Summary
Togoder Security scanned the npm package @sigstore/sign@4.1.1 on Oct 6, 2026. An AI review of 33 source files produced 4 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 5
Environment variable harvesting
NPS-003974952C10
The code reads process.env.ACTIONS_ID_TOKEN_REQUEST_URL, process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN, and process.env.SIGSTORE_ID_TOKEN. These are CI/CD OIDC token credentials. While this is expected behavior for a Sigstore identity provider, it demonstrates access to sensitive authentication tokens from the environment.
Suspicious network request
NPS-7162404D4765
The getGHAToken function makes an HTTP request to the URL provided by the ACTIONS_ID_TOKEN_REQUEST_URL environment variable, attaching the ACTIONS_ID_TOKEN_REQUEST_TOKEN as a Bearer token in the Authorization header. This transmits the CI token to that URL. In a legitimate GitHub Actions context this URL is GitHub's OIDC endpoint, but the destination is fully controlled by the environment variable.
Potential unhandled flow control
NPS-C19BCA982C58
createSigningCertificate calls internalError inside a catch block but does not return or rethrow after invoking it. Depending on the implementation of internalError, execution may continue and attempt to access cert.chain on a possibly undefined cert, or silently proceed with an undefined return value.
Undefined variable reference
NPS-455094CCF49A
In toCertificateRequest, the field is assigned 'identity' which is not defined in the function scope. The function parameter is 'identityToken'. This either indicates a typo that will cause a ReferenceError at runtime or references an undeclared global variable, which could silently break certificate signing or mask a deeper bug.
Network communication
NPS-CE97D83E3E56
The CAClient communicates with a Fulcio certificate authority via a baseURL supplied through options.fulcioBaseURL. This is expected for a signing client but represents external network transmission of a public key and OIDC identity token to a configurable endpoint; if the base URL is attacker-controlled this could leak credentials.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/identity/ci.js | medium | This appears to be a legitimate Sigstore CIContextProvider that harvests CI OIDC tokens from environment variables and sends them to the environment-specified GitHub Actions token endpoint; the behavior is expected for the package but involves credential handling and network requests that warrant review. |
| dist/signer/fulcio/ca.js | medium | The file contains no overtly malicious patterns, but has a clear bug (undefined 'identity' variable) and a potential missing return/rethrow in error handling that could cause runtime failures or unintended behavior. |
| dist/bundler/base.js | safe | No malicious patterns detected; the code is a straightforward base class implementation for signing and witnessing artifacts without any suspicious activities. |
| dist/bundler/bundle.js | safe | No malicious patterns detected; the file is standard TypeScript bundler helper code for Sigstore bundle assembly with no data exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/bundler/dsse.js | safe | No malicious patterns detected; the code is a legitimate Sigstore DSSE bundle builder with no exfiltration, credential harvesting, dynamic execution, or process spawning. |
| dist/bundler/index.js | safe | No malicious patterns detected |
| dist/bundler/message.js | safe | No malicious patterns detected |
| dist/config.js | safe | No malicious patterns detected; the code is a legitimate Sigstore configuration module that only constructs signer and witness objects from provided configuration without any exfiltration, obfuscation, or suspicious behavior. |
| dist/error.js | safe | No malicious patterns detected |
| dist/external/error.js | safe | No malicious patterns detected |
| dist/external/fetch.js | safe | No malicious patterns detected; the code is a standard fetch-with-retry utility from the Sigstore project with no exfiltration, credential harvesting, obfuscation, or process spawning. |
| dist/external/fulcio.js | safe | No malicious patterns detected; the code is a legitimate Fulcio API client for Sigstore that makes expected network requests to a configurable baseURL. |
| dist/external/rekor-v2.js | safe | No malicious patterns detected; the code is a legitimate Sigstore Rekor v2 API client that only performs expected network requests to a configurable base URL. |
| dist/external/rekor.js | safe | No malicious patterns detected |
| dist/external/tsa.js | safe | No malicious patterns detected; the code is a legitimate Sigstore Timestamp Authority client that makes expected network requests for timestamping. |
| dist/identity/index.js | safe | The file is a simple re-export module from a Sigstore identity package with no malicious patterns, network activity, filesystem access, or dynamic code execution. |
| dist/identity/provider.js | safe | No malicious patterns detected |
| dist/index.js | safe | No malicious patterns detected; the file only re-exports public API symbols from internal modules without any suspicious behavior. |
| dist/signer/fulcio/ephemeral.js | safe | No malicious patterns detected; the code is a legitimate Sigstore ephemeral keypair signer that generates an in-memory P-256 keypair and signs data using Node's crypto module without any exfiltration, obfuscation, or suspicious behavior. |
| dist/signer/fulcio/index.js | safe | The code implements a legitimate Fulcio certificate signer for sigstore, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or backdoor installation. |
| dist/signer/index.js | safe | No malicious patterns detected; the file is a simple re-export module for the Sigstore Fulcio signer. |
| dist/signer/signer.js | safe | No malicious patterns detected |
| dist/types/fetch.js | safe | No malicious patterns detected |
| dist/util/index.js | safe | No malicious patterns detected; the file is a standard TypeScript-generated utility module from the Sigstore project that only re-exports modules and contains no suspicious behavior. |
| dist/util/oidc.js | safe | No malicious patterns detected; the code is a simple utility for extracting the subject from a JWT payload using the @sigstore/core library. |
Show 8 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/util/ua.js | safe | No malicious patterns detected; the file simply builds a User-Agent string using package version, Node version, and OS platform/arch. |
| dist/witness/index.js | safe | No malicious patterns detected; the file is a simple module re-export for Sigstore witness utilities. |
| dist/witness/tlog/client.js | safe | The code is a legitimate Sigstore Rekor transparency log client with no malicious patterns detected. |
| dist/witness/tlog/entry.js | safe | No malicious patterns detected; the code performs legitimate cryptographic entry formatting for Sigstore/Rekor transparency logs. |
| dist/witness/tlog/index.js | safe | No malicious patterns detected |
| dist/witness/tsa/client.js | safe | The code is a legitimate Sigstore TSA client that computes a SHA-256 digest and sends it to a configurable timestamp authority endpoint, with no exfiltration, credential harvesting, obfuscation, or other malicious patterns. |
| dist/witness/tsa/index.js | safe | No malicious patterns detected; the code is a benign Sigstore TSA witness client that creates RFC3161 timestamps via an external TSA without data exfiltration, credential harvesting, obfuscation, or process/network abuse. |
| dist/witness/witness.js | safe | No malicious patterns detected |
Scanned versions of @sigstore/sign
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 4.1.1 | Needs review | 33 | Oct 6, 2026 |
Frequently asked questions
Is @sigstore/sign safe to use?
No confirmed malware was found in @sigstore/sign@4.1.1, but the review flagged 4 medium, 1 low severity findings for risky patterns worth checking before you rely on it.
Does @sigstore/sign contain malware?
No malware was identified in @sigstore/sign@4.1.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @sigstore/sign checked?
Togoder Security downloaded the published npm package and had an AI model read its 33 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @sigstore/sign together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @sigstore/sign@4.1.1, cost nothing.