Encyclopedia
npm⚠ HIGHslopsquat⚠ ACTIVE THREAT

express-rate-limiter-pro

First seen: Nov 21, 2024 0 viewsMimics: express-rate-limit
Share threatHN
Threat Description

Hallucinated 'pro' tier of express-rate-limit. The package reads process.env on load and ships the entire environment variable snapshot to an external endpoint, exposing database URLs, API keys, and secrets in one shot.

AI Hallucination Analysis
Very Likely AI Hallucination88%
Known to be hallucinated by: ChatGPT-3.5, Copilot
Remediation Guide
  1. Remove 'express-rate-limiter-pro' from your dependencies immediately.
  2. Replace with the legitimate package 'express-rate-limit'.
  3. Rotate ALL environment secrets (DB URLs, API keys, tokens).
  4. Audit your codebase for any imports of the malicious package.
Quick Facts
Ecosystem
npm
Risk Level
HIGH
Type
slopsquat
Status
ACTIVE
Legitimate Package
express-rate-limit
Hallucination Confidence
88%
Check My Project
Scan for this package