T08 · Insecure Dependencies
- Location
scripts/setup.sh:332- Finding
Unpinned Global npm Installation Exposes the Setup Process to Supply-Chain Compromise
- Content
View full analysis
/dev/null; then : else log "[WARN] First install attempt failed, cleaning npm cache and retrying..." npm cache clean --force 2>/dev/null || true npm install -g mcporter fi ``` `scripts/setup.ps1.txt:204-210`: ```powershell Write-Log '[INSTALL] Installing mcporter via npm...' try { & npm install -g mcporter 2>&1 | Out-Null } catch {} if (-not (Test-CommandExists 'mcporter')) { Write-Log '[WARN] First install attempt failed, cleaning npm cache and retrying...' try { & npm cache clean --force 2>&1 | Out-Null } catch {} & npm install -g mcporter } ``` ### Technical Analysis Both setup implementations install the mutable latest version of the `mcporter` npm package globally. The project does not pin an exact version, provide a lockfile, verify a package integrity hash, or authenticate an expected publisher or artifact. npm installation may execute package lifecycle scripts such as `preinstall`, `install`, and `postinstall`. Consequently, a compromised package release, maintainer account, registry response, or transitive dependency could execute code during setup. The global installation scope also modifies shared user or system tooling rather than isolating the dependency to this Skill. The fallback clears the npm cache and repeats the unpinned installation. This does not provide integrity protection and further reduces reproducibility. ### Attack Path 1. An attacker compromises the `mcporter` package, one of its dependencies, or the relevant npm publishing account. 2. The attacker publishes a malicious version or injects malicious lifecycle code into the dependency chain. 3. A user or Agent runs `setup ...[truncated 785 chars]- Remediation
View remediation
