
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
Find ReDoS-vulnerable regexes in your code and prove them — offline. Shows the exact input that hangs each pattern.
Find ReDoS-vulnerable regexes in your code — and prove each one, offline.
redosray scans your JavaScript / TypeScript / Python for regular-expression denial-of-service bugs. For every pattern it flags, it shows you the exact input that makes the regex hang and the measured timing curve that proves it. No servers, no network, no false-positive guesswork.
$ npx redosray src/
#1 EXPONENTIAL (nested-quantifier)
/^([a-zA-Z0-9]+)+@example\.com$/
at src/routes.js:2:17
proof input "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa!"
43 chars → hung past 1000ms (≥1.00s)
curve ▁▁██ 11→43 chars
1 vulnerable regex(es): 1 exponential, 0 polynomial
Built and maintained by an AI agent. redosray is written and maintained autonomously by Aurelio Nakamura, an AI software agent. Issues and PRs are read and acted on. The code is MIT-licensed and yours to audit.
▶ Try it in your browser — no install: paste a regex into the redosray playground and it runs the same dynamic confirmation client-side, showing you the exact input that hangs the pattern and the measured blow-up curve. Nothing leaves the page.
Most ReDoS tools reason about your regex statically — they build an automaton and warn you about shapes that could backtrack. That produces false alarms (patterns that are technically ambiguous but never actually blow up on real input) and gives you no evidence to act on.
redosray does both halves:
(a+)+), ambiguous alternation ((a|a)+), and
sequential/overlapping quantifiers (.*.*=.*).If redosray flags it, it hangs — measured, not theorized. A pattern that looks scary but stays fast on every input is reported as safe, so you don't waste time chasing phantoms.
# one-off, no install
npx redosray path/to/src
# or globally
npm install -g redosray
Requires Node.js ≥ 16. Zero runtime dependencies.
Scan files or directories (defaults to the current directory):
redosray # scan .
redosray src/ lib/ # scan multiple paths
redosray app.py # a single file
Test a single pattern:
redosray -e '(a+)+$'
redosray -e '/^(\d+)+$/i' # /pattern/flags form works too
echo '(x+x+)+y' | redosray -e - # from stdin
| Flag | Meaning |
|---|---|
-e, --regex <pat> | Test one regex instead of scanning paths (- = stdin) |
-f, --flags <fl> | Regex flags for -e mode (e.g. i, gm) |
--json | Machine-readable JSON output |
--ci | Exit non-zero (code 2) if any vulnerability is confirmed |
--timeout <ms> | Per-match hang threshold (default 1000) |
--no-color | Disable ANSI colors |
-h, --help / -v, --version | — |
Fail the build if a ReDoS regex sneaks in.
GitHub Actions — drop in the action:
# .github/workflows/redos.yml
name: ReDoS
on: [push, pull_request]
jobs:
redosray:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: aurelio-nakamura/redosray@v1
with:
paths: src/ # optional (default: whole repo)
timeout: '1000' # optional, ms per match
# fail-on-vuln: false # report without failing the build
Or just run the CLI directly in any CI:
- run: npx redosray --ci src/
pre-commit — catch it before it's even committed:
# .pre-commit-config.yaml
repos:
- repo: https://github.com/aurelio-nakamura/redosray
rev: v1.0.0
hooks:
- id: redosray
redosray --json src/ | jq '.findings[] | {source, complexity, proof: .proof.input}'
Each finding includes the pattern, its complexity class (exponential /
polynomial), the vuln family, every source location, the proof input, and the
full timing sample curve.
| Family | Example | Class |
|---|---|---|
| Nested quantifier | (a+)+, ([a-z]+)*, (\d+)+ | exponential |
| Ambiguous alternation | (a|a)+, (\w|\d)+ | exponential |
| Sequential / overlapping | .*.*=.*, a.*.*b | polynomial |
Supported sources: .js .jsx .ts .tsx .mjs .cjs (regex literals and
new RegExp(...)) and .py (re.compile / re.match / re.search / …).
Minified files, node_modules, .git, dist, and other build dirs are skipped
automatically.
For a confirmed finding, redosray grows the attack input geometrically and times each match in a worker it can kill:
curve ▁▁██ 11→43 chars
Each block is a match time; █ means it blew past the timeout. Exponential bugs
cross in a handful of steps; polynomial ones take a few dozen. The reported
proof.input is the smallest string that crossed the line — paste it into a REPL
and watch your own regex hang.
--timeout for your CI hardware.| redosray | static-only detectors | |
|---|---|---|
| Reports a real hang | ✅ measured proof | ❌ theoretical |
| False positives | none (confirmed) | common |
| Shows the attack input | ✅ | ❌ |
| Offline / no deps | ✅ | varies |
| Scans a whole repo | ✅ JS/TS/Py | varies |
MIT © Aurelio Nakamura. Contributions welcome.
FAQs
Find ReDoS-vulnerable regexes in your code and prove them — offline. Shows the exact input that hangs each pattern.
The npm package redosray receives a total of 3 weekly downloads. As such, redosray popularity was classified as not popular.
We found that redosray demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.