# @npmcli/config@10.12.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:22:58.000Z
- Files reviewed: 13
- Findings: 9 low severity findings
- Report: https://security.togoder.click/npm/@npmcli/config
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @npmcli/config@10.12.0 on Oct 6, 2026. An AI review of 13 source files produced 9 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] Environment variable harvesting

Finding ID: `NPS-003BC8FC5B8C`

File: `lib/definitions/definitions.js`

The module reads a number of environment variables at import time, including process.env.EDITOR, process.env.VISUAL, process.env.SYSTEMROOT, process.env.ComSpec, process.env.SHELL, process.env.LOCALAPPDATA, process.env.LC_ALL, process.env.LC_CTYPE, process.env.LANG, process.env.NO_COLOR, process.env.NODE_ENV, process.env.HTTPS_PROXY, process.env.HTTP_PROXY, and GitHub Actions-specific variables (GITHUB_SERVER_URL, RUNNER_ENVIRONMENT) inside the user-agent flatten function. While these are all legitimate uses typical of the npm CLI, the collection and, in the user-agent case, transmittal of environment-derived values to a remote registry constitutes an environment variable harvesting surface. It should be verified that these are only sent as part of the User-Agent header and not through other channels.

### [low] Credential-adjacent file read

Finding ID: `NPS-023CCF496AF7`

File: `lib/definitions/definitions.js`

The 'cafile' definition reads an arbitrary file from a path supplied via the cafile configuration option using readFileSync. Although this is expected behavior for CA bundle loading, the file contents are then placed into flatOptions.ca and (as with all flat options) may be propagated into network requests. If an attacker can influence the cafile path (e.g. via project-local .npmrc), they could cause the file's contents to be read and forwarded to the configured registry in the TLS handshake or as configuration, which is a potential exfiltration vector for arbitrary local files.

### [low] Environment variable mutation

Finding ID: `NPS-1ACE7B3CA122`

File: `lib/definitions/definitions.js`

process.env.NODE_ENV is set to 'production' inside buildOmitList (called from the omit flatten function) and process.env.npm_config_user_agent is set inside the user-agent flatten function. Modifying process-wide environment variables at config-flattening/import time can affect unrelated code paths (including third-party modules loaded later) and can surprise operators, though in this context it matches documented npm behavior.

### [low] Default behavior weakens install-script protection

Finding ID: `NPS-187267DCFCDA`

File: `lib/definitions/definitions.js`

Several settings around install scripts are defined with permissive defaults: 'allow-scripts' defaults to an empty string (which behaves as an allow-all in many npm versions unless an explicit policy exists), 'dangerously-allow-all-scripts' defaults to false but is exposed as a documented escape hatch that is trivial to flip in a project .npmrc, and 'strict-allow-scripts' defaults to false. Combined with the many allow-* (directory/file/git/remote) settings defaulting to 'all', the module's defaults permit broad dependency sourcing and lifecycle-script execution. These defaults are documented npm behavior but represent a meaningful supply-chain attack surface for a package-manager config module.

### [low] Credential handling

Finding ID: `NPS-160827CFD736`

File: `lib/index.js`

The code reads, stores, and manipulates npm authentication credentials (tokens, passwords, usernames) from .npmrc files and environment variables. While this is expected behavior for npm's config module, it represents a high-value target for credential harvesting if the package were compromised or malicious.

### [low] Dynamic module loading

Finding ID: `NPS-73F50691F31C`

File: `lib/index.js:225`

Uses require() with paths derived from configuration (e.g., require(join(this.npmPath, 'package.json')), require('@npmcli/package-json'), require('@npmcli/map-workspaces')). While these are expected dependencies, dynamic require based on config paths could be a risk if paths are attacker-controlled.

### [low] Environment variable harvesting

Finding ID: `NPS-4FD37534D6C0`

File: `lib/index.js:310`

The module processes all environment variables matching 'npm_config_*' and incorporates them into configuration. This is standard npm behavior but could be abused to capture sensitive environment data if the package were modified maliciously.

### [low] File system access outside package scope

Finding ID: `NPS-345F8FA8CB5D`

File: `lib/index.js:510`

Reads and writes configuration files at user-level (~/.npmrc), global-level, and project-level locations. Writes use chmod to set permissions (0o600 for user config). This is expected for a config library but involves accessing files outside the package scope.

### [low] Environment variable expansion

Finding ID: `NPS-86CB1767ABA8`

File: `lib/parse-field.js:44`

The code calls envReplace(f, env) which performs environment variable substitution. While this is a normal feature for a config parser, it does expand environment variable values into strings. No exfiltration or credential harvesting behavior is present.

## Files reviewed

- `lib/definitions/definitions.js` (medium): This file is the npm CLI's configuration definition table; it contains no obfuscation, network calls, shell execution, or credential exfiltration, but it does read environment variables and one configurable file (cafile) at import time and exposes permissive install-script defaults that together form a low-severity supply-chain/attack-surface concern.
- `lib/index.js` (medium): This is npm's official config module with expected credential and environment variable handling; no malicious patterns such as exfiltration, backdoors, or obfuscated code were found.
- `lib/definitions/definition.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/definitions/index.js` (safe): The code contains only configuration flattening and shorthand definitions for npm CLI, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
- `lib/env-replace.js` (safe): No malicious patterns detected; the code performs straightforward environment variable substitution with no network, filesystem, process, or dynamic code execution.
- `lib/errors.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/nerf-dart.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/parse-allow-scripts-list.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/parse-field.js` (safe): This file is a benign config-parsing utility that while performing environment variable substitution is not malicious and shows no exfiltration, credential harvesting, code execution, or backdoor patterns.
- `lib/set-envs.js` (safe): No malicious patterns detected; the code is a benign npm config-to-environment-variable exporter.
- `lib/type-defs.js` (safe): No malicious patterns detected; the file only defines validation schemas for nopt and uses standard semver and local umask validation without any suspicious behavior.
- `lib/type-description.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/umask.js` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
