nuqs-codemod-runner
Audited by Socket on Sep 16, 2026
3 alerts found:
Anomalyx3The supplied text documents a legitimate codemod pipeline and contains no direct evidence of malware or data theft. The main security risks are execution of the unpinned jscodeshift@latest package, execution of configurable verification commands, and potentially destructive rollback instructions. Pin and integrity-check the jscodeshift version, review config.json and transforms, and avoid --allow-dirty unless file changes are backed up. Confidence is limited because no executable implementation was provided.
The script is an automation wrapper for applying codemods, not clearly malware by itself. Its principal supply-chain concern is executing an unpinned jscodeshift@latest obtained through npx. It also has exploitable input-validation weaknesses: scan.json paths and codemod names are not constrained, and scannedAt is embedded into Python source, permitting code injection if scan.json can be tampered with. The risk is moderate and depends heavily on the integrity of scan.json, config.json, and the transform directory.
The code appears to implement a legitimate codemod verification and rollback workflow. It contains a significant command-injection risk because configuration-controlled commands are executed with eval, and repoRoot is not validated. No direct malware, credential theft, network exfiltration, persistence, or destructive behavior beyond intended Git restoration is evident in the fragment.