T08 · Insecure Dependencies
- Location
package-lock.json:18- Finding
Dependencies Retrieved over Unencrypted HTTP
- Content
View full analysis
Vulnerability Details
File Location:
package-lock.json:18-21
Vulnerability Type: Insecure dependency source and transport
Risk Level: MediumVulnerable Code
json "node_modules/ansi-styles": { "version": "4.3.0", "resolved": "http://mirrors.tencentyun.com/npm/ansi-styles/-/ansi-styles-4.3.0.tgz", "integrity": "sha512-zbB9rCJAT1rbjiVDb2hqKFHNYLxgtk8NURxZ3IZwD3F6NtxbXZQCnnSi1Lkx+IDohdPlFp222wVALIheZJQSEg==",The same plaintext mirror is used for all locked dependencies at
package-lock.json:20,36,42,58,70,76,82.Technical Analysis
Dependency archives are resolved through
http://mirrors.tencentyun.comrather than an authenticated HTTPS registry. Plaintext HTTP does not provide transport confidentiality or server authentication, allowing an on-path attacker to observe, redirect, block, or replace dependency responses.The lockfile contains SHA-512 integrity values, so a normal npm installation should reject modified archives whose contents do not match the recorded hashes. This substantially limits direct package substitution when the lockfile remains trusted. It does not prevent denial of service, dependency-request monitoring, mirror impersonation attempts, or compromise where an attacker can also modify the lockfile or its integrity metadata.
The project also declares
asciichartandchalk, although the reviewed implementation does not import either dependency. Unnecessary dependencies increase the supply-chain attack surface.Attack Path
- A developer or deployment system runs
npm installusing the committed lockfile. - npm requests dependency archives through plaintext HTTP.
- An attacker positioned on the network intercepts or redirects these requests.
- The attacker can block or corrupt responses, causing installation failure.
- Arbitrary substituted content should fail npm integrity verification while the lockfile is trusted.
- If the attacker can also ...[truncated 710 chars]
- A developer or deployment system runs
- Remediation
View remediation
Remediation Suggestions
- Configure npm to use the official HTTPS registry or another explicitly trusted HTTPS registry:
bash npm config set registry https://registry.npmjs.org/ - Delete and regenerate
package-lock.jsonfrom the trusted registry, then verify that everyresolvedURL uses HTTPS. - Pin and review dependency versions through the lockfile in CI.
- Run dependency integrity and vulnerability checks during builds, such as
npm ciandnpm audit. - Remove the unused
asciichartandchalkdependencies to reduce supply-chain exposure. - Protect the lockfile through branch review, signed commits where practical, and CI checks that reject plaintext dependency URLs.
- Configure npm to use the official HTTPS registry or another explicitly trusted HTTPS registry:
