Node.js Dependency Security¶
Source: hooks/ways/softwaredev/code/supplychain/depscan/node/node.md
Frontmatter
| Field | Value |
|---|---|
description |
Node.js dependency security, npm audit, postinstall scripts, typosquatting |
vocabulary |
npm audit package-lock.json node_modules postinstall preinstall yarn pnpm npx typosquat javascript typescript |
refire |
0.15 |
scope |
agent, subagent |
Scanning¶
Node-Specific Risks¶
postinstallscripts run onnpm install. Checkpackage.jsonscripts section for unfamiliar packages.npm install --ignore-scriptsskips them but may break legitimate packages.npxruns packages without installing — convenient but downloads and executes in one step. Know what you're running.- Transitive dependencies are the real surface. A project with 20 direct deps can have 800+ transitive.
npm auditcovers them all. - Typosquatting is rampant on npm.
lodahs,crossenv,event-stream(compromised maintainer). Verify package names and check download counts on npmjs.com.