@sharkvoid/rasp
v2.2.13
Published
Production-grade Runtime Application Self-Protection for Express, Next.js, Firebase, and Supabase. Defends against SQL injection, XSS, path traversal, command injection, bots, brute force, and AI-powered attackers. Powered by SharkVoid.
Maintainers
Readme
@sharkvoid/rasp
Runtime Application Self-Protection for Node.js, powered by SharkVoid. Every request passes through nine detection layers before reaching your route handlers. Attacks are blocked, tarpitted, or flagged in milliseconds. Your dashboard updates in real time.
Install
npm install @sharkvoid/raspRequires Node 18+.
Quick Start
const express = require('express');
const { sharkvoidRasp } = require('@sharkvoid/rasp');
const app = express();
app.use(express.json());
app.use(sharkvoidRasp({
agentId: 'rasp_xxxxxxxx_xxxxxx',
secret: 'your-webhook-secret',
}));
app.get('/', (req, res) => res.send('Hello world'));
app.listen(3000);Get your agentId and secret by creating an agent at sharkvoid.com.
What It Detects
SQL injection, XSS, path traversal, LFI, command injection, SSTI, XXE, prototype pollution, brute force, bots and scanners, AI agents, credential harvesting, and encoding bypass attacks. Requests are decoded through URL encoding, base64, HTML entities, hex escapes, Unicode normalization, and null bytes before scanning, so encoding tricks do not evade detection.
How Risk Scoring Works
Every request gets a score from 0 to 100 combining IP reputation, pattern matches, behavioral signals, header analysis, and async LLM review. The score maps to an action automatically.
| Score | Action | |---|---| | 0-29 | Allow | | 30-49 | Watch and log | | 50-69 | Challenge (CAPTCHA) | | 70-84 | Tarpit with convincing fake data | | 85-94 | Block, 24-hour IP ban | | 95-100 | Block, permanent ban |
Tarpitted requests receive realistic fake responses: fake JWT tokens, fake .env files, fake passwd files, fake user lists. The attacker thinks they succeeded.
Modes
Switch modes from your dashboard with no redeploy. Changes take effect within 60 seconds.
Block — enforces everything. Recommended for production.
Challenge — shows CAPTCHA to suspicious requests. Humans pass, bots fail.
Monitor — logs everything, blocks nothing. Start here to baseline your traffic.
Paused — all analysis skipped, every request passes through immediately.
Platform Adapters
| Platform | Import |
|---|---|
| Express / Node.js | @sharkvoid/rasp |
| Next.js (Edge Middleware) | @sharkvoid/rasp/nextjs |
| Firebase Functions | @sharkvoid/rasp/firebase |
| AWS Lambda | @sharkvoid/rasp/lambda |
| Azure Functions | @sharkvoid/rasp/azure |
| Supabase Edge Functions | @sharkvoid/rasp/supabase |
Tarpit and CAPTCHA are not available on serverless platforms due to timeout and billing constraints. Behavioral analysis resets on cold starts in Deno-based environments (Supabase). All other detection layers work fully across every platform.
Optional: Geo-IP
npm install geoip-liteAdds country detection to your event logs. Without it, country shows as null.
Links
- Dashboard and agent setup: sharkvoid.com
- Documentation: sharkvoid.com/rasp/docs
- How it works in depth: sharkvoid.com/rasp/how-it-works
