Togoder security

npm package security report

@pnpm/npm-conf npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 3.0.2 Files reviewed 7 Size 20.9 KB Scanned

Summary

Togoder Security scanned the npm package @pnpm/npm-conf@3.0.2 on Oct 6, 2026. An AI review of 7 source files produced 12 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
12
low

Findings 12

low

dynamic module resolution

NPS-4BDE3D006C28

Uses require.resolve('npm', {paths: paths.slice(-1)}) with computed paths to locate the built-in npm module and derive its npmrc location. This is a computed module resolution but is constrained to npm's own package and is not driven by untrusted external input.

index.js:18
low

credential/config file access

NPS-8175B4F2836A

The module loads npm configuration from multiple locations including project .npmrc, workspace .npmrc, user config (~/.npmrc), global config, and a built-in npmrc derived from the resolved npm package path. These files frequently contain authentication tokens and registry credentials. While this mirrors standard npm CLI config loading behavior, it means the package reads potentially sensitive credential-bearing configuration files at import time.

index.js:31
low

environment variable harvesting

NPS-FCF3ADC48140

Calls conf.addEnv() which reads environment variables into the configuration object. Environment variables can contain npm auth tokens (e.g. NPM_TOKEN) and other secrets. This is expected behavior for a config loader but represents secret ingestion.

index.js:36
low

filesystem access outside package scope

NPS-B416C94672B4

Resolves and reads configuration files at absolute paths derived from the user's home directory (userconfig), global prefix/etc (globalconfig), and project/workspace directories, reaching well outside the package's own directory tree.

index.js:44
low

File system access outside package scope

NPS-E037D4549EF8

Methods like addFile, loadCAFile, loadUser, and loadPrefix read files from the local filesystem (e.g., .npmrc files, CA files, prefix directory) and access process.cwd(). This is typical for a configuration loader but could be used to read sensitive files if paths are controlled by an attacker.

lib/conf.js:42
low

Environment variable harvesting

NPS-1567BFDADA0E

The addEnv method reads all environment variables matching /^npm_config_/i and processes them. While this is standard for npm/pnpm config loading, it could capture sensitive values like tokens if they are passed via environment variables with npm_config_ prefix.

lib/conf.js:78
low

Credential access via SUDO_UID

NPS-738BAFB3D88E

The loadUser method reads process.env.SUDO_UID to determine the user. While not directly harvesting credentials, it relies on environment variables that could be manipulated.

lib/conf.js:170
low

Environment variable and credential harvesting

NPS-F09676EFB0F2

The code reads process.env.HOME, process.env.EDITOR, process.env.VISUAL, process.env.COMSPEC, process.env.SHELL, process.env.PREFIX, process.env.DESTDIR, process.env.APPDATA, process.env.NO_COLOR, process.env.SUDO_GID, process.env.TRAVIS, and process.env.CI. It also computes paths to user configuration files such as ~/.npmrc and ~/.npm-init.js. While these are standard npm configuration lookups, the pattern of harvesting environment and user-specific config paths is a common precursor to credential theft if the values are exfiltrated elsewhere. In this isolated file there is no exfiltration, but the behavior warrants a warning.

lib/defaults.js
low

File system path manipulation outside package scope

NPS-421E1CDF84BD

The module determines and stores paths to global npm configuration (globalconfig), user npm configuration (userconfig), npm cache directory, home directory, and prefix directory. It also mutates process.env.HOME if os.homedir() returns a value. These operations read and potentially influence the filesystem environment outside the package's own scope, which could be abused by a malicious actor to redirect configuration or cache locations.

lib/defaults.js
low

Environment access in generated template (not executed by this file)

NPS-80395B84EAAF

The generated template (defaultsTemplate) references process.env, os.tmpdir, home directory, and npm cache paths. This is normal npm config default code and is not executed during this script's execution—it is only embedded as a string into generated output.

lib/make.js:14
low

Reading dependency source file

NPS-7C5E97147B48

The script reads npm's config defaults file from node_modules and transforms it via babylon/babel. This is expected behavior for a code generation tool and does not exfiltrate or execute external input.

lib/make.js:61
low

Filesystem write within package scope

NPS-1CBD16A2E2AE

The script writes generated files (defaults.js and types.js) into its own __dirname. It reads from a resolved dependency path (npm/lib/config/defaults) and writes only within the package directory. This is a code generation/build-time script and not malicious in nature.

lib/make.js:80

Files reviewed

FileVerdictWhat the reviewer saw
index.js medium The file is a standard npm configuration loader that reads .npmrc files and environment variables (which may contain credentials) but shows no data exfiltration, code execution, network activity, or other clearly malicious behavior.
lib/conf.js medium The code appears to be a legitimate configuration loader for pnpm, but it accesses environment variables and the filesystem, which are common vectors for credential harvesting if abused.
lib/defaults.js medium This file contains standard npm configuration defaults but performs environment variable harvesting and filesystem path manipulation that, while typical for npm, could be leveraged for credential theft or configuration hijacking.
lib/envKeyToSetting.js safe Cleared by Jev triage; no further analysis needed
lib/make.js safe The file is a benign code-generation script that transforms npm's config defaults into local defaults.js/types.js files, with no exfiltration, dynamic execution, or suspicious network/process activity.
lib/types.js safe This file is a static configuration type definition module from npm's config system and contains no executable malicious logic, network operations, or credential harvesting.
lib/util.js safe No malicious patterns detected

Scanned versions of @pnpm/npm-conf

VersionVerdictFilesScanned
3.0.2 Needs review 7 Oct 6, 2026

Frequently asked questions

Is @pnpm/npm-conf safe to use?

No confirmed malware was found in @pnpm/npm-conf@3.0.2, but the review flagged 12 low severity findings for risky patterns worth checking before you rely on it.

Does @pnpm/npm-conf contain malware?

No malware was identified in @pnpm/npm-conf@3.0.2 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @pnpm/npm-conf checked?

Togoder Security downloaded the published npm package and had an AI model read its 7 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @pnpm/npm-conf together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @pnpm/npm-conf@3.0.2, cost nothing.

Related security reports