Definition
Install scripts are commands a package declares in package.json (preinstall, install, postinstall) that npm runs automatically during installation, with the installing user's permissions, for every package in the dependency tree.
What install scripts are for
Legitimate packages use them to compile native addons (node-gyp rebuild) or download a prebuilt binary for the current platform. They are declared like this:
{
"scripts": {
"postinstall": "node scripts/download-binary.js"
}
}
The same mechanism is the single most common way npm malware runs. The code executes the moment someone types npm install, before any of your code imports the package, and it has access to environment variables, SSH keys, cloud credentials and npm tokens.
How to disable or allow-list install scripts
npm ci --ignore-scripts npm config set ignore-scripts true
- pnpm 10 and later do not run dependencies' install scripts unless the package is listed in
onlyBuiltDependencies. - Bun only runs scripts for packages listed in
trustedDependencies. - Disabling scripts does not stop malicious code that runs when the package is imported, so it complements code review rather than replacing it.
Python has an equivalent: setup.py runs during a source install. Prefer wheels (pip install --only-binary :all:) where possible.
Frequently asked questions
Is it safe to always use --ignore-scripts?
It is safe in the sense that nothing runs at install time, but packages with native code may break. Allow-list the few packages that genuinely need a build step.
How do I see which of my dependencies have install scripts?
Run npm query ':attr(scripts, [postinstall])' in your project (npm 8.16+), or check npm view <pkg> scripts for a single package.