# @npmcli/run-script@10.0.4 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:23:05.000Z
- Files reviewed: 8
- Findings: 2 medium, 6 low severity findings
- Report: https://security.togoder.click/npm/@npmcli/run-script
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @npmcli/run-script@10.0.4 on Oct 6, 2026. An AI review of 8 source files produced 2 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic module resolution

Finding ID: `NPS-4BB62A55C14C`

File: `lib/make-spawn-args.js:26`

Uses require.resolve('node-gyp/bin/node-gyp.js') to dynamically resolve a module path, which could be influenced by the environment (npm_config_node_gyp) to point to an arbitrary file. This could allow execution of an attacker-controlled script if the environment variable is set maliciously.

### [medium] Shell command execution

Finding ID: `NPS-B34DF12A5FC9`

File: `lib/run-script-pkg.js`

This module executes lifecycle scripts defined in package.json (e.g., preinstall, install, postinstall, start) via @npmcli/promise-spawn. While this is the intended behavior of npm's script runner, a compromised package.json can execute arbitrary commands during install/build. The code itself is not malicious, but it is a powerful execution vector.

### [low] Environment variable harvesting

Finding ID: `NPS-896A1902176F`

File: `lib/make-spawn-args.js:32`

The code reads and merges all environment variables from process.env and options.env, then includes them in the spawned process environment. This is standard for npm lifecycle scripts but could expose sensitive environment variables to child processes if not properly sanitized.

### [low] Process spawning

Finding ID: `NPS-F4F9BA5BA9E8`

File: `lib/make-spawn-args.js:40`

The function constructs arguments and options for spawning a child process, returning them to the caller. While it does not directly spawn the process, it facilitates process execution with a configurable shell (scriptShell) and environment, which could be abused if inputs are not validated.

### [low] Environment variable merging

Finding ID: `NPS-F5BF83E90E13`

File: `lib/run-script-pkg.js`

Environment variables from the parent process are merged with package-specific environment variables (packageEnvs(pkg)) and passed to spawned child processes. This is standard npm behavior, but in a malicious dependency it could be abused to leak or alter sensitive environment variables to child processes.

### [low] Fallback command execution

Finding ID: `NPS-31388437DC0D`

File: `lib/run-script-pkg.js`

If no explicit script exists, the code may automatically execute 'node server.js' for packages detected as server packages, or run node-gyp rebuild for packages with a gypfile. This automatic fallback execution could be unexpected.

### [low] Signal propagation

Finding ID: `NPS-B4B578B6DD6A`

File: `lib/run-script-pkg.js`

When stdio is 'inherit' and a child process exits with a signal, the parent process re-raises the same signal on itself. This is designed for proper exit status propagation but could be misused if a child is manipulated to send unexpected signals.

### [low] Path/Environment Variable Mutation

Finding ID: `NPS-AC367AB5C20D`

File: `lib/set-path.js:39`

The function modifies PATH-like environment variables to inject directories walking up from projectPath to filesystem root. While this is consistent with npm's run-script behavior, it manipulates environment state broadly and resolves paths outside the immediate package scope.

## Files reviewed

- `lib/make-spawn-args.js` (medium): The code is a utility for npm lifecycle scripts that handles environment variables and process spawning; it contains standard patterns that could be risky if inputs are not trusted, but no overt malicious behavior is evident.
- `lib/run-script-pkg.js` (medium): This is a legitimate npm lifecycle script runner with no direct malicious patterns, but it executes package-defined commands and merges environment variables, which are inherent risks in any script-executing module.
- `lib/set-path.js` (medium): The file constructs and mutates PATH environment variables for npm script execution; no credential harvesting, network calls, obfuscation, or process spawning were detected, but it does broadly modify environment state.
- `lib/is-server-package.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/package-envs.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/run-script.js` (safe): The file is a thin wrapper around npm's run-script-pkg that normalizes package.json and delegates execution; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or shell spawning were detected.
- `lib/signal-manager.js` (safe): No malicious patterns detected; the code is a legitimate signal-forwarding helper for child processes.
- `lib/validate-options.js` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
