T08 · Insecure Dependencies
- Location
references/best-practices.md:138- Finding
Unpinned Global Installation of a Mutable npm Dependency
- Content
View full analysis
Vulnerability Details
File Location:
references/best-practices.md:138
Vulnerability Type: Insecure third-party dependency installation
Risk Level: MediumComplete Code Snippet
bash npm install -g @liquiditytech/rapidx-cli@latestTechnical Analysis
The documented command installs the mutable
latestrelease of@liquiditytech/rapidx-cliglobally. Because npm distribution tags can be reassigned, the effective package content may change after this Skill has been audited. The command does not pin an audited version or verify package integrity.npm installation can also execute package lifecycle scripts. Consequently, compromise of the package publisher, npm account, release process, or package contents could cause attacker-controlled code to execute during installation. Global installation increases exposure because the resulting executable is available across workspaces rather than being isolated to this project.
This finding is limited to supply-chain risk in the documented installation process. The audited project itself contains no embedded executable scripts or confirmed malicious payload.
Attack Path
- An attacker compromises the npm publisher account, package release process, or another component capable of publishing
@liquiditytech/rapidx-cli. - The attacker publishes a malicious release and assigns it the
latestdistribution tag. - An Agent follows the Skill guidance and runs the documented global installation command.
- npm downloads the attacker-controlled release.
- Malicious lifecycle scripts, if present, execute with the privileges of the user running npm.
- The compromised globally installed
rapidxexecutable remains available to subsequent workspaces and can intercept credentials or alter future RapidX operations.
Impact Assessment
Successful exploitation could provide arbitrary code execution with the privileges of the installing user. Depending on those privileges and the host configu ...[truncated 471 chars]
- An attacker compromises the npm publisher account, package release process, or another component capable of publishing
- Remediation
View remediation
Remediation Suggestions
- Replace the mutable
@latesttag with an exact, reviewed version:bash npm install -g @liquiditytech/rapidx-cli@1.2.3 - Prefer a project-local dependency recorded in
package.jsonand protected by a committed lockfile instead of a global installation. - Install with
npm ciwhere applicable so dependency resolution follows the reviewed lockfile. - Verify that the package is retrieved from the expected npm registry and validate package provenance, signatures, or published integrity metadata before installation.
- Review package contents and lifecycle scripts before approving each upgrade.
- Do not upgrade automatically. Audit a new exact version first, then deliberately update the pinned version and lockfile.
- Run installation and the CLI as a non-privileged user in an isolated environment with access only to required credentials and files.
- Where operationally feasible, disable lifecycle scripts during installation and explicitly enable only reviewed setup steps:
bash npm install --ignore-scripts --save-exact @liquiditytech/rapidx-cli@1.2.3
- Replace the mutable
