Summary
Togoder Security scanned the npm package @npmcli/config@10.12.0 on Oct 6, 2026. An AI review of 13 source files produced 9 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 9
Environment variable harvesting
NPS-003BC8FC5B8C
The module reads a number of environment variables at import time, including process.env.EDITOR, process.env.VISUAL, process.env.SYSTEMROOT, process.env.ComSpec, process.env.SHELL, process.env.LOCALAPPDATA, process.env.LC_ALL, process.env.LC_CTYPE, process.env.LANG, process.env.NO_COLOR, process.env.NODE_ENV, process.env.HTTPS_PROXY, process.env.HTTP_PROXY, and GitHub Actions-specific variables (GITHUB_SERVER_URL, RUNNER_ENVIRONMENT) inside the user-agent flatten function. While these are all legitimate uses typical of the npm CLI, the collection and, in the user-agent case, transmittal of environment-derived values to a remote registry constitutes an environment variable harvesting surface. It should be verified that these are only sent as part of the User-Agent header and not through other channels.
Credential-adjacent file read
NPS-023CCF496AF7
The 'cafile' definition reads an arbitrary file from a path supplied via the cafile configuration option using readFileSync. Although this is expected behavior for CA bundle loading, the file contents are then placed into flatOptions.ca and (as with all flat options) may be propagated into network requests. If an attacker can influence the cafile path (e.g. via project-local .npmrc), they could cause the file's contents to be read and forwarded to the configured registry in the TLS handshake or as configuration, which is a potential exfiltration vector for arbitrary local files.
Environment variable mutation
NPS-1ACE7B3CA122
process.env.NODE_ENV is set to 'production' inside buildOmitList (called from the omit flatten function) and process.env.npm_config_user_agent is set inside the user-agent flatten function. Modifying process-wide environment variables at config-flattening/import time can affect unrelated code paths (including third-party modules loaded later) and can surprise operators, though in this context it matches documented npm behavior.
Default behavior weakens install-script protection
NPS-187267DCFCDA
Several settings around install scripts are defined with permissive defaults: 'allow-scripts' defaults to an empty string (which behaves as an allow-all in many npm versions unless an explicit policy exists), 'dangerously-allow-all-scripts' defaults to false but is exposed as a documented escape hatch that is trivial to flip in a project .npmrc, and 'strict-allow-scripts' defaults to false. Combined with the many allow-* (directory/file/git/remote) settings defaulting to 'all', the module's defaults permit broad dependency sourcing and lifecycle-script execution. These defaults are documented npm behavior but represent a meaningful supply-chain attack surface for a package-manager config module.
Credential handling
NPS-160827CFD736
The code reads, stores, and manipulates npm authentication credentials (tokens, passwords, usernames) from .npmrc files and environment variables. While this is expected behavior for npm's config module, it represents a high-value target for credential harvesting if the package were compromised or malicious.
Dynamic module loading
NPS-73F50691F31C
Uses require() with paths derived from configuration (e.g., require(join(this.npmPath, 'package.json')), require('@npmcli/package-json'), require('@npmcli/map-workspaces')). While these are expected dependencies, dynamic require based on config paths could be a risk if paths are attacker-controlled.
Environment variable harvesting
NPS-4FD37534D6C0
The module processes all environment variables matching 'npm_config_*' and incorporates them into configuration. This is standard npm behavior but could be abused to capture sensitive environment data if the package were modified maliciously.
File system access outside package scope
NPS-345F8FA8CB5D
Reads and writes configuration files at user-level (~/.npmrc), global-level, and project-level locations. Writes use chmod to set permissions (0o600 for user config). This is expected for a config library but involves accessing files outside the package scope.
Environment variable expansion
NPS-86CB1767ABA8
The code calls envReplace(f, env) which performs environment variable substitution. While this is a normal feature for a config parser, it does expand environment variable values into strings. No exfiltration or credential harvesting behavior is present.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/definitions/definitions.js | medium | This file is the npm CLI's configuration definition table; it contains no obfuscation, network calls, shell execution, or credential exfiltration, but it does read environment variables and one configurable file (cafile) at import time and exposes permissive install-script defaults that together form a low-severity supply-chain/attack-surface concern. |
| lib/index.js | medium | This is npm's official config module with expected credential and environment variable handling; no malicious patterns such as exfiltration, backdoors, or obfuscated code were found. |
| lib/definitions/definition.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/definitions/index.js | safe | The code contains only configuration flattening and shorthand definitions for npm CLI, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
| lib/env-replace.js | safe | No malicious patterns detected; the code performs straightforward environment variable substitution with no network, filesystem, process, or dynamic code execution. |
| lib/errors.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/nerf-dart.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/parse-allow-scripts-list.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/parse-field.js | safe | This file is a benign config-parsing utility that while performing environment variable substitution is not malicious and shows no exfiltration, credential harvesting, code execution, or backdoor patterns. |
| lib/set-envs.js | safe | No malicious patterns detected; the code is a benign npm config-to-environment-variable exporter. |
| lib/type-defs.js | safe | No malicious patterns detected; the file only defines validation schemas for nopt and uses standard semver and local umask validation without any suspicious behavior. |
| lib/type-description.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/umask.js | safe | Cleared by Jev triage; no further analysis needed |
Scanned versions of @npmcli/config
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 10.12.0 | Needs review | 13 | Oct 6, 2026 |
Frequently asked questions
Is @npmcli/config safe to use?
No confirmed malware was found in @npmcli/config@10.12.0, but the review flagged 9 low severity findings for risky patterns worth checking before you rely on it.
Does @npmcli/config contain malware?
No malware was identified in @npmcli/config@10.12.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @npmcli/config checked?
Togoder Security downloaded the published npm package and had an AI model read its 13 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @npmcli/config together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @npmcli/config@10.12.0, cost nothing.