T08 · Insecure Dependencies
- Location
cli.md:5- Finding
Unpinned Global Installation of a Third-Party CLI Package
- Content
View full analysis
Vulnerability Details
File Location:
cli.md:5
Vulnerability Type: Unpinned third-party dependency installed globally
Risk Level: MediumComplete Code Snippet:
markdown 2. If `adkit` is not found, install it: `npm i -g @adkit/cli`.Technical Analysis
The setup instructions install
@adkit/cliglobally without specifying an exact version or integrity constraint. Consequently, npm resolves whichever release the configured registry currently associates with the requested package and tag. The project contains no lockfile, checksum, signature-verification procedure, or vendored implementation that would allow the installed executable to be matched to an audited version.A global npm installation may run package lifecycle scripts and makes the resulting executable available across the user's environment. This increases the consequences of a compromised package publisher, npm account, registry response, or release pipeline. This finding does not establish that
@adkit/cliis malicious; it identifies an avoidable supply-chain exposure caused by mutable dependency resolution.Attack Path
- An attacker compromises the package publisher, release pipeline, or relevant package-registry delivery path.
- The attacker publishes a malicious or backdoored version under the legitimate
@adkit/clipackage name or alters the version resolved by its default distribution tag. - A user follows the documented setup command:
bash npm i -g @adkit/cli - npm retrieves the mutable current release rather than a previously reviewed, exact version.
- Malicious package lifecycle scripts can execute during installation, or malicious CLI logic can execute when the installed command is invoked.
- The payload operates with the privileges of the user running npm and may access that user's files, network connectivity, and environment variables.
Impact Assessment
Successful exploitation ...[truncated 849 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin the CLI to an audited exact version rather than relying on the mutable latest release:
bash npm install --global --ignore-scripts @adkit/cli@0.2.3The example version must be replaced with the specific release independently reviewed and approved by the maintainer.
-
Prefer a project-local dependency recorded in
package.jsonand a committed lockfile. Usenpm ciso installation fails if dependency resolution differs from the reviewed lockfile. -
Verify package provenance and integrity through npm provenance attestations, trusted publisher information, and expected integrity hashes where supported.
-
Disable lifecycle scripts with
--ignore-scriptswhen the package does not require them. If scripts are required, audit them before installation and document why execution is necessary. -
Run installation and the CLI as an unprivileged, isolated user. Do not recommend
sudo npm install -g, and consider a container or sandbox with only the required filesystem and network access. -
Provide an approved-version policy and controlled upgrade process. Review release changes before updating the pinned version.
-
Keep
ADKIT_API_KEYout of broadly inherited environments where possible. Supply it only to the required process, limit its permissions, rotate it after suspected compromise, and avoid exposing it to package installation lifecycle scripts.
-
