# node-gyp-build@4.8.4 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:35:59.000Z
- Files reviewed: 5
- Findings: 1 high, 3 medium, 3 low severity findings
- Report: https://security.togoder.click/npm/node-gyp-build
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package node-gyp-build@4.8.4 on Oct 4, 2026. An AI review of 5 source files produced 1 high, 3 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [high] Command execution with user-controlled input

Finding ID: `NPS-6B7E9E54F95A`

File: `bin.js:28`

The `exec` function spawns shell commands using `process.argv[2]` and `process.argv[3]` without any validation. An attacker who can control command-line arguments passed to this script could execute arbitrary shell commands.

### [medium] Dynamic child process spawning

Finding ID: `NPS-A431F751FF12`

File: `bin.js:12`

The script uses `child_process.spawn` and `child_process.exec` to run external commands (`node-gyp`, `node-gyp-build-test`, and user-supplied commands). While this is common for build tools, it introduces risk if inputs are not sanitized.

### [medium] Dynamic code execution via require()

Finding ID: `NPS-C8417CF7B944`

File: `build-test.js:17`

The script dynamically requires a module based on the 'prebuild.test' field from package.json, which is read from the current working directory. If an attacker can influence the package.json or the value of prebuild.test, they could execute arbitrary code by pointing to a malicious file. However, this is likely intended behavior for a test runner.

### [medium] Dynamic require of relative path

Finding ID: `NPS-5470F5D605D6`

File: `build-test.js:17`

The script requires a module relative to the current working directory, which could execute arbitrary code if the current directory is untrusted. However, this is typical for build/test scripts.

### [low] Environment variable usage for build flags

Finding ID: `NPS-B4ADC2D30187`

File: `bin.js:63`

Reads `npm_config_argv` and `npm_config_build_from_source` environment variables to conditionally execute build commands. No exfiltration or credential harvesting, but behavior can be influenced by environment variables.

### [low] Environment variable check to bypass execution

Finding ID: `NPS-0D39E4AF10AF`

File: `build-test.js:10`

The script checks if an environment variable based on the package name (uppercased, hyphens replaced with underscores) is set, and if so, exits early. This could be used to skip tests or avoid detection, but it's not inherently malicious and may be a legitimate feature.

### [low] dynamic module loading

Finding ID: `NPS-58443C5C70C6`

File: `index.js:1`

The code dynamically selects between a native addon loader and a runtime JavaScript fallback based on the presence of a custom `addon` method on the require function. While this is a common pattern for packages like `node-gyp-build`, it constitutes dynamic module resolution that could be abused if the runtime environment or dependencies are compromised. No direct exfiltration or malicious behavior is present in this file.

## Files reviewed

- `bin.js` (medium): This is a legitimate build helper script for node-gyp that executes shell commands, but it lacks input validation on command-line arguments, posing a potential command injection risk if arguments are attacker-controlled.
- `build-test.js` (medium): The script dynamically loads code based on package.json configuration and environment variables, which could be abused if the package or its configuration is compromised, but it appears to be a standard test runner with no overtly malicious patterns.
- `index.js` (medium): The file is a benign native module loader with dynamic resolution but no overt malicious patterns; risk is low but noted due to dynamic loading behavior.
- `node-gyp-build.js` (safe): No malicious patterns detected; the code is a legitimate native module loader used by packages like node-gyp-build.
- `optional.js` (safe): The script simply exits successfully to skip optional native dependency compilation and contains no malicious patterns.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
