# registry-auth-token@5.1.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:24:21.000Z
- Files reviewed: 2
- Findings: 2 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/registry-auth-token
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package registry-auth-token@5.1.1 on Oct 6, 2026. An AI review of 2 source files produced 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] credential harvesting

Finding ID: `NPS-A807CAB45346`

File: `index.js:12`

The module reads npm registry authentication tokens, usernames, passwords, and legacy auth values from .npmrc configuration files (via @pnpm/npm-conf) and returns them as token objects. This is credential access behavior. While the code appears to be a legitimate npm auth token resolver (similar to known packages like @pnpm/npm-conf usage in npm-registry-fetch), it accesses sensitive registry credentials and environment variables, which is a pattern that could be abused if modified or if the package is compromised.

### [medium] environment variable harvesting

Finding ID: `NPS-02AF7325BE9A`

File: `index.js:97`

The replaceEnvironmentVariable function extracts values from process.env based on variable names found in .npmrc files. This could be used to read arbitrary environment variables if a malicious .npmrc is crafted, potentially leaking secrets from the environment.

### [low] dynamic input handling

Finding ID: `NPS-290F73A2EBC8`

File: `index.js:54`

The module processes URLs and configuration paths dynamically, constructing registry URLs and looking up auth info. While not directly malicious, the recursive URL traversal and dynamic key construction could be exploited in a supply-chain attack scenario to leak credentials to unexpected hosts if the checkUrl is attacker-controlled.

## Files reviewed

- `index.js` (medium): The code appears to be a legitimate npm registry auth token resolver that accesses .npmrc credentials and environment variables, but its credential-harvesting behavior warrants caution if the package or its dependencies are compromised.
- `registry-url.js` (safe): The code is a simple utility for reading registry URLs from npm configuration and contains no malicious patterns.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
