# libnpmpack@9.1.12 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:23:19.000Z
- Files reviewed: 1
- Findings: 2 medium, 2 low severity findings
- Report: https://security.togoder.click/npm/libnpmpack
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package libnpmpack@9.1.12 on Oct 6, 2026. An AI review of 1 source file produced 2 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Lifecycle Script Execution

Finding ID: `NPS-7B1424259FC5`

File: `lib/index.js:21`

The code executes package lifecycle scripts ('prepack' and 'postpack') via @npmcli/run-script when packing a directory. While this is standard npm behavior for `npm pack`, in a third-party package this can execute arbitrary code from a target package's package.json. If invoked on untrusted input (e.g., an attacker-controlled directory or package spec), it could lead to arbitrary command execution.

### [medium] Lifecycle Script Execution

Finding ID: `NPS-B9526BF45F39`

File: `lib/index.js:46`

The code runs the 'postpack' script with environment variables derived from the tarball, again via @npmcli/run-script. This is expected behavior for an npm pack utility but represents a code-execution surface.

### [low] Network Fetch via pacote

Finding ID: `NPS-E6DE3BC05A95`

File: `lib/index.js:17`

Uses `pacote.manifest` and `pacote.tarball` to fetch manifests/tarballs from network registries based on the provided spec. This is inherent to the package manager function and expected, but means the module will perform outbound network requests based on input spec.

### [low] Filesystem Write

Finding ID: `NPS-883169093C56`

File: `lib/index.js:38`

Writes the packed tarball to a destination resolved from `opts.packDestination`. Destination path is user-controlled via opts, which is normal CLI behavior but should be validated to avoid unintended writes (e.g., path traversal if a malicious caller controls packDestination).

## Files reviewed

- `lib/index.js` (medium): This appears to be a legitimate npm pack utility (functionally similar to `npm pack`) that fetches manifests/tarballs and runs standard prepack/postpack lifecycle scripts; no malicious exfiltration, credential harvesting, obfuscation, or backdoor patterns were detected, though lifecycle script execution and network fetches are inherent risks to be aware of.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
