# libnpmexec@10.3.2 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:23:17.000Z
- Files reviewed: 8
- Findings: 2 medium, 4 low severity findings
- Report: https://security.togoder.click/npm/libnpmexec
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package libnpmexec@10.3.2 on Oct 6, 2026. An AI review of 8 source files produced 2 medium, 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Command injection potential

Finding ID: `NPS-DF62BC58CD52`

File: `lib/run-script.js:21`

The args array is passed to runScript and executed as a shell command. Although there is an attempt to escape the executable path on non-Windows systems by single-quoting, the remaining args are passed without sanitization, which could lead to command injection if untrusted input reaches this function.

### [medium] Shell command execution

Finding ID: `NPS-0CFB98E6E394`

File: `lib/run-script.js:62`

The code uses @npmcli/run-script to execute arbitrary shell commands. While this is the intended purpose of the npx command, it represents a process spawning capability that could be abused if the module is compromised or if arguments are not properly sanitized.

### [low] Environment variable and credential access

Finding ID: `NPS-9B4120BB59C1`

File: `lib/run-script.js:38`

The code loads package.json and flatOptions which may contain environment variables, registry credentials, and other sensitive configuration. This is normal for npm CLI tools but represents access to potentially sensitive data.

### [low] file system manipulation

Finding ID: `NPS-5E6AE30EBCE3`

File: `lib/with-lock.js`

Uses fs.utimes to touch lock files for liveness detection. This is a normal part of lock maintenance.

### [low] file system manipulation

Finding ID: `NPS-DF35791A8667`

File: `lib/with-lock.js:48`

Creates and removes lock directories (mkdir, rmdirSync) at user-provided lockPath. This is intended behavior for a lockfile library and does not indicate exfiltration or malicious activity.

### [low] timing/race condition

Finding ID: `NPS-B4A9BD8C53AB`

File: `lib/with-lock.js:62`

Stale lock detection and removal have a small window where another process could also delete and recreate the lock; the code acknowledges and attempts to detect this via inode/mtime checks.

## Files reviewed

- `lib/run-script.js` (medium): This is legitimate npm CLI code for running npx scripts, but it executes arbitrary shell commands with potential command injection risks if untrusted input is passed as arguments.
- `lib/file-exists.js` (safe): The code is a straightforward utility for locating local binaries in node_modules/.bin directories, using only filesystem stat checks with no network, process execution, or obfuscated behavior.
- `lib/get-bin-from-manifest.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/index.js` (safe): This is the legitimate npm exec implementation that resolves and runs packages without any malicious patterns such as data exfiltration, credential theft, or backdoors.
- `lib/is-windows.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/no-tty.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/strict-allow-scripts-preflight.js` (safe): No malicious patterns detected
- `lib/with-lock.js` (safe): The code implements a standard advisory lockfile mechanism with no evidence of data exfiltration, credential harvesting, obfuscation, or other malicious patterns.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
