Semgrep added three JavaScript-focused rulesets to its registry—p/javascript, p/nodejs, and p/expressjs—to separate browser-side JavaScript checks from Node.js API misuse and Express framework misconfigurations. The expanded coverage includes detections for prototype pollution, bracket object injection, non-literal regular expressions, hardcoded secrets, shell command execution with shell=true, weak cryptography, TLS misconfigurations, insecure cookie settings, CORS issues, response injection, and XSS patterns. The JavaScript coverage aligns with long-standing research into prototype pollution attacks in Node.js, a class of flaws that can let attackers tamper with object inheritance and trigger unsafe application behavior.
The release comes alongside broader discussion of JavaScript static analysis tradeoffs as GitLab shifted most of its SAST analyzers from ESLint and Bandit to Semgrep. Semgrep said its approach offers easier custom rule authoring, multilingual support, and stronger CI/CD integration, while comparisons noted that ESLint can be faster and produce fewer false positives in some JavaScript cases. Semgrep also published guidance for building higher-quality custom rules, recommending iterative testing against real repositories, use of constructs such as pattern-not and pattern-either, and continuous tuning to reduce false positives and false negatives before enforcing scans in pull requests.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Semgrep announced three JavaScript-focused registry rulesets: an expanded p/javascript ruleset and new p/nodejs and p/expressjs rulesets. The update separated previously mixed coverage into clearer scopes for browser JavaScript, Node.js risks, and Express misconfigurations.
The authors reported submitting a merge request to GitLab's Semgrep analyzer to reduce false positives in the non-literal regular expression detection rule.
The Semgrep comparison article states that GitLab transitioned most of its SAST analyzers from ESLint and Bandit to Semgrep, marking a tooling change in GitLab's security scanning approach.
Semgrep published a methodology guide for creating and refining custom Semgrep rules, covering iterative testing, false-positive reduction, and validation across repositories.
A research paper documenting JavaScript prototype pollution attacks in Node.js was published, providing technical details on the vulnerability class referenced by later detection content.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
semgrep.dev
Open sourcesemgrep.dev
Open sourcesemgrep.dev
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.