# config-chain@1.1.13 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:14:50.000Z
- Files reviewed: 1
- Findings: 4 medium severity findings
- Report: https://security.togoder.click/npm/config-chain
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package config-chain@1.1.13 on Oct 6, 2026. An AI review of 1 source file produced 4 medium severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Network request to arbitrary URL

Finding ID: `NPS-22A229433B43`

File: `index.js`

`ConfigChain.prototype.addUrl` performs an HTTP request to a caller-supplied URL and reads the response body. If an attacker can control the `req` argument, this allows SSRF and data exfiltration. The use of `http.request` (rather than `https`) also permits plaintext transmission of potentially sensitive configuration data.

### [medium] File write outside package scope

Finding ID: `NPS-8BBA87795D93`

File: `index.js`

`ConfigChain.prototype.save` writes configuration data to the path stored in `target.path`, which can be arbitrary (e.g., a path obtained via `find` or `addFile`). This allows writing files anywhere the process has permission, which could be abused to overwrite configuration or inject content into other applications.

### [medium] Arbitrary file read via path traversal

Finding ID: `NPS-65ACD28CF6EB`

File: `index.js:22`

The `find` function recursively traverses up the directory tree from `__dirname` using `path.dirname` until reaching the filesystem root, attempting to locate a file matching the supplied relative path. If an attacker can influence the arguments passed to `find`, they could read arbitrary files anywhere on the filesystem. This pattern is commonly used to locate configuration files such as `.npmrc` in parent directories, which is a typical step in credential-harvesting attacks.

### [medium] Environment variable harvesting

Finding ID: `NPS-66DC03577D9B`

File: `index.js:60`

The `env` function copies all environment variables that start with a given prefix into an object. If invoked with a sensitive prefix (e.g., `npm_config_`, `AWS_`, `GITHUB_`), it can collect credentials and secrets from the process environment. While this is a legitimate utility for configuration, in a malicious context it would facilitate exfiltration.

## Files reviewed

- `index.js` (medium): The module is a configuration loader with legitimate functionality, but it contains dangerous primitives—recursive parent-directory file discovery, environment variable harvesting, arbitrary HTTP requests, and arbitrary file writes—that could be abused for reconnaissance or data exfiltration if invoked with attacker-controlled arguments.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
