Togoder security

npm package security report

@npmcli/run-script npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 10.0.4 Files reviewed 8 Size 9.6 KB Scanned

Summary

Togoder Security scanned the npm package @npmcli/run-script@10.0.4 on Oct 6, 2026. An AI review of 8 source files produced 2 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
6
low

Findings 8

medium

Dynamic module resolution

NPS-4BB62A55C14C

Uses require.resolve('node-gyp/bin/node-gyp.js') to dynamically resolve a module path, which could be influenced by the environment (npm_config_node_gyp) to point to an arbitrary file. This could allow execution of an attacker-controlled script if the environment variable is set maliciously.

lib/make-spawn-args.js:26
medium

Shell command execution

NPS-B34DF12A5FC9

This module executes lifecycle scripts defined in package.json (e.g., preinstall, install, postinstall, start) via @npmcli/promise-spawn. While this is the intended behavior of npm's script runner, a compromised package.json can execute arbitrary commands during install/build. The code itself is not malicious, but it is a powerful execution vector.

lib/run-script-pkg.js
low

Environment variable harvesting

NPS-896A1902176F

The code reads and merges all environment variables from process.env and options.env, then includes them in the spawned process environment. This is standard for npm lifecycle scripts but could expose sensitive environment variables to child processes if not properly sanitized.

lib/make-spawn-args.js:32
low

Process spawning

NPS-F4F9BA5BA9E8

The function constructs arguments and options for spawning a child process, returning them to the caller. While it does not directly spawn the process, it facilitates process execution with a configurable shell (scriptShell) and environment, which could be abused if inputs are not validated.

lib/make-spawn-args.js:40
low

Environment variable merging

NPS-F5BF83E90E13

Environment variables from the parent process are merged with package-specific environment variables (packageEnvs(pkg)) and passed to spawned child processes. This is standard npm behavior, but in a malicious dependency it could be abused to leak or alter sensitive environment variables to child processes.

lib/run-script-pkg.js
low

Fallback command execution

NPS-31388437DC0D

If no explicit script exists, the code may automatically execute 'node server.js' for packages detected as server packages, or run node-gyp rebuild for packages with a gypfile. This automatic fallback execution could be unexpected.

lib/run-script-pkg.js
low

Signal propagation

NPS-B4B578B6DD6A

When stdio is 'inherit' and a child process exits with a signal, the parent process re-raises the same signal on itself. This is designed for proper exit status propagation but could be misused if a child is manipulated to send unexpected signals.

lib/run-script-pkg.js
low

Path/Environment Variable Mutation

NPS-AC367AB5C20D

The function modifies PATH-like environment variables to inject directories walking up from projectPath to filesystem root. While this is consistent with npm's run-script behavior, it manipulates environment state broadly and resolves paths outside the immediate package scope.

lib/set-path.js:39

Files reviewed

FileVerdictWhat the reviewer saw
lib/make-spawn-args.js medium The code is a utility for npm lifecycle scripts that handles environment variables and process spawning; it contains standard patterns that could be risky if inputs are not trusted, but no overt malicious behavior is evident.
lib/run-script-pkg.js medium This is a legitimate npm lifecycle script runner with no direct malicious patterns, but it executes package-defined commands and merges environment variables, which are inherent risks in any script-executing module.
lib/set-path.js medium The file constructs and mutates PATH environment variables for npm script execution; no credential harvesting, network calls, obfuscation, or process spawning were detected, but it does broadly modify environment state.
lib/is-server-package.js safe Cleared by Jev triage; no further analysis needed
lib/package-envs.js safe Cleared by Jev triage; no further analysis needed
lib/run-script.js safe The file is a thin wrapper around npm's run-script-pkg that normalizes package.json and delegates execution; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or shell spawning were detected.
lib/signal-manager.js safe No malicious patterns detected; the code is a legitimate signal-forwarding helper for child processes.
lib/validate-options.js safe Cleared by Jev triage; no further analysis needed

Scanned versions of @npmcli/run-script

VersionVerdictFilesScanned
10.0.4 Needs review 8 Oct 6, 2026

Frequently asked questions

Is @npmcli/run-script safe to use?

No confirmed malware was found in @npmcli/run-script@10.0.4, but the review flagged 2 medium, 6 low severity findings for risky patterns worth checking before you rely on it.

Does @npmcli/run-script contain malware?

No malware was identified in @npmcli/run-script@10.0.4 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @npmcli/run-script checked?

Togoder Security downloaded the published npm package and had an AI model read its 8 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @npmcli/run-script together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @npmcli/run-script@10.0.4, cost nothing.

Related security reports