T08 · Insecure Dependencies
- Location
scripts/setup.sh:11- Finding
Unpinned Global npm Package Installation Executes Unverified Supply-Chain Code
- Content
View full analysis
/dev/null; then echo "mcporter is required but not installed." read -rp "Install mcporter now? (Y/n): " install_mcporter if [[ "$install_mcporter" =~ ^[Nn]$ ]]; then echo "Cannot continue without mcporter. Install with: npm i -g mcporter" exit 1 fi echo "Installing mcporter..." npm i -g mcporter ``` The same unpinned installation command is also recommended in `SKILL.md` lines 16–19 and `README.md` line 27. ### Technical Analysis The setup script installs the latest package published under the `mcporter` name without specifying an audited version, integrity hash, lockfile, or trusted package provenance. npm installations may execute package lifecycle scripts such as `preinstall`, `install`, and `postinstall`. Consequently, the code executed by the setup process can differ from the code that was reviewed. A compromised maintainer account, malicious newly published release, registry compromise, or dependency-chain compromise could cause arbitrary code to run during setup. The global installation flag expands the potential impact because the package is installed into the user's global npm environment. The installer executes with the privileges of the account running the script; if a user invokes setup through a privileged npm configuration or elevated shell, the package lifecycle code receives those elevated privileges. ### Attack Path 1. An attacker compromises the `mcporter` npm package, one of its install-time dependencies, or its publishing account. 2. The attacker publishes a new release containing a malicious lifecycle script or runtime payload. 3. A user without `mcporter` runs `scripts/setup.sh`. 4. The script offers to install the dependency and invokes `npm i -g mcporter` without ...[truncated 1093 chars]- Remediation
View remediation
