T08 · Insecure Dependencies
- Location
README.md:76- Finding
Unpinned Global Installation of a Third-Party CLI Package
- Content
View full analysis
Vulnerability Details
File Location:
README.md:76
Vulnerability Type: Supply-chain risk caused by an unpinned global dependency
Risk Level: MediumVulnerable Code
bash npm i -g clawhubTechnical Analysis
The publishing instructions install the latest available version of the third-party
clawhubpackage globally. No exact version, package integrity value, lockfile, or other verification mechanism is specified.Consequently, the executable package installed by a user can differ from the version that was available when this project was audited. An upstream account compromise, malicious package release, or unexpected behavioral change could introduce arbitrary executable code. npm lifecycle scripts may run during installation, and a global installation increases exposure by making the resulting CLI available system-wide for the affected user.
This finding does not establish that the current
clawhubpackage is malicious. It identifies an unsafe dependency installation practice that leaves future package contents outside the reviewed trust boundary.Attack Path
- An attacker compromises the package publisher or otherwise causes a malicious future version of
clawhubto be distributed through the configured npm registry. - A user follows the documented publishing instructions and executes
npm i -g clawhub. - npm resolves the current package version rather than a previously reviewed version.
- Malicious package code or lifecycle scripts execute with the permissions of the user running npm.
- The globally installed CLI remains available for later invocation and may perform additional attacker-controlled behavior.
Impact Assessment
Successful exploitation could execute arbitrary code with the privileges of the user performing the installation. Depending on that user's access, this may expose project files, source code, authentication tokens accessible to the process, and ot ...[truncated 329 chars]
- An attacker compromises the package publisher or otherwise causes a malicious future version of
- Remediation
View remediation
Remediation Suggestions
- Pin the CLI to an exact reviewed version, for example
npm install --global clawhub@X.Y.Z. - Document the expected package registry, publisher, and reviewed package version.
- Verify package provenance and integrity before installation where the package ecosystem supports it.
- Prefer a project-local development dependency governed by a committed lockfile instead of a global installation.
- Disable lifecycle scripts during installation when they are not required, then invoke only reviewed package entry points.
- Establish a dependency-update process that reviews package contents and release changes before updating the documented version.
- Pin the CLI to an exact reviewed version, for example
