Togoder security

Glossary

What are install scripts?

Also called: postinstall script, lifecycle scripts, preinstall scriptUpdated

Definition

Install scripts are commands a package declares in package.json (preinstall, install, postinstall) that npm runs automatically during installation, with the installing user's permissions, for every package in the dependency tree.

What install scripts are for

Legitimate packages use them to compile native addons (node-gyp rebuild) or download a prebuilt binary for the current platform. They are declared like this:

{
  "scripts": {
    "postinstall": "node scripts/download-binary.js"
  }
}

The same mechanism is the single most common way npm malware runs. The code executes the moment someone types npm install, before any of your code imports the package, and it has access to environment variables, SSH keys, cloud credentials and npm tokens.

How to disable or allow-list install scripts

npm ci --ignore-scripts
npm config set ignore-scripts true
  • pnpm 10 and later do not run dependencies' install scripts unless the package is listed in onlyBuiltDependencies.
  • Bun only runs scripts for packages listed in trustedDependencies.
  • Disabling scripts does not stop malicious code that runs when the package is imported, so it complements code review rather than replacing it.

Python has an equivalent: setup.py runs during a source install. Prefer wheels (pip install --only-binary :all:) where possible.

Frequently asked questions

Is it safe to always use --ignore-scripts?

It is safe in the sense that nothing runs at install time, but packages with native code may break. Allow-list the few packages that genuinely need a build step.

How do I see which of my dependencies have install scripts?

Run npm query ':attr(scripts, [postinstall])' in your project (npm 8.16+), or check npm view <pkg> scripts for a single package.