Summary
Togoder Security scanned the npm package prebuild-install@7.1.3 on Oct 4, 2026. An AI review of 9 source files produced 2 high, 3 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 13
Unvalidated network download
NPS-BE3B522E74D5
downloadPrebuild downloads a tarball from downloadUrl without any integrity verification (no checksum, no signature, no hash pinning). The contents are extracted and potentially executed, creating a supply-chain risk if the source is untrusted or the connection is hijacked.
Arbitrary code execution via require()
NPS-F9B95ADBEB28
The code extracts a .node binary from a downloaded tarball and then calls require(resolved) on it, executing the native module. While gated behind runtime/platform/abi/arch checks that match the current environment, this still executes downloaded binary code at import/runtime. If the download URL is attacker-controlled or compromised, this is arbitrary native code execution.
Network download of prebuilt binaries
NPS-F33791A5F49C
The script downloads prebuilt native binaries from a remote URL at install/run time via the 'download' module and util.getDownloadUrl. This is expected behavior for prebuild-install, but downloading and executing prebuilt binaries from external sources is inherently risky if the URL/asset source is not strictly controlled or verified.
Package extraction to filesystem
NPS-97CD93ABBFA6
tar-fs extract is used to unpack the downloaded tarball into opts.path. There is no explicit path traversal validation in this file; tar-fs may protect against some traversal but the extraction target is effectively outside the package scope and depends on the tarball contents.
dynamic module loading
NPS-9AC696252E39
The file re-exports the result of require('./download'). The actual behavior depends entirely on the contents of ./download.js, which is not provided for analysis. This pattern is commonly used by malicious packages to hide payloads in a secondary file so the entry point appears benign.
Dynamic module loading via require
NPS-448071FCAE69
Modules are loaded via relative require('./rc'), require('./log'), require('./download'), require('./asset'), require('./util'). These are package-local and expected, but the content of those files is not shown, so hidden behavior cannot be ruled out.
Environment variable usage
NPS-98700F775FC9
The script reads process.env and passes it to config/log modules and util.packageOrigin. While this is normal for CI/build tooling, environment variables can contain sensitive tokens/credentials. No direct exfiltration is visible, but downstream modules could access them.
Process exit and chdir based on config
NPS-862905B3E4B9
process.chdir(rc.path) changes working directory based on configuration input. If rc.path is not sanitized, this could be used to influence which package.json and other files are read or written.
Authentication token handling
NPS-747877B30279
opts.token is used to fetch an asset ID before download. Token handling and transmission to remote services (likely GitHub) depends on implementation of util.getAssetUrl and assets module, which are not shown.
Credential/token usage in network request
NPS-F80BF1365F36
If opts.token is provided, it is sent as an Authorization header to the download URL. This is a normal pattern for private registries but means a token could be exfiltrated to whatever host the downloadUrl points to if that URL is untrusted/attacker-influenced.
Dynamic URL construction for downloads
NPS-1FA6BFEF00C6
getDownloadUrl constructs download URLs from template expansion using package metadata and environment-derived values (host mirrors, local prebuilds). While not direct malicious behavior, this enables downloads from configurable external sources which could be hijacked.
External network requests to GitHub API
NPS-991954E38E70
getApiUrl, getAssetUrl build URLs to GitHub releases API based on package repository metadata, resulting in network fetches. This is expected behavior for prebuild-install but involves external requests.
Environment variable harvesting
NPS-FF4B5BDF5330
The getHostMirrorUrl and localPrebuild functions read custom environment variables prefixed with npm_config_ containing package name, which could be abused to redirect downloads to untrusted mirrors or local paths. This is a legitimate feature of prebuild-install but represents a potential supply chain risk if an attacker can control environment variables.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| bin.js | medium | The script is consistent with the legitimate prebuild-install tool behavior (downloading prebuilt binaries and reading config/env), but it downloads and prepares to execute external native binaries and relies on unseen modules, warranting a caution-level review of trust in the source and the downloaded assets. |
| download.js | medium | downloadPrebuild fetches and extracts a tarball without integrity verification and can require() a native .node binary from it, posing a supply-chain arbitrary-code-execution risk if the download source is untrusted. |
| index.js | medium | Entry point only re-exports an external module; malicious behavior may be hidden in ./download.js, which must be reviewed. |
| util.js | medium | Code appears to be a legitimate prebuild-install utility (downloading prebuilt binaries) with expected network and environment variable usage, but presents low-severity supply chain risks due to configurable download sources via environment variables. |
| asset.js | safe | No malicious patterns detected |
| error.js | safe | Cleared by Jev triage; no further analysis needed |
| log.js | safe | No malicious patterns detected |
| proxy.js | safe | No malicious patterns detected; the code is a standard proxy configuration helper using the tunnel-agent package. |
| rc.js | safe | No malicious patterns detected; the code is a standard prebuild-install configuration helper that reads environment variables and CLI arguments for build settings. |
Scanned versions of prebuild-install
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 7.1.3 | Needs review | 9 | Oct 4, 2026 |
Frequently asked questions
Is prebuild-install safe to use?
No confirmed malware was found in prebuild-install@7.1.3, but the review flagged 2 high, 3 medium, 8 low severity findings for risky patterns worth checking before you rely on it.
Does prebuild-install contain malware?
No malware was identified in prebuild-install@7.1.3 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was prebuild-install checked?
Togoder Security downloaded the published npm package and had an AI model read its 9 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan prebuild-install together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in prebuild-install@7.1.3, cost nothing.