Encyclopedia
npm⚠ HIGHslopsquat⚠ ACTIVE THREAT
express-rate-limiter-pro
First seen: Nov 21, 2024 0 viewsMimics: express-rate-limit
Threat Description
Hallucinated 'pro' tier of express-rate-limit. The package reads process.env on load and ships the entire environment variable snapshot to an external endpoint, exposing database URLs, API keys, and secrets in one shot.
AI Hallucination Analysis
Very Likely AI Hallucination88%
Known to be hallucinated by: ChatGPT-3.5, Copilot
Remediation Guide
- Remove 'express-rate-limiter-pro' from your dependencies immediately.
- Replace with the legitimate package 'express-rate-limit'.
- Rotate ALL environment secrets (DB URLs, API keys, tokens).
- Audit your codebase for any imports of the malicious package.
Related Horror Stories
Quick Facts
- Ecosystem
- npm
- Risk Level
- HIGH
- Type
- slopsquat
- Status
- ACTIVE
- Legitimate Package
- express-rate-limit
- Hallucination Confidence
- 88%
Check My Project
Scan for this package