Summary
Togoder Security scanned the npm package @npmcli/git@7.0.2 on Oct 6, 2026. An AI review of 13 source files produced 3 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 11
Spawning processes or shell commands
NPS-80874DE42816
The code imports './spawn.js' and calls it with arguments to run a command (likely 'git status --porcelain=v1 -uno'). While the arguments appear hardcoded, the imported spawn module could execute arbitrary shell commands or have side effects. This is a common pattern for executing external processes, which can be abused if the spawn module is malicious or if the arguments are influenced by external input (here they are static).
Security-relevant behavior modification
NPS-6794B6A8F20D
Sets GIT_SSH_COMMAND to 'ssh -oStrictHostKeyChecking=accept-new' and GIT_ASKPASS to 'echo' by default. This silently disables SSH host key verification and supplies a no-op askpass, weakening the end-user's SSH security posture without explicit consent.
Process / child_process spawning
NPS-44027F202070
The default GIT_SSH_COMMAND configures ssh to be spawned by git. Combined with GIT_ASKPASS='echo', this changes how external processes are executed on behalf of the user, though the module itself does not directly spawn processes.
Spawn processes
NPS-B8407499A834
The code spawns git subprocesses (clone, fetch, checkout, init, remote, submodule, rev-parse) via a spawn utility. This is expected for a package manager's git cloning functionality and arguments are constructed from package metadata (repo, ref, revDoc.rawRef), not from arbitrary untrusted user input.
Network requests
NPS-ACCAC79ED8A1
Git commands make network requests to the repository URL provided in package metadata. This is inherent to the package's purpose (cloning git repositories) and not exfiltration of local data.
File system manipulation
NPS-5AF40F6A941E
Creates directories, initializes git repositories, and writes files within the specified target directory (derived from repo name and cwd). Operations are scoped to the intended clone target.
Environment / Config Harvesting
NPS-832D57319159
Reads the user's ~/.gitconfig file and inspects core.sshCommand and core.askpass settings, plus GIT_SSH_COMMAND and GIT_ASKPASS environment variables. While only boolean presence is checked, it is still reading user credentials-adjacent configuration data outside the package scope.
Top-level code execution on import
NPS-C3BDBC5CEB42
The module executes file system reads (loadGitConfig → fs.readFileSync on ~/.gitconfig) and environment reads at import time, and computes finalGitEnv using those values. This side-effecting behavior runs whenever the module is required.
Dynamic module loading inside function
NPS-D00B31259F4C
require('./which.js') is executed lazily at call time rather than at module load. This is an unusual pattern but not inherently malicious; it could be used to defer resolution, though no external/computed path is used.
Spawning processes
NPS-06D527F10FA8
The module wraps git command execution via @npmcli/promise-spawn, spawning child processes with user-controllable arguments (gitArgs). This is expected for a git utility package, but in a malicious context it could be abused to execute arbitrary commands.
Retry logic on failures
NPS-64DC911160D7
The promiseRetry wrapper retries failed git commands up to a configurable number of times. While normal for network operations, uncontrolled retries with attacker-supplied opts could amplify certain requests.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/is-clean.js | medium | The file spawns a child process via a local spawn module, which could be a vector for command execution, though no obvious malicious intent is present in this snippet alone. |
| lib/opts.js | medium | The module reads ~/.gitconfig and git-related environment variables and, without user opt-in, weakens SSH host key checking via GIT_SSH_COMMAND and disables credential prompting via GIT_ASKPASS; no exfiltration or code execution red flags, but it degrades security posture and runs logic at import time. |
| lib/spawn.js | medium | The file is a legitimate git-spawning helper with no clear exfiltration, credential harvesting, obfuscation, or backdoor patterns, though it does spawn subprocesses and lazily requires a local module. |
| lib/clone.js | safe | The code is a legitimate git cloning utility from npm's pacote library; it spawns git commands and performs filesystem/network operations as expected for its function, with no malicious patterns detected. |
| lib/errors.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/find.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/index.js | safe | No malicious patterns detected; the file is a simple module aggregator that re-exports sibling modules with no executable, network, or obfuscated code. |
| lib/is.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/lines-to-revs.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/make-error.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/revs.js | safe | No malicious patterns detected; the code performs a legitimate git ls-remote call with caching and no data exfiltration or suspicious behavior. |
| lib/utils.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/which.js | safe | No malicious patterns detected; the module only resolves the git binary path via the 'which' package and returns it or an error. |
Frequently asked questions
Is @npmcli/git safe to use?
No confirmed malware was found in @npmcli/git@7.0.2, but the review flagged 3 medium, 8 low severity findings for risky patterns worth checking before you rely on it.
Does @npmcli/git contain malware?
No malware was identified in @npmcli/git@7.0.2 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @npmcli/git checked?
Togoder Security downloaded the published npm package and had an AI model read its 13 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @npmcli/git together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @npmcli/git@7.0.2, cost nothing.