# prebuild-install@7.1.3 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:39:26.000Z
- Files reviewed: 9
- Findings: 2 high, 3 medium, 8 low severity findings
- Report: https://security.togoder.click/npm/prebuild-install
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package prebuild-install@7.1.3 on Oct 4, 2026. An AI review of 9 source files produced 2 high, 3 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [high] Unvalidated network download

Finding ID: `NPS-BE3B522E74D5`

File: `download.js:60`

downloadPrebuild downloads a tarball from downloadUrl without any integrity verification (no checksum, no signature, no hash pinning). The contents are extracted and potentially executed, creating a supply-chain risk if the source is untrusted or the connection is hijacked.

### [high] Arbitrary code execution via require()

Finding ID: `NPS-F9B95ADBEB28`

File: `download.js:122`

The code extracts a .node binary from a downloaded tarball and then calls require(resolved) on it, executing the native module. While gated behind runtime/platform/abi/arch checks that match the current environment, this still executes downloaded binary code at import/runtime. If the download URL is attacker-controlled or compromised, this is arbitrary native code execution.

### [medium] Network download of prebuilt binaries

Finding ID: `NPS-F33791A5F49C`

File: `bin.js`

The script downloads prebuilt native binaries from a remote URL at install/run time via the 'download' module and util.getDownloadUrl. This is expected behavior for prebuild-install, but downloading and executing prebuilt binaries from external sources is inherently risky if the URL/asset source is not strictly controlled or verified.

### [medium] Package extraction to filesystem

Finding ID: `NPS-97CD93ABBFA6`

File: `download.js:104`

tar-fs extract is used to unpack the downloaded tarball into opts.path. There is no explicit path traversal validation in this file; tar-fs may protect against some traversal but the extraction target is effectively outside the package scope and depends on the tarball contents.

### [medium] dynamic module loading

Finding ID: `NPS-9AC696252E39`

File: `index.js:1`

The file re-exports the result of require('./download'). The actual behavior depends entirely on the contents of ./download.js, which is not provided for analysis. This pattern is commonly used by malicious packages to hide payloads in a secondary file so the entry point appears benign.

### [low] Dynamic module loading via require

Finding ID: `NPS-448071FCAE69`

File: `bin.js:6`

Modules are loaded via relative require('./rc'), require('./log'), require('./download'), require('./asset'), require('./util'). These are package-local and expected, but the content of those files is not shown, so hidden behavior cannot be ruled out.

### [low] Environment variable usage

Finding ID: `NPS-98700F775FC9`

File: `bin.js:9`

The script reads process.env and passes it to config/log modules and util.packageOrigin. While this is normal for CI/build tooling, environment variables can contain sensitive tokens/credentials. No direct exfiltration is visible, but downstream modules could access them.

### [low] Process exit and chdir based on config

Finding ID: `NPS-862905B3E4B9`

File: `bin.js:19`

process.chdir(rc.path) changes working directory based on configuration input. If rc.path is not sanitized, this could be used to influence which package.json and other files are read or written.

### [low] Authentication token handling

Finding ID: `NPS-747877B30279`

File: `bin.js:64`

opts.token is used to fetch an asset ID before download. Token handling and transmission to remote services (likely GitHub) depends on implementation of util.getAssetUrl and assets module, which are not shown.

### [low] Credential/token usage in network request

Finding ID: `NPS-F80BF1365F36`

File: `download.js:67`

If opts.token is provided, it is sent as an Authorization header to the download URL. This is a normal pattern for private registries but means a token could be exfiltrated to whatever host the downloadUrl points to if that URL is untrusted/attacker-influenced.

### [low] Dynamic URL construction for downloads

Finding ID: `NPS-1FA6BFEF00C6`

File: `util.js:6`

getDownloadUrl constructs download URLs from template expansion using package metadata and environment-derived values (host mirrors, local prebuilds). While not direct malicious behavior, this enables downloads from configurable external sources which could be hijacked.

### [low] External network requests to GitHub API

Finding ID: `NPS-991954E38E70`

File: `util.js:27`

getApiUrl, getAssetUrl build URLs to GitHub releases API based on package repository metadata, resulting in network fetches. This is expected behavior for prebuild-install but involves external requests.

### [low] Environment variable harvesting

Finding ID: `NPS-FF4B5BDF5330`

File: `util.js:78`

The getHostMirrorUrl and localPrebuild functions read custom environment variables prefixed with npm_config_ containing package name, which could be abused to redirect downloads to untrusted mirrors or local paths. This is a legitimate feature of prebuild-install but represents a potential supply chain risk if an attacker can control environment variables.

## Files reviewed

- `bin.js` (medium): The script is consistent with the legitimate prebuild-install tool behavior (downloading prebuilt binaries and reading config/env), but it downloads and prepares to execute external native binaries and relies on unseen modules, warranting a caution-level review of trust in the source and the downloaded assets.
- `download.js` (medium): downloadPrebuild fetches and extracts a tarball without integrity verification and can require() a native .node binary from it, posing a supply-chain arbitrary-code-execution risk if the download source is untrusted.
- `index.js` (medium): Entry point only re-exports an external module; malicious behavior may be hidden in ./download.js, which must be reviewed.
- `util.js` (medium): Code appears to be a legitimate prebuild-install utility (downloading prebuilt binaries) with expected network and environment variable usage, but presents low-severity supply chain risks due to configurable download sources via environment variables.
- `asset.js` (safe): No malicious patterns detected
- `error.js` (safe): Cleared by Jev triage; no further analysis needed
- `log.js` (safe): No malicious patterns detected
- `proxy.js` (safe): No malicious patterns detected; the code is a standard proxy configuration helper using the tunnel-agent package.
- `rc.js` (safe): No malicious patterns detected; the code is a standard prebuild-install configuration helper that reads environment variables and CLI arguments for build settings.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
