{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/pnpm-12.0.0-alpha.0-12.0.0-alpha.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:pnpm:pnpm:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-101043"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["pnpm (11.0.0 \u003c= version \u003c 11.11.0)","pnpm (10.7.0 \u003c= version \u003c 10.34.5)","pnpm (\u003e=12.0.0-alpha.0 \u003c12.0.0-alpha.5)"],"_cs_severities":["high"],"_cs_tags":["supply-chain","pnpm","vulnerability","credential-theft"],"_cs_type":"advisory","_cs_vendors":["pnpm"],"content_html":"\u003cp\u003eCVE-2026-101043 affects pnpm versions 11.0.0 through 11.10.x and 10.7.0 through 10.34.4. The vulnerability arises from improper handling of environment variable expansion within the httpProxy, httpsProxy, and noProxy configuration keys located in a project's pnpm-workspace.yaml file. Unlike other sensitive keys that are protected from expansion to prevent untrusted manifest exploitation, these proxy keys are processed before lifecycle scripts execute.\u003c/p\u003e\n\u003cp\u003eAn attacker can create a malicious pnpm-workspace.yaml file within a repository that references sensitive environment variables such as NPM_TOKEN or GITHUB_TOKEN. When a victim clones the repository and executes a pnpm command like pnpm install, the pnpm client expands these variables into the proxy configuration. This leads to the exfiltration of the token values via DNS queries or HTTP traffic routed through an attacker-controlled proxy server. This vulnerability allows for unauthorized access to private package registries and CI/CD environments.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker creates a malicious repository containing a crafted pnpm-workspace.yaml file.\u003c/li\u003e\n\u003cli\u003eAttacker sets the httpProxy or httpsProxy key in the manifest to include an environment variable placeholder (e.g., ${NPM_TOKEN}).\u003c/li\u003e\n\u003cli\u003eAttacker lures a victim to clone the repository into their local environment.\u003c/li\u003e\n\u003cli\u003eVictim executes a standard pnpm command (e.g., pnpm install) within the root of the cloned repository.\u003c/li\u003e\n\u003cli\u003epnpm loads the pnpm-workspace.yaml manifest and parses the proxy configuration.\u003c/li\u003e\n\u003cli\u003eThe client engine expands the placeholder ${NPM_TOKEN} into its actual sensitive value.\u003c/li\u003e\n\u003cli\u003eThe pnpm process triggers a network connection or DNS lookup toward an attacker-controlled proxy host, appending the expanded token to the request metadata.\u003c/li\u003e\n\u003cli\u003eAttacker logs the incoming connection or DNS request on their infrastructure to capture the exfiltrated secret.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to the theft of sensitive development credentials, including NPM_TOKEN and GITHUB_TOKEN. This allows attackers to authenticate as the victim, potentially accessing private repositories, stealing proprietary source code, or injecting malicious packages into the software supply chain.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade pnpm to version 11.11.0 or 10.34.5 immediately to include the fix that prevents environment variable expansion in untrusted proxy configurations.\u003c/li\u003e\n\u003cli\u003eImplement repository scanning tools to detect pnpm-workspace.yaml files containing suspicious proxy configurations or references to environment variable patterns.\u003c/li\u003e\n\u003cli\u003eRotate all credentials that may have been stored in local environment variables (e.g., NPM_TOKEN, GITHUB_TOKEN) if they were used in environments where malicious repositories were cloned and processed.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-27T21:09:25Z","date_published":"2026-09-27T19:08:52Z","id":"https://feed.craftedsignal.io/briefs/2026-09-pnpm-env-expansion/","summary":"Vulnerable pnpm versions expand sensitive environment variables within proxy settings in malicious pnpm-workspace.yaml files, enabling credential exfiltration during configuration loading.","title":"Arbitrary Environment Variable Disclosure via pnpm-workspace.yaml","url":"https://feed.craftedsignal.io/briefs/2026-09-pnpm-env-expansion/"}],"language":"en","title":"CraftedSignal Threat Feed - Pnpm (\u003e=12.0.0-Alpha.0 \u003c12.0.0-Alpha.5)","version":"https://jsonfeed.org/version/1.1"}