See discussion on https://gerrit.wikimedia.org/r/c/mediawiki/extensions/ConfirmAccount/+/563442
Fairly sure this is an upstream npm issue, specifically https://github.com/npm/cli/issues/301
in any case, https://gerrit.wikimedia.org/r/q/hashtag:%22cve-2016-10540%22+(status:open%20OR%20status:merged) shows the impact of this and we need to work around it...