# @pnpm/npm-conf@3.0.2 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:11:41.000Z
- Files reviewed: 7
- Findings: 12 low severity findings
- Report: https://security.togoder.click/npm/@pnpm/npm-conf
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @pnpm/npm-conf@3.0.2 on Oct 6, 2026. An AI review of 7 source files produced 12 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] dynamic module resolution

Finding ID: `NPS-4BDE3D006C28`

File: `index.js:18`

Uses require.resolve('npm', {paths: paths.slice(-1)}) with computed paths to locate the built-in npm module and derive its npmrc location. This is a computed module resolution but is constrained to npm's own package and is not driven by untrusted external input.

### [low] credential/config file access

Finding ID: `NPS-8175B4F2836A`

File: `index.js:31`

The module loads npm configuration from multiple locations including project .npmrc, workspace .npmrc, user config (~/.npmrc), global config, and a built-in npmrc derived from the resolved npm package path. These files frequently contain authentication tokens and registry credentials. While this mirrors standard npm CLI config loading behavior, it means the package reads potentially sensitive credential-bearing configuration files at import time.

### [low] environment variable harvesting

Finding ID: `NPS-FCF3ADC48140`

File: `index.js:36`

Calls conf.addEnv() which reads environment variables into the configuration object. Environment variables can contain npm auth tokens (e.g. NPM_TOKEN) and other secrets. This is expected behavior for a config loader but represents secret ingestion.

### [low] filesystem access outside package scope

Finding ID: `NPS-B416C94672B4`

File: `index.js:44`

Resolves and reads configuration files at absolute paths derived from the user's home directory (userconfig), global prefix/etc (globalconfig), and project/workspace directories, reaching well outside the package's own directory tree.

### [low] File system access outside package scope

Finding ID: `NPS-E037D4549EF8`

File: `lib/conf.js:42`

Methods like addFile, loadCAFile, loadUser, and loadPrefix read files from the local filesystem (e.g., .npmrc files, CA files, prefix directory) and access process.cwd(). This is typical for a configuration loader but could be used to read sensitive files if paths are controlled by an attacker.

### [low] Environment variable harvesting

Finding ID: `NPS-1567BFDADA0E`

File: `lib/conf.js:78`

The addEnv method reads all environment variables matching /^npm_config_/i and processes them. While this is standard for npm/pnpm config loading, it could capture sensitive values like tokens if they are passed via environment variables with npm_config_ prefix.

### [low] Credential access via SUDO_UID

Finding ID: `NPS-738BAFB3D88E`

File: `lib/conf.js:170`

The loadUser method reads process.env.SUDO_UID to determine the user. While not directly harvesting credentials, it relies on environment variables that could be manipulated.

### [low] Environment variable and credential harvesting

Finding ID: `NPS-F09676EFB0F2`

File: `lib/defaults.js`

The code reads process.env.HOME, process.env.EDITOR, process.env.VISUAL, process.env.COMSPEC, process.env.SHELL, process.env.PREFIX, process.env.DESTDIR, process.env.APPDATA, process.env.NO_COLOR, process.env.SUDO_GID, process.env.TRAVIS, and process.env.CI. It also computes paths to user configuration files such as ~/.npmrc and ~/.npm-init.js. While these are standard npm configuration lookups, the pattern of harvesting environment and user-specific config paths is a common precursor to credential theft if the values are exfiltrated elsewhere. In this isolated file there is no exfiltration, but the behavior warrants a warning.

### [low] File system path manipulation outside package scope

Finding ID: `NPS-421E1CDF84BD`

File: `lib/defaults.js`

The module determines and stores paths to global npm configuration (globalconfig), user npm configuration (userconfig), npm cache directory, home directory, and prefix directory. It also mutates process.env.HOME if os.homedir() returns a value. These operations read and potentially influence the filesystem environment outside the package's own scope, which could be abused by a malicious actor to redirect configuration or cache locations.

### [low] Environment access in generated template (not executed by this file)

Finding ID: `NPS-80395B84EAAF`

File: `lib/make.js:14`

The generated template (defaultsTemplate) references process.env, os.tmpdir, home directory, and npm cache paths. This is normal npm config default code and is not executed during this script's execution—it is only embedded as a string into generated output.

### [low] Reading dependency source file

Finding ID: `NPS-7C5E97147B48`

File: `lib/make.js:61`

The script reads npm's config defaults file from node_modules and transforms it via babylon/babel. This is expected behavior for a code generation tool and does not exfiltrate or execute external input.

### [low] Filesystem write within package scope

Finding ID: `NPS-1CBD16A2E2AE`

File: `lib/make.js:80`

The script writes generated files (defaults.js and types.js) into its own __dirname. It reads from a resolved dependency path (npm/lib/config/defaults) and writes only within the package directory. This is a code generation/build-time script and not malicious in nature.

## Files reviewed

- `index.js` (medium): The file is a standard npm configuration loader that reads .npmrc files and environment variables (which may contain credentials) but shows no data exfiltration, code execution, network activity, or other clearly malicious behavior.
- `lib/conf.js` (medium): The code appears to be a legitimate configuration loader for pnpm, but it accesses environment variables and the filesystem, which are common vectors for credential harvesting if abused.
- `lib/defaults.js` (medium): This file contains standard npm configuration defaults but performs environment variable harvesting and filesystem path manipulation that, while typical for npm, could be leveraged for credential theft or configuration hijacking.
- `lib/envKeyToSetting.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/make.js` (safe): The file is a benign code-generation script that transforms npm's config defaults into local defaults.js/types.js files, with no exfiltration, dynamic execution, or suspicious network/process activity.
- `lib/types.js` (safe): This file is a static configuration type definition module from npm's config system and contains no executable malicious logic, network operations, or credential harvesting.
- `lib/util.js` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
