Togoder security

npm package security report

registry-auth-token npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 5.1.1 Files reviewed 2 Size 4.6 KB Scanned

Summary

Togoder Security scanned the npm package registry-auth-token@5.1.1 on Oct 6, 2026. An AI review of 2 source files produced 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
1
low

Findings 3

medium

credential harvesting

NPS-A807CAB45346

The module reads npm registry authentication tokens, usernames, passwords, and legacy auth values from .npmrc configuration files (via @pnpm/npm-conf) and returns them as token objects. This is credential access behavior. While the code appears to be a legitimate npm auth token resolver (similar to known packages like @pnpm/npm-conf usage in npm-registry-fetch), it accesses sensitive registry credentials and environment variables, which is a pattern that could be abused if modified or if the package is compromised.

index.js:12
medium

environment variable harvesting

NPS-02AF7325BE9A

The replaceEnvironmentVariable function extracts values from process.env based on variable names found in .npmrc files. This could be used to read arbitrary environment variables if a malicious .npmrc is crafted, potentially leaking secrets from the environment.

index.js:97
low

dynamic input handling

NPS-290F73A2EBC8

The module processes URLs and configuration paths dynamically, constructing registry URLs and looking up auth info. While not directly malicious, the recursive URL traversal and dynamic key construction could be exploited in a supply-chain attack scenario to leak credentials to unexpected hosts if the checkUrl is attacker-controlled.

index.js:54

Files reviewed

FileVerdictWhat the reviewer saw
index.js medium The code appears to be a legitimate npm registry auth token resolver that accesses .npmrc credentials and environment variables, but its credential-harvesting behavior warrants caution if the package or its dependencies are compromised.
registry-url.js safe The code is a simple utility for reading registry URLs from npm configuration and contains no malicious patterns.

Scanned versions of registry-auth-token

VersionVerdictFilesScanned
5.1.1 Needs review 2 Oct 6, 2026

Frequently asked questions

Is registry-auth-token safe to use?

No confirmed malware was found in registry-auth-token@5.1.1, but the review flagged 2 medium, 1 low severity findings for risky patterns worth checking before you rely on it.

Does registry-auth-token contain malware?

No malware was identified in registry-auth-token@5.1.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was registry-auth-token checked?

Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan registry-auth-token together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in registry-auth-token@5.1.1, cost nothing.

Related security reports