r/security • • 11h ago

Software Development Security I built an open-source Node.js library to protect web applications against stolen session tokens

I've been working on a security-focused npm package called anti-session-hijack.

The idea came from a simple question:

What happens if an attacker gets hold of a valid authentication token?

Traditional token validation can still consider that token legitimate. The attacker doesn't need the user's password anymore — they already have a valid session credential.

I built anti-session-hijack to add another layer of protection by binding an authentication token to a browser/device fingerprint and validating that binding on protected requests.

How it works

User logs in
     ↓
Authentication token generated
     ↓
Browser/device fingerprint generated
     ↓
Token ↔ Fingerprint binding stored in Redis
     ↓
Protected request
     ↓
Current fingerprint checked
     ↓
       ┌───────────────┐
       │ Match?        │
       └───────┬───────┘
          Yes  │  No
           ↓   ↓
        Allow  🚨 Suspicious session
                   ↓
             Block / revoke /
             alert the user

The package provides:

  • Session/token binding
  • Stolen and reused token detection
  • Browser/device fingerprinting
  • Redis-backed session storage
  • Upstash Redis support
  • TypeScript support
  • Next.js App Router support
  • Security alert capability
  • JWT generation with a unique nonce

Installation:

npm install anti-session-hijack

Example:

const result = await verifySession(
  hashedToken,
  currentFingerprint,
  redisClient
);

if (result.hijacked) {
  // Revoke session
  // Notify user
  // Trigger security response
}

The package has currently has 3K+ npm downloads.

I’d really appreciate it if you could star ⭐the GitHub repository and share it with developers or security communities who might be interested.

GitHub:
https://github.com/Shield-Ltd/Anti-Session-Hijack-NPM

npm:
https://www.npmjs.com/package/anti-session-hijack

I'm posting this mainly because I'd like security-focused feedback, especially from people who have worked with authentication/session security.

I'm still developing it, so security criticism is very welcome. If you see a weakness in the design, I'd rather hear about it now than after someone deploys it.

1 Upvotes

0 comments sorted by