Encyclopedia
RubyGems⚠ HIGHslopsquat⚠ ACTIVE THREAT

devise-auth-jwt

First seen: Oct 15, 2024 2 viewsMimics: devise-jwt
Share threatHN
Threat Description

Hallucinated JWT authentication gem for Devise. The package patches Devise's session controller to accept a hidden backdoor parameter that bypasses JWT verification entirely, granting unauthenticated admin access.

AI Hallucination Analysis
Very Likely AI Hallucination87%
Known to be hallucinated by: Copilot, ChatGPT-3.5
Remediation Guide
  1. Remove 'devise-auth-jwt' from your Gemfile immediately.
  2. Replace with the legitimate gem 'devise-jwt'.
  3. Audit your authentication controllers for backdoor parameters.
  4. Rotate JWT signing keys and review access logs.
Quick Facts
Ecosystem
RubyGems
Risk Level
HIGH
Type
slopsquat
Status
ACTIVE
Legitimate Package
devise-jwt
Hallucination Confidence
87%
Check My Project
Scan for this package