Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Malicious code in express-rate-controller (npm)

0
Critical
Published: 08/05/2026 (08/05/2026, 13:04:26 UTC)
Source: GCVE Database
Product: express-rate-controller

Description

The npm package express-rate-controller version 2.0.1 contains malicious code that executes attacker-controlled JavaScript fetched from a remote server with TLS verification disabled. The package misrepresents itself as an SVG utilities library and hides the malicious export from ESM and typed consumers. Any user requiring the package and invoking the hidden getPlugin() function, or iterating over the exported API, will execute arbitrary code with full require access.

Affected software

npmghsa
express-rate-controller
Affected versions
=2.0.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/05/2026, 17:14:10 UTC

Technical Analysis

The express-rate-controller package version 2.0.1 exports a hidden function getPlugin() in its CommonJS build that performs an HTTPS GET request to https://api.avax-test.dev/ext/bc/rpc with TLS verification disabled (rejectUnauthorized: false). It then executes the response body as JavaScript code with full require access via new Function('require', data)(require). This allows remote attacker-controlled code execution. The malicious export is not declared in the ESM or TypeScript builds, hiding it from typed and ESM consumers. The package also misrepresents its purpose, describing itself as an SVG utilities library and shipping a CLI named svgcraft, which does not match the package name or functionality.

Potential Impact

Any consumer that requires express-rate-controller version 2.0.1 and invokes the getPlugin() function, or iterates over the exported API object, will execute arbitrary JavaScript code fetched from a remote server controlled by an attacker. This results in remote code execution with full require access, potentially compromising the host environment. The TLS verification is disabled, allowing man-in-the-middle attacks to alter the fetched code.

Mitigation Recommendations

No official patch or remediation is currently documented. Users should avoid using express-rate-controller version 2.0.1. Verify the integrity and provenance of npm packages before use. Monitor vendor advisories for updates or official fixes. Since this is a malicious package, removing it from projects and replacing it with trusted alternatives is recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
MAL-2026-12378
Osv Schema Version
1.7.4
Aliases
[]
Ecosystems
["npm"]
Database Specific Severity
null
Cvss Version
null

Threat ID: 6a735743bf8831d539159bf8

Added to database: 08/05/2026, 15:31:15 UTC

Last enriched: 08/05/2026, 17:14:10 UTC

Last updated: 08/05/2026, 17:14:10 UTC

Views: 2

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses