Node statically links OpenSSL and uses gyp (the chromium build system) to build it.
Initially we used the chromium project OpenSSL fork which had these flags set [1]; when we moved to maintain our own gyp-ified fork we kept these flags [2], under the assumption that the chromium folks would know what they're doing.
You may argue that this is naive and you may be right.
However, just looking at that FAQ, OpenSSL provides a justification why it is safe to ignore the specific valgrind error that -DPURIFY surpresses, so I currently see no reason to change it.
When OpenSSL's PRNG routines are called to generate random numbers the
supplied buffer contents are mixed into the entropy pool: so it
technically does not matter whether the buffer is initialized at this
point or not. Valgrind (and other test tools) will complain about this.
When using Valgrind, make sure the OpenSSL library has been compiled with
the PURIFY macro defined (-DPURIFY) to get rid of these warnings.
[1]
https://github.com/joyent/node/blob/e80cac622569dda0f6753b45...[2] https://github.com/joyent/node/commit/7eaea7f9e501db0072455f...
Edit: fixed link