Malicious code in express-rate-controller (npm)
The npm package express-rate-controller version 2.0.1 contains malicious code that executes attacker-controlled JavaScript fetched from a remote server with TLS verification disabled. The package misrepresents itself as an SVG utilities library and hides the malicious export from ESM and typed consumers. Any user requiring the package and invoking the hidden getPlugin() function, or iterating over the exported API, will execute arbitrary code with full require access.
AI Analysis
Technical Summary
The express-rate-controller package version 2.0.1 exports a hidden function getPlugin() in its CommonJS build that performs an HTTPS GET request to https://api.avax-test.dev/ext/bc/rpc with TLS verification disabled (rejectUnauthorized: false). It then executes the response body as JavaScript code with full require access via new Function('require', data)(require). This allows remote attacker-controlled code execution. The malicious export is not declared in the ESM or TypeScript builds, hiding it from typed and ESM consumers. The package also misrepresents its purpose, describing itself as an SVG utilities library and shipping a CLI named svgcraft, which does not match the package name or functionality.
Potential Impact
Any consumer that requires express-rate-controller version 2.0.1 and invokes the getPlugin() function, or iterates over the exported API object, will execute arbitrary JavaScript code fetched from a remote server controlled by an attacker. This results in remote code execution with full require access, potentially compromising the host environment. The TLS verification is disabled, allowing man-in-the-middle attacks to alter the fetched code.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid using express-rate-controller version 2.0.1. Verify the integrity and provenance of npm packages before use. Monitor vendor advisories for updates or official fixes. Since this is a malicious package, removing it from projects and replacing it with trusted alternatives is recommended.
Malicious code in express-rate-controller (npm)
Description
The npm package express-rate-controller version 2.0.1 contains malicious code that executes attacker-controlled JavaScript fetched from a remote server with TLS verification disabled. The package misrepresents itself as an SVG utilities library and hides the malicious export from ESM and typed consumers. Any user requiring the package and invoking the hidden getPlugin() function, or iterating over the exported API, will execute arbitrary code with full require access.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The express-rate-controller package version 2.0.1 exports a hidden function getPlugin() in its CommonJS build that performs an HTTPS GET request to https://api.avax-test.dev/ext/bc/rpc with TLS verification disabled (rejectUnauthorized: false). It then executes the response body as JavaScript code with full require access via new Function('require', data)(require). This allows remote attacker-controlled code execution. The malicious export is not declared in the ESM or TypeScript builds, hiding it from typed and ESM consumers. The package also misrepresents its purpose, describing itself as an SVG utilities library and shipping a CLI named svgcraft, which does not match the package name or functionality.
Potential Impact
Any consumer that requires express-rate-controller version 2.0.1 and invokes the getPlugin() function, or iterates over the exported API object, will execute arbitrary JavaScript code fetched from a remote server controlled by an attacker. This results in remote code execution with full require access, potentially compromising the host environment. The TLS verification is disabled, allowing man-in-the-middle attacks to alter the fetched code.
Mitigation Recommendations
No official patch or remediation is currently documented. Users should avoid using express-rate-controller version 2.0.1. Verify the integrity and provenance of npm packages before use. Monitor vendor advisories for updates or official fixes. Since this is a malicious package, removing it from projects and replacing it with trusted alternatives is recommended.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-12378
- Osv Schema Version
- 1.7.4
- Aliases
- []
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a735743bf8831d539159bf8
Added to database: 08/05/2026, 15:31:15 UTC
Last enriched: 08/05/2026, 17:14:10 UTC
Last updated: 08/05/2026, 17:14:10 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.