Togoder security

npm package security report

config-chain npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 1.1.13 Files reviewed 1 Size 7.0 KB Scanned

Summary

Togoder Security scanned the npm package config-chain@1.1.13 on Oct 6, 2026. An AI review of 1 source file produced 4 medium severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
4
medium
0
low

Findings 4

medium

Network request to arbitrary URL

NPS-22A229433B43

ConfigChain.prototype.addUrl performs an HTTP request to a caller-supplied URL and reads the response body. If an attacker can control the req argument, this allows SSRF and data exfiltration. The use of http.request (rather than https) also permits plaintext transmission of potentially sensitive configuration data.

index.js
medium

File write outside package scope

NPS-8BBA87795D93

ConfigChain.prototype.save writes configuration data to the path stored in target.path, which can be arbitrary (e.g., a path obtained via find or addFile). This allows writing files anywhere the process has permission, which could be abused to overwrite configuration or inject content into other applications.

index.js
medium

Arbitrary file read via path traversal

NPS-65ACD28CF6EB

The find function recursively traverses up the directory tree from __dirname using path.dirname until reaching the filesystem root, attempting to locate a file matching the supplied relative path. If an attacker can influence the arguments passed to find, they could read arbitrary files anywhere on the filesystem. This pattern is commonly used to locate configuration files such as .npmrc in parent directories, which is a typical step in credential-harvesting attacks.

index.js:22
medium

Environment variable harvesting

NPS-66DC03577D9B

The env function copies all environment variables that start with a given prefix into an object. If invoked with a sensitive prefix (e.g., npm_config_, AWS_, GITHUB_), it can collect credentials and secrets from the process environment. While this is a legitimate utility for configuration, in a malicious context it would facilitate exfiltration.

index.js:60

Files reviewed

FileVerdictWhat the reviewer saw
index.js medium The module is a configuration loader with legitimate functionality, but it contains dangerous primitives—recursive parent-directory file discovery, environment variable harvesting, arbitrary HTTP requests, and arbitrary file writes—that could be abused for reconnaissance or data exfiltration if invoked with attacker-controlled arguments.

Scanned versions of config-chain

VersionVerdictFilesScanned
1.1.13 Needs review 1 Oct 6, 2026

Frequently asked questions

Is config-chain safe to use?

No confirmed malware was found in config-chain@1.1.13, but the review flagged 4 medium severity findings for risky patterns worth checking before you rely on it.

Does config-chain contain malware?

No malware was identified in config-chain@1.1.13 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was config-chain checked?

Togoder Security downloaded the published npm package and had an AI model read its 1 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan config-chain together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in config-chain@1.1.13, cost nothing.

Related security reports