T08 · Insecure Dependencies
- Location
package.json:15- Finding
Unpinned Security-Sensitive Dependency Creates Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
package.json, lines 15-17
Vulnerability Type: Unpinned third-party dependency without a committed lockfile
Risk Level: MediumVulnerable Code
json "dependencies": { "ccxt": "^4.0.0" }Technical Analysis
The project permits npm to install any compatible
ccxt4.x release through the caret version range^4.0.0. No package lockfile is present to pin the exact package and transitive dependency versions resolved during installation.This dependency occupies a security-sensitive trust boundary. Both scripts provide
ccxtwith the user's Binance API key and secret and use it to process authenticated Binance requests and private financial account responses. Consequently, newly resolved dependency code executes with access to:- The Node.js process and its operating-system permissions.
- Binance API credentials loaded from
~/.openclaw/secrets/binance.json. - Private balance, position, leverage, and profit-and-loss information.
- Network access available to the process.
The audited project contains no evidence that the current dependency is malicious. The vulnerability is that future installations are not reproducible and may silently resolve to code that was not included in this audit. If an allowed future release or one of its transitive dependencies is compromised, it could misuse credentials or account data.
The documentation recommends read-only Binance keys, but the scripts cannot verify that the supplied keys are actually restricted. Therefore, the practical impact of a dependency compromise depends on the permissions configured for the user's Binance API key.
Attack Path
- An attacker compromises a future
ccxt4.x release, its publication account, or a transitive dependency. - The malicious release remains semantically compatible with the declared
^4.0.0version range. - A user performs a fresh dependency installation, and npm resolves the compromised version because ...[truncated 1311 chars]
- Remediation
View remediation
Remediation Suggestions
-
Replace the caret range with an exact, reviewed version:
json "dependencies": { "ccxt": "4.x.y" }Substitute
4.x.ywith a currently supported version that has been explicitly reviewed and tested. -
Generate and commit
package-lock.jsonso that the complete transitive dependency graph and integrity hashes are reproducible. -
Use
npm ciin installation and deployment workflows instead of unconstrained dependency resolution. -
Review lockfile changes as security-sensitive changes and require explicit approval before updating
ccxtor its transitive dependencies. -
Run dependency auditing and provenance checks in continuous integration, including
npm auditand package integrity verification. -
Require Binance API keys to be read-only and IP-restricted. Explicitly warn users not to enable trading or withdrawal permissions.
-
Consider isolating these scripts in a restricted runtime with only the filesystem access needed to read the designated credential file and network access limited to official Binance API endpoints.
-
