Summary
Togoder Security scanned the npm package config-chain@1.1.13 on Oct 6, 2026. An AI review of 1 source file produced 4 medium severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 4
Network request to arbitrary URL
NPS-22A229433B43
ConfigChain.prototype.addUrl performs an HTTP request to a caller-supplied URL and reads the response body. If an attacker can control the req argument, this allows SSRF and data exfiltration. The use of http.request (rather than https) also permits plaintext transmission of potentially sensitive configuration data.
File write outside package scope
NPS-8BBA87795D93
ConfigChain.prototype.save writes configuration data to the path stored in target.path, which can be arbitrary (e.g., a path obtained via find or addFile). This allows writing files anywhere the process has permission, which could be abused to overwrite configuration or inject content into other applications.
Arbitrary file read via path traversal
NPS-65ACD28CF6EB
The find function recursively traverses up the directory tree from __dirname using path.dirname until reaching the filesystem root, attempting to locate a file matching the supplied relative path. If an attacker can influence the arguments passed to find, they could read arbitrary files anywhere on the filesystem. This pattern is commonly used to locate configuration files such as .npmrc in parent directories, which is a typical step in credential-harvesting attacks.
Environment variable harvesting
NPS-66DC03577D9B
The env function copies all environment variables that start with a given prefix into an object. If invoked with a sensitive prefix (e.g., npm_config_, AWS_, GITHUB_), it can collect credentials and secrets from the process environment. While this is a legitimate utility for configuration, in a malicious context it would facilitate exfiltration.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| index.js | medium | The module is a configuration loader with legitimate functionality, but it contains dangerous primitives—recursive parent-directory file discovery, environment variable harvesting, arbitrary HTTP requests, and arbitrary file writes—that could be abused for reconnaissance or data exfiltration if invoked with attacker-controlled arguments. |
Frequently asked questions
Is config-chain safe to use?
No confirmed malware was found in config-chain@1.1.13, but the review flagged 4 medium severity findings for risky patterns worth checking before you rely on it.
Does config-chain contain malware?
No malware was identified in config-chain@1.1.13 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was config-chain checked?
Togoder Security downloaded the published npm package and had an AI model read its 1 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan config-chain together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in config-chain@1.1.13, cost nothing.