Summary
Togoder Security scanned the npm package bottleneck@2.19.5 on Oct 6, 2026. An AI review of 24 source files produced 1 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 4
Dynamic code execution
NPS-165AB4CAB0E7
The code uses eval("require")("ioredis") to dynamically load the ioredis module. While the comment explains this is to avoid bundler inlining of an optional dependency, eval is a dangerous pattern that can be abused if the module name or resolution path is influenced by attacker-controlled input.
Dynamic code execution via eval
NPS-93A79B702585
Uses eval("require")("redis") to dynamically load the redis module. While the comment explains this is to avoid bundler inlining, eval with string literal is a code smell. However, the string is a static literal, so it is not directly exploitable with external input.
Top-level import side effect
NPS-F20963FB5F1D
The module unconditionally requires 'regenerator-runtime/runtime' at import time, which patches the global environment and executes top-level code when the module is loaded. While regenerator-runtime is a widely used and generally benign Babel/runtime polyfill, importing it unconditionally means any consumer of this file executes third-party runtime code as a side effect of a simple require.
Indirect module loading
NPS-D3863E2BAC24
module.exports re-exports './Bottleneck', meaning the actual attack surface of this package is in a sibling file that is not provided for review. The top-level file is only a thin wrapper, so any malicious logic could be hidden in the referenced module and would not appear here.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/IORedisConnection.js | medium | The file is a legitimate Bottleneck Redis connection wrapper, but it uses eval for dynamic module loading, which is a security concern despite an explanatory comment. |
| lib/RedisConnection.js | medium | The code is a legitimate Redis connection wrapper for Bottleneck with no malicious intent; only a minor concern is the use of eval() for dynamic module loading, which is a common bundler workaround but should be noted. |
| lib/es5.js | medium | No direct malicious patterns are present in this wrapper file, but it unconditionally loads a runtime polyfill at import time and defers all substantive behavior to an unreviewed sibling module, warranting further inspection of './Bottleneck'. |
| lib/Batcher.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/Bottleneck.js | safe | No malicious patterns detected; the code is a legitimate rate limiter library with standard Babel-compiled async helpers and expected module imports. |
| lib/BottleneckError.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/DLList.js | safe | No malicious patterns detected; the file implements a simple doubly linked list with optional increment/decrement callbacks and contains no network, filesystem, process, or dynamic code execution behavior. |
| lib/Events.js | safe | No malicious patterns detected; the file implements a standard event emitter with async support and does not contain any network, filesystem, process execution, or obfuscated code. |
| lib/Group.js | safe | No malicious patterns detected; the code is a legitimate rate-limiting library implementation with no signs of exfiltration, credential harvesting, obfuscation, or other red flags. |
| lib/Job.js | safe | This is a legitimate implementation of the Bottleneck job scheduling library with no malicious patterns detected. |
| lib/LocalDatastore.js | safe | No malicious patterns detected; the code implements a local rate-limiting datastore with no external network, filesystem, credential, or process execution activity. |
| lib/Queues.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/RedisDatastore.js | safe | No malicious patterns detected; the code is a legitimate Redis-backed datastore implementation for the Bottleneck library. |
| lib/Scripts.js | safe | No malicious patterns detected; the code is a benign script loader for Lua templates used by a task queue (likely BullMQ) and contains no exfiltration, obfuscation, dynamic execution, or suspicious behavior. |
| lib/States.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/Sync.js | safe | No malicious patterns detected |
| lib/index.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/parser.js | safe | Cleared by Jev triage; no further analysis needed |
| light.js | safe | No malicious patterns detected; the file is a legitimate ES2017 build of the Bottleneck rate limiter library without clustering support. |
| rollup.config.es5.js | safe | No malicious patterns detected; the Rollup configuration uses standard, legitimate plugins and contains no obfuscation, data exfiltration, credential harvesting, or dynamic execution. |
| rollup.config.light.js | safe | Cleared by Jev triage; no further analysis needed |
| scripts/assemble_lua.js | safe | The script reads local Lua source files and prints their combined contents as JSON; no malicious patterns were detected. |
| scripts/version.js | safe | No malicious patterns detected |
| test.ts | safe | This is a TypeScript type-checking test file for the Bottleneck library with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution. |
Scanned versions of bottleneck
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 2.19.5 | Needs review | 24 | Oct 6, 2026 |
Frequently asked questions
Is bottleneck safe to use?
No confirmed malware was found in bottleneck@2.19.5, but the review flagged 1 medium, 3 low severity findings for risky patterns worth checking before you rely on it.
Does bottleneck contain malware?
No malware was identified in bottleneck@2.19.5 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was bottleneck checked?
Togoder Security downloaded the published npm package and had an AI model read its 24 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan bottleneck together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in bottleneck@2.19.5, cost nothing.