Provides empirical evidence for multiple supply chain risk signals, specifically linking install scripts and expired domains to package hijack risk.
Analysis of 1.63 million npm packages identified six key weak link signals that predict susceptibility to supply chain attacks. These include installation scripts (found in 2.2% of packages but 93.9% of malicious ones), maintainer accounts with expired email domains (2,818 domains identified), and unmaintained packages (58.7% inactive for over two years). The study found 2,818 maintainers whose expired domains could allow attackers to hijack 8,494 packages. While 97.5% of popular packages avoid install scripts, 38% are currently inactive. Survey results from 470 maintainers showed strong support for treating expired domains, install scripts, and lack of maintenance as critical security signals.
93.9% of malicious npm packages analyzed contained at least one install script used to steal data or execute remote commands.
automatic execution of malicious shell commands during package installation
the correlation between install scripts and malicious behavior in npm is exceptionally high, making the presence of these scripts a primary signal of elevated risk.
58.7% of npm packages were found to be inactive (no updates for 2 years), increasing the risk of unpatched vulnerabilities and ownership hijack.
dependency on unmaintained code that will not receive security fixes or domain monitoring
extended inactivity is a documented precursor to both functional decay and increased vulnerability to malicious takeover attempts.
The study suggests that a higher number of maintainers can increase the attack surface, but also that fewer maintainers facilitate better communication and security oversight.
lack of independent peer review or redundant security oversight
limiting the number of trusted maintainers reduces the social engineering attack surface while ensuring that all code changes undergo at least one layer of external review.
A maintainer's email address is associated with an expired domain... attackers can register and alter the DNS MX records to hijack the maintainer's email address.
Risk Guard does not check for expired maintainer email domains or account-takeover risks.
Risk Guard would be better if it integrated domain registration status checks for maintainer emails to flag potential account takeover vulnerabilities.