npmweak-linksaccount-takeoverinstall-scripts

Zahan et al. — Weak Links in npm, ICSE-SEIP

Provides empirical evidence for multiple supply chain risk signals, specifically linking install scripts and expired domains to package hijack risk.

Summary

Analysis of 1.63 million npm packages identified six key weak link signals that predict susceptibility to supply chain attacks. These include installation scripts (found in 2.2% of packages but 93.9% of malicious ones), maintainer accounts with expired email domains (2,818 domains identified), and unmaintained packages (58.7% inactive for over two years). The study found 2,818 maintainers whose expired domains could allow attackers to hijack 8,494 packages. While 97.5% of popular packages avoid install scripts, 38% are currently inactive. Survey results from 470 maintainers showed strong support for treating expired domains, install scripts, and lack of maintenance as critical security signals.

Related Checks

PACKAGE_INSTALL_SCRIPTS

93.9% of malicious npm packages analyzed contained at least one install script used to steal data or execute remote commands.

Adverse Outcome

automatic execution of malicious shell commands during package installation

Because

the correlation between install scripts and malicious behavior in npm is exceptionally high, making the presence of these scripts a primary signal of elevated risk.

SOURCE_REPO_ABANDONED

58.7% of npm packages were found to be inactive (no updates for 2 years), increasing the risk of unpatched vulnerabilities and ownership hijack.

Adverse Outcome

dependency on unmaintained code that will not receive security fixes or domain monitoring

Because

extended inactivity is a documented precursor to both functional decay and increased vulnerability to malicious takeover attempts.

SOURCE_SINGLE_CONTRIBUTOR

The study suggests that a higher number of maintainers can increase the attack surface, but also that fewer maintainers facilitate better communication and security oversight.

Adverse Outcome

lack of independent peer review or redundant security oversight

Because

limiting the number of trusted maintainers reduces the social engineering attack surface while ensuring that all code changes undergo at least one layer of external review.

Gaps Analysis

Evidence

A maintainer's email address is associated with an expired domain... attackers can register and alter the DNS MX records to hijack the maintainer's email address.

Blind Spot

Risk Guard does not check for expired maintainer email domains or account-takeover risks.

Actionable Capability

Risk Guard would be better if it integrated domain registration status checks for maintainer emails to flag potential account takeover vulnerabilities.

← Previous Next →