T08 · Insecure Dependencies
- Location
README.md:41- Finding
Mutable Package Execution Through Unpinned npx Installation Command
- Content
View full analysis
Vulnerability Details
File Location:
README.md:41
Vulnerability Type: Supply-chain exposure through mutable package execution
Risk Level: HighVulnerable Code
bash npx clawhub@latest install EdwardWason/xhs-crafterTechnical Analysis
The documented installation command instructs
npxto retrieve and execute the package currently associated with the mutablelatesttag. Neither an exact package version nor an integrity digest is specified.Consequently, the code executed during installation is not limited to the package version covered by this audit. The effective installer can change after review if a new release is published or if the package registry account, package namespace, or dependency chain is compromised.
This is a supply-chain weakness rather than evidence that the currently audited repository contains an intentionally malicious dependency.
Attack Path
- An attacker compromises the
clawhubpackage, its publishing account, or a transitive dependency used by a future release. - The malicious release is assigned the
latestdistribution tag. - A user follows the Quick Start command from the README.
npxdownloads the unaudited mutable release.- The package's CLI, initialization logic, or dependency code executes with the privileges of the user running the command.
Impact Assessment
Successful exploitation could provide arbitrary code execution under the installing user's account. Depending on that account's privileges and environment, the malicious package could access user-readable files, environment variables, project credentials, network services, and writable application data.
The command does not itself request administrator privileges, so the direct scope is normally limited to the invoking user's permissions.
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith an exact, reviewed package version, for exampleclawhub@X.Y.Z. - Publish and document expected package integrity hashes or signed release artifacts.
- Instruct users to verify the package publisher and release signature before installation.
- Use a lockfile for development and deployment dependencies.
- Avoid commands that automatically execute newly downloaded packages where a verified local installer or pinned package can be used.
- Review each package update before changing the documented pinned version.
- Replace
