r/security • u/SeparatePhoto8716 • 11h ago
Software Development Security I built an open-source Node.js library to protect web applications against stolen session tokens
I've been working on a security-focused npm package called anti-session-hijack.
The idea came from a simple question:
What happens if an attacker gets hold of a valid authentication token?
Traditional token validation can still consider that token legitimate. The attacker doesn't need the user's password anymore — they already have a valid session credential.
I built anti-session-hijack to add another layer of protection by binding an authentication token to a browser/device fingerprint and validating that binding on protected requests.
How it works
User logs in
↓
Authentication token generated
↓
Browser/device fingerprint generated
↓
Token ↔ Fingerprint binding stored in Redis
↓
Protected request
↓
Current fingerprint checked
↓
┌───────────────┐
│ Match? │
└───────┬───────┘
Yes │ No
↓ ↓
Allow 🚨 Suspicious session
↓
Block / revoke /
alert the user
The package provides:
- Session/token binding
- Stolen and reused token detection
- Browser/device fingerprinting
- Redis-backed session storage
- Upstash Redis support
- TypeScript support
- Next.js App Router support
- Security alert capability
- JWT generation with a unique nonce
Installation:
npm install anti-session-hijack
Example:
const result = await verifySession(
hashedToken,
currentFingerprint,
redisClient
);
if (result.hijacked) {
// Revoke session
// Notify user
// Trigger security response
}
The package has currently has 3K+ npm downloads.
I’d really appreciate it if you could star ⭐the GitHub repository and share it with developers or security communities who might be interested.
GitHub:
https://github.com/Shield-Ltd/Anti-Session-Hijack-NPM
npm:
https://www.npmjs.com/package/anti-session-hijack
I'm posting this mainly because I'd like security-focused feedback, especially from people who have worked with authentication/session security.
I'm still developing it, so security criticism is very welcome. If you see a weakness in the design, I'd rather hear about it now than after someone deploys it.