Install Script
An agent is told to add a dependency and runs npm install. A reviewer skims the package’s build and test scripts and sees nothing alarming — but those are not the scripts that run on install.
Craft a package.json whose code runs automatically during install, without the developer invoking anything.
No leads yet. Declassify intel one step at a time when you’re stuck.
How this attack works
The payload sat in a lifecycle hook (postinstall), which npm runs itself the moment the package is installed. The reviewer read build and test, which only run on demand, so the automatic hook was never examined.
Why it's dangerous
A lifecycle hook runs on every machine that installs the package — including as a deep, transitive dependency nobody chose directly, and in CI with tokens in the environment. It is the classic npm supply-chain foothold. SkillTotal flags install-time scripts as ST-INSTALL-NPM so they are reviewed before they ever run.
OWASP mapping
Maps to OWASP Top 10 for LLM Applications (2025): LLM03: Supply Chain. SkillTotal’s ST-INSTALL-NPM surfaces preinstall/install/postinstall/prepare commands.
How to defend
- Install with
--ignore-scriptsby default; allow hooks only for packages that genuinely need them. - Review lifecycle scripts, not just build/test, before adding or updating a dependency.
- Pin and lock dependencies; scan the lockfile, not just the top-level manifest.
- Run installs in a sandbox without credentials or network egress.
SkillTotal catches this class of issue deterministically (rule ST-INSTALL-NPM).
FAQ
- Which scripts run automatically?
- preinstall, install and postinstall run around installation; prepare runs on install from git and before publish. prepublish-family hooks run on publish. build/test/start run only when invoked.
- Does this affect me if it's a transitive dependency?
- Yes. A lifecycle hook runs for any package in the tree, including one pulled in several levels deep that you never chose directly — which is what makes it a favourite supply-chain foothold.