# bottleneck@2.19.5 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:14:02.000Z
- Files reviewed: 24
- Findings: 1 medium, 3 low severity findings
- Report: https://security.togoder.click/npm/bottleneck
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package bottleneck@2.19.5 on Oct 6, 2026. An AI review of 24 source files produced 1 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic code execution

Finding ID: `NPS-165AB4CAB0E7`

File: `lib/IORedisConnection.js:22`

The code uses eval("require")("ioredis") to dynamically load the ioredis module. While the comment explains this is to avoid bundler inlining of an optional dependency, eval is a dangerous pattern that can be abused if the module name or resolution path is influenced by attacker-controlled input.

### [low] Dynamic code execution via eval

Finding ID: `NPS-93A79B702585`

File: `lib/RedisConnection.js:17`

Uses eval("require")("redis") to dynamically load the redis module. While the comment explains this is to avoid bundler inlining, eval with string literal is a code smell. However, the string is a static literal, so it is not directly exploitable with external input.

### [low] Top-level import side effect

Finding ID: `NPS-F20963FB5F1D`

File: `lib/es5.js:3`

The module unconditionally requires 'regenerator-runtime/runtime' at import time, which patches the global environment and executes top-level code when the module is loaded. While regenerator-runtime is a widely used and generally benign Babel/runtime polyfill, importing it unconditionally means any consumer of this file executes third-party runtime code as a side effect of a simple require.

### [low] Indirect module loading

Finding ID: `NPS-D3863E2BAC24`

File: `lib/es5.js:5`

module.exports re-exports './Bottleneck', meaning the actual attack surface of this package is in a sibling file that is not provided for review. The top-level file is only a thin wrapper, so any malicious logic could be hidden in the referenced module and would not appear here.

## Files reviewed

- `lib/IORedisConnection.js` (medium): The file is a legitimate Bottleneck Redis connection wrapper, but it uses eval for dynamic module loading, which is a security concern despite an explanatory comment.
- `lib/RedisConnection.js` (medium): The code is a legitimate Redis connection wrapper for Bottleneck with no malicious intent; only a minor concern is the use of eval() for dynamic module loading, which is a common bundler workaround but should be noted.
- `lib/es5.js` (medium): No direct malicious patterns are present in this wrapper file, but it unconditionally loads a runtime polyfill at import time and defers all substantive behavior to an unreviewed sibling module, warranting further inspection of './Bottleneck'.
- `lib/Batcher.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/Bottleneck.js` (safe): No malicious patterns detected; the code is a legitimate rate limiter library with standard Babel-compiled async helpers and expected module imports.
- `lib/BottleneckError.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/DLList.js` (safe): No malicious patterns detected; the file implements a simple doubly linked list with optional increment/decrement callbacks and contains no network, filesystem, process, or dynamic code execution behavior.
- `lib/Events.js` (safe): No malicious patterns detected; the file implements a standard event emitter with async support and does not contain any network, filesystem, process execution, or obfuscated code.
- `lib/Group.js` (safe): No malicious patterns detected; the code is a legitimate rate-limiting library implementation with no signs of exfiltration, credential harvesting, obfuscation, or other red flags.
- `lib/Job.js` (safe): This is a legitimate implementation of the Bottleneck job scheduling library with no malicious patterns detected.
- `lib/LocalDatastore.js` (safe): No malicious patterns detected; the code implements a local rate-limiting datastore with no external network, filesystem, credential, or process execution activity.
- `lib/Queues.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/RedisDatastore.js` (safe): No malicious patterns detected; the code is a legitimate Redis-backed datastore implementation for the Bottleneck library.
- `lib/Scripts.js` (safe): No malicious patterns detected; the code is a benign script loader for Lua templates used by a task queue (likely BullMQ) and contains no exfiltration, obfuscation, dynamic execution, or suspicious behavior.
- `lib/States.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/Sync.js` (safe): No malicious patterns detected
- `lib/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/parser.js` (safe): Cleared by Jev triage; no further analysis needed
- `light.js` (safe): No malicious patterns detected; the file is a legitimate ES2017 build of the Bottleneck rate limiter library without clustering support.
- `rollup.config.es5.js` (safe): No malicious patterns detected; the Rollup configuration uses standard, legitimate plugins and contains no obfuscation, data exfiltration, credential harvesting, or dynamic execution.
- `rollup.config.light.js` (safe): Cleared by Jev triage; no further analysis needed
- `scripts/assemble_lua.js` (safe): The script reads local Lua source files and prints their combined contents as JSON; no malicious patterns were detected.
- `scripts/version.js` (safe): No malicious patterns detected
- `test.ts` (safe): This is a TypeScript type-checking test file for the Bottleneck library with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
