Summary
Togoder Security scanned the npm package @npmcli/run-script@10.0.4 on Oct 6, 2026. An AI review of 8 source files produced 2 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 8
Dynamic module resolution
NPS-4BB62A55C14C
Uses require.resolve('node-gyp/bin/node-gyp.js') to dynamically resolve a module path, which could be influenced by the environment (npm_config_node_gyp) to point to an arbitrary file. This could allow execution of an attacker-controlled script if the environment variable is set maliciously.
Shell command execution
NPS-B34DF12A5FC9
This module executes lifecycle scripts defined in package.json (e.g., preinstall, install, postinstall, start) via @npmcli/promise-spawn. While this is the intended behavior of npm's script runner, a compromised package.json can execute arbitrary commands during install/build. The code itself is not malicious, but it is a powerful execution vector.
Environment variable harvesting
NPS-896A1902176F
The code reads and merges all environment variables from process.env and options.env, then includes them in the spawned process environment. This is standard for npm lifecycle scripts but could expose sensitive environment variables to child processes if not properly sanitized.
Process spawning
NPS-F4F9BA5BA9E8
The function constructs arguments and options for spawning a child process, returning them to the caller. While it does not directly spawn the process, it facilitates process execution with a configurable shell (scriptShell) and environment, which could be abused if inputs are not validated.
Environment variable merging
NPS-F5BF83E90E13
Environment variables from the parent process are merged with package-specific environment variables (packageEnvs(pkg)) and passed to spawned child processes. This is standard npm behavior, but in a malicious dependency it could be abused to leak or alter sensitive environment variables to child processes.
Fallback command execution
NPS-31388437DC0D
If no explicit script exists, the code may automatically execute 'node server.js' for packages detected as server packages, or run node-gyp rebuild for packages with a gypfile. This automatic fallback execution could be unexpected.
Signal propagation
NPS-B4B578B6DD6A
When stdio is 'inherit' and a child process exits with a signal, the parent process re-raises the same signal on itself. This is designed for proper exit status propagation but could be misused if a child is manipulated to send unexpected signals.
Path/Environment Variable Mutation
NPS-AC367AB5C20D
The function modifies PATH-like environment variables to inject directories walking up from projectPath to filesystem root. While this is consistent with npm's run-script behavior, it manipulates environment state broadly and resolves paths outside the immediate package scope.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/make-spawn-args.js | medium | The code is a utility for npm lifecycle scripts that handles environment variables and process spawning; it contains standard patterns that could be risky if inputs are not trusted, but no overt malicious behavior is evident. |
| lib/run-script-pkg.js | medium | This is a legitimate npm lifecycle script runner with no direct malicious patterns, but it executes package-defined commands and merges environment variables, which are inherent risks in any script-executing module. |
| lib/set-path.js | medium | The file constructs and mutates PATH environment variables for npm script execution; no credential harvesting, network calls, obfuscation, or process spawning were detected, but it does broadly modify environment state. |
| lib/is-server-package.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/package-envs.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/run-script.js | safe | The file is a thin wrapper around npm's run-script-pkg that normalizes package.json and delegates execution; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or shell spawning were detected. |
| lib/signal-manager.js | safe | No malicious patterns detected; the code is a legitimate signal-forwarding helper for child processes. |
| lib/validate-options.js | safe | Cleared by Jev triage; no further analysis needed |
Scanned versions of @npmcli/run-script
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 10.0.4 | Needs review | 8 | Oct 6, 2026 |
Frequently asked questions
Is @npmcli/run-script safe to use?
No confirmed malware was found in @npmcli/run-script@10.0.4, but the review flagged 2 medium, 6 low severity findings for risky patterns worth checking before you rely on it.
Does @npmcli/run-script contain malware?
No malware was identified in @npmcli/run-script@10.0.4 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @npmcli/run-script checked?
Togoder Security downloaded the published npm package and had an AI model read its 8 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @npmcli/run-script together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @npmcli/run-script@10.0.4, cost nothing.