Encyclopedia
npm☠ CRITICALslopsquat⚠ ACTIVE THREAT

mongoose-slug-generator

First seen: Sep 30, 2024 0 viewsMimics: mongoose-slug-generator (legit variants exist - verify)
Share threatHN
Threat Description

A hallucinated slug generator for Mongoose. The registered malicious version writes an attacker's SSH public key to ~/.ssh/authorized_keys on install, granting persistent remote access to developer machines and CI runners.

AI Hallucination Analysis
Very Likely AI Hallucination87%
Known to be hallucinated by: Cursor, ChatGPT-4
Remediation Guide
  1. Remove 'mongoose-slug-generator' from your dependencies immediately.
  2. Inspect ~/.ssh/authorized_keys on all affected machines and remove unknown keys.
  3. Rotate SSH keys and revoke any unauthorized access.
  4. Audit your codebase for imports of the malicious package.
Quick Facts
Ecosystem
npm
Risk Level
CRITICAL
Type
slopsquat
Status
ACTIVE
Legitimate Package
mongoose-slug-generator (legit variants exist - verify)
Hallucination Confidence
87%
Check My Project
Scan for this package