessible scope can include ...[truncated 427 chars]- Remediation
View remediation
