Summary
Togoder Security scanned the npm package @octokit/plugin-throttling@11.0.3 on Oct 6, 2026. An AI review of 6 source files produced 1 medium severity finding. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 1
ReDoS (Regular Expression Denial of Service)
NPS-07907DCC9F87
The routeMatcher function builds a regular expression from user-controlled paths. The pattern (?:.+?) inserted for each {...} segment, combined with nested non-capturing groups and alternation, can lead to catastrophic backtracking on crafted inputs, potentially causing excessive CPU usage and denial of service.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist-src/route-matcher.js | medium | The code is not malicious, but it constructs regexes from external input in a way that can cause ReDoS. |
| dist-bundle/index.js | safe | No malicious patterns detected; the code is a legitimate Octokit throttling plugin with no exfiltration, credential harvesting, obfuscation, or backdoor behavior. |
| dist-src/generated/triggers-notification-paths.js | safe | No malicious patterns detected; the file contains only a static array of GitHub API notification path templates with no executable, network, or file-system behavior. |
| dist-src/index.js | safe | No malicious patterns detected; code implements GitHub API throttling with expected Bottleneck usage and no exfiltration, credential harvesting, or dynamic execution. |
| dist-src/version.js | safe | Cleared by Jev triage; no further analysis needed |
| dist-src/wrap-request.js | safe | No malicious patterns detected; the code implements rate-limiting/retry logic for GitHub API requests without exfiltration, credential harvesting, obfuscation, or process execution. |
Frequently asked questions
Is @octokit/plugin-throttling safe to use?
No confirmed malware was found in @octokit/plugin-throttling@11.0.3, but the review flagged 1 medium severity finding for risky patterns worth checking before you rely on it.
Does @octokit/plugin-throttling contain malware?
No malware was identified in @octokit/plugin-throttling@11.0.3 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @octokit/plugin-throttling checked?
Togoder Security downloaded the published npm package and had an AI model read its 6 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @octokit/plugin-throttling together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @octokit/plugin-throttling@11.0.3, cost nothing.