
Research
/Security News
77 Firefox Extensions Linked to Crypto Wallet and Credential Theft
Socket uncovered 77 linked Firefox extensions, including 40 that steal wallet secrets or credentials and 37 deceptive sports-score shells.
@bolthub/verify
Advanced tools
Verify bolthub gateway signatures on your origin server — Express, Fastify, or generic Node.js middleware
Verify that incoming requests to your origin server were proxied through the BoltHub gateway. Zero dependencies; uses only Node.js built-in crypto.
npm install @bolthub/verify
import { expressHmacMiddleware } from "@bolthub/verify";
app.use(
expressHmacMiddleware({
secrets: [process.env.HMAC_SECRET!],
})
);
Requests without a valid X-Gateway-Signature header are rejected with 403.
BoltHub supports two verification methods:
The gateway signs every request with HMAC-SHA256 over the canonical payload
METHOD\nPATH\nTIMESTAMP\nNONCE\nBODY. This prevents replay attacks and
body tampering.
import { verifyGatewaySignature } from "@bolthub/verify";
const result = verifyGatewaySignature(
{
method: req.method,
path: req.path,
headers: req.headers,
body: rawBody,
},
{ secrets: [process.env.HMAC_SECRET!] }
);
if (!result.valid) {
return res.status(403).json({ error: result.error });
}
A simpler method where the gateway sends a static X-Gateway-Secret header.
No replay protection, but easier to set up.
import { verifyGatewaySecret } from "@bolthub/verify";
const result = verifyGatewaySecret(
{ method: req.method, path: req.path, headers: req.headers },
{ secrets: [process.env.GATEWAY_SECRET!] }
);
Both methods accept an array of secrets, allowing zero-downtime rotation:
expressHmacMiddleware({
secrets: [currentSecret, previousSecret],
maxAgeMs: 30_000,
});
The library tries each secret in order and accepts the first match.
| Export | Description |
|---|---|
verifyGatewaySignature(request, options) | Verify HMAC-SHA256 signature headers |
verifyGatewaySecret(request, options) | Verify shared secret header |
expressHmacMiddleware(options) | Express/Connect middleware for HMAC verification |
expressSecretMiddleware(options) | Express/Connect middleware for shared secret verification |
VerifyOptions | Options: secrets, maxAgeMs |
VerifyResult | Result: { valid: boolean; error?: string } |
RequestLike | Minimal request shape accepted by verify functions |
MIT
FAQs
Verify bolthub gateway signatures on your origin server — Express, Fastify, or generic Node.js middleware
The npm package @bolthub/verify receives a total of 5 weekly downloads. As such, @bolthub/verify popularity was classified as not popular.
We found that @bolthub/verify demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Socket uncovered 77 linked Firefox extensions, including 40 that steal wallet secrets or credentials and 37 deceptive sports-score shells.

Security News
NIST disclosed an unreleased AI tool called V-etalon and opened a broad inquiry into NVD modernization after years of automation plans produced no public enrichment system.

Security News
In his AI Council 2026 talk, Feross Aboukhadijeh covers recent package compromises, vulnerability discovery, and a more automated security model.