# bin-links@6.0.2 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:23:13.000Z
- Files reviewed: 15
- Findings: 4 medium, 2 low severity findings
- Report: https://security.togoder.click/npm/bin-links
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package bin-links@6.0.2 on Oct 6, 2026. An AI review of 15 source files produced 4 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] File system manipulation outside package scope

Finding ID: `NPS-0E03852FC849`

File: `lib/fix-bin.js:1`

The fixBin function accepts an arbitrary file path and will chmod it to 0o777 (minus umask) and potentially rewrite it. If invoked by other package code with paths outside the package (e.g., system binaries or user scripts), it could alter permissions of unrelated files.

### [medium] File system manipulation

Finding ID: `NPS-41699BEB19E7`

File: `lib/fix-bin.js:24`

The script modifies file permissions with chmod using mode 0o777 (masked by umask) and rewrites bin files to convert Windows line endings to Unix. This changes executable permissions and file contents on the user's system, potentially weakening security if applied broadly.

### [medium] File system manipulation outside package scope

Finding ID: `NPS-9CB1C89B6ECA`

File: `lib/index.js`

The module links binaries and man pages into system-wide locations when run globally (e.g. {prefix}/bin, {prefix}/share/man) and into node_modules/.bin for local packages. This is expected behavior for a package installer/linker (npm's bin-links), but it modifies files outside the package's own directory, which is a potential security concern if the source or options are untrusted.

### [medium] Dynamic module loading / dependency resolution

Finding ID: `NPS-20D16BD78B26`

File: `lib/index.js:1`

The code requires several local modules (./link-bins.js, ./link-mans.js, ./shim-bin.js, ./link-gently.js, ./check-bins.js, ./get-paths.js). These files were not provided for review, so their behavior cannot be verified. In a real audit, these dependencies must be inspected for malicious or obfuscated code.

### [low] Dependency risk

Finding ID: `NPS-D2A74C7E5708`

File: `lib/fix-bin.js:7`

Uses write-file-atomic, which writes to a temporary file and renames it, performing file system operations. While legitimate, it is a third-party dependency that could itself be compromised; combined with the chmod logic, it increases the attack surface for local file tampering.

### [low] Global install path modification

Finding ID: `NPS-D78C2B874E3B`

File: `lib/index.js:15`

When 'top' and 'global' are true, binaries may be installed into system prefix directories. This grants elevated privilege effects if run with sufficient permissions, but no explicit privilege escalation or shell execution is present in the provided file.

## Files reviewed

- `lib/fix-bin.js` (medium): The code is a legitimate utility for fixing executable permissions and hashbang line endings, but its broad chmod and file-rewrite behavior on arbitrary paths presents a moderate security risk if misused or invoked with untrusted input.
- `lib/index.js` (medium): This file is likely npm's bin-links module and contains no explicit malicious patterns, but it performs system-level file linking and relies on unaudited local modules, warranting caution.
- `lib/bin-target.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/check-bin.js` (safe): No malicious patterns detected
- `lib/check-bins.js` (safe): No malicious patterns detected; the module only performs package bin conflict checking via local helper functions.
- `lib/get-node-modules.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/get-paths.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/get-prefix.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/is-windows.js` (safe): No malicious patterns detected
- `lib/link-bin.js` (safe): No malicious patterns detected
- `lib/link-bins.js` (safe): No malicious patterns detected
- `lib/link-gently.js` (safe): No malicious patterns detected; the code performs benign symlink management for package binaries and manpages with no network, credential, or code-execution behavior.
- `lib/link-mans.js` (safe): No malicious patterns detected; the code performs legitimate man page link management with proper path sanitization and validation.
- `lib/man-target.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/shim-bin.js` (safe): This npm bin shim utility contains no malicious patterns; it only uses standard path/fs modules and well-known shim libraries to create command shims, with no network, credential, or dynamic-execution behavior.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
