Togoder security

npm package security report

@sigstore/tuf@4.0.2 security report

Risky patterns found that deserve a look.

Needs review Version 4.0.2 Files reviewed 5 Size 11.5 KB Scanned

Summary

Togoder Security scanned the npm package @sigstore/tuf@4.0.2 on Oct 6, 2026. An AI review of 5 source files produced 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
4
low

Findings 4

low

Legitimate platform-specific path resolution

NPS-4E08E18B3829

The code computes standard application data directories using os.homedir(), process.env.XDG_DATA_HOME, and process.env.LOCALAPPDATA. These are common, documented environment variables used for resolving user data directories on Linux, macOS, and Windows. No credentials, tokens, or sensitive files (.npmrc, .ssh, .aws, etc.) are read, exfiltrated, or harvested.

dist/appdata.js
low

File system manipulation outside package scope

NPS-85EB7684DFC7

The code creates and writes cache directories (targets, root.json) to a path derived directly from options.cachePath with no validation restricting it to a safe location. A malicious caller could set cachePath to a sensitive directory (e.g. filesystem root or user config dirs), and the code will create directories and copy/write files there. This is a legitimate caching mechanism for a TUF client, but the lack of path confinement is a potential abuse vector.

dist/client.js
low

Dynamic require of external data blob

NPS-70C482B7265D

The code uses require('../seeds.json') and indexes it with the untrusted mirrorURL string: seeds[mirrorURL]. If seeds.json ever contained malicious keys, prototype pollution-style access could occur (e.g. mirrorURL = '__proto__' or 'constructor'). Validating the mirrorURL and using Object.prototype.hasOwnProperty.call would mitigate this.

dist/client.js
low

Encoded payload decoding (base64)

NPS-05CA400C2A15

Base64-decoded content from seeds.json is written directly to disk as root.json and as target files. This is standard for TUF metadata seeding, but writing decoded blobs to the filesystem is worth noting for supply-chain review.

dist/client.js

Files reviewed

FileVerdictWhat the reviewer saw
dist/client.js medium This is a legitimate Sigstore TUF client implementation with no clear malicious behavior, though it performs cache directory creation/file writes based on caller-supplied paths and decodes base64 seed data to disk, warranting caution.
dist/appdata.js safe Code is a benign utility from sigstore that resolves OS-specific application data paths using standard environment variables and homedir; no malicious patterns detected.
dist/error.js safe Cleared by Jev triage; no further analysis needed
dist/index.js safe This is a legitimate Sigstore TUF client initialization module with no malicious patterns detected; it only makes expected network requests to the Sigstore TUF repository.
dist/target.js safe The code is a legitimate Sigstore TUF target reader that only uses fs.readFile and a TUF updater; no malicious patterns were detected.

Frequently asked questions

Is @sigstore/tuf safe to use?

No confirmed malware was found in @sigstore/tuf@4.0.2, but the review flagged 4 low severity findings for risky patterns worth checking before you rely on it.

Does @sigstore/tuf contain malware?

No malware was identified in @sigstore/tuf@4.0.2 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @sigstore/tuf checked?

Togoder Security downloaded the published npm package and had an AI model read its 5 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @sigstore/tuf together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @sigstore/tuf@4.0.2, cost nothing.

Related security reports