T08 · Insecure Dependencies
- Location
package-lock.json:22- Finding
Dependencies are locked to a third-party package mirror over plaintext HTTP
- Content
View full analysis
Vulnerability Details
File Location:
package-lock.json:22-25and additionalresolvedentries throughoutpackage-lock.json
Vulnerability Type: Insecure dependency source and software supply-chain exposure
Risk Level: MediumVulnerable Code
json "node_modules/@pinojs/redact": { "version": "0.4.0", "resolved": "http://mirrors.tencentyun.com/npm/@pinojs/redact/-/redact-0.4.0.tgz", "integrity": "sha512-k2ENnmBugE/rzQfEcdWHcCY+/FM3VLzH9cYEsbdsoqrvzAKRhUZeRNhAZvB8OitQJ1TBed3yqWtdjzS6wJKBwg==" }The same plaintext mirror is used for security-sensitive runtime packages, including:
json "node_modules/imapflow": { "version": "1.2.12", "resolved": "http://mirrors.tencentyun.com/npm/imapflow/-/imapflow-1.2.12.tgz", "integrity": "sha512-UX8qCKXZk2xExe/x8KPTSbhROdtUGP13bSLSjT9Sb3YwGuryD4aFNlGhbWBW5B1GtgHMRxVv9yvl61RqXgIQtQ==" }json "node_modules/nodemailer": { "version": "6.10.1", "resolved": "http://mirrors.tencentyun.com/npm/nodemailer/-/nodemailer-6.10.1.tgz", "integrity": "sha512-Z+iLaBGVaSjbIzQ4pX6XV41HrooLsQ10ZWPUehGmuantvzWoDVBnmsdUcOIDM1t+yPor5pDhVlDESgOMEGxhHA==" }Technical Analysis
The lockfile directs npm to download dependencies from
mirrors.tencentyun.comusing unencrypted HTTP rather than HTTPS. This exposes dependency retrieval metadata and package responses to interception or modification by network-adjacent attackers.npm integrity hashes provide an important mitigation: an attacker who only changes a package archive should normally cause installation to fail because its hash no longer matches the lockfile. Exploitation would therefore additionally require modification of the lockfile or integrity metadata, a compromised mirror serving an artifact matching already-poisoned metadata, an integrity-verification weakness, or a workflow that regenerates or accepts changed lockfiles without review.
The risk is significant becau ...[truncated 1317 chars]
- Remediation
View remediation
Remediation Suggestions
- Regenerate
package-lock.jsonusing the official npm registry over HTTPS:bash npm config set registry https://registry.npmjs.org/ rm -rf node_modules package-lock.json npm install - Review and commit the regenerated lockfile, confirming that every
resolvedpackage URL uses HTTPS and an approved registry. - Use
npm ciin production and CI so installations cannot silently rewrite dependency versions. - Require code review for all lockfile changes and fail CI when a
resolvedURL uses HTTP or an unapproved domain. - Run dependency vulnerability and provenance checks, such as
npm audit, software composition analysis, and package-signature or provenance verification where available. - Pin reviewed dependency versions and periodically reassess transitive dependencies because these packages process credentials and untrusted email content.
- Regenerate
