Initial release
🚀 v1.0.0 - Initial Release: The Security "Safety Net"
LibraryInTheMiddleJS (LITM) is a lightweight security proxy designed to provide a posture of Prevent, Detect, and Correct for legacy library dependencies.
We’ve all been there: you’re stuck with a legacy package because upgrading to the latest version would break your entire stack. LITM.js allows you to wrap those vulnerable dependencies in a secure layer, giving you visibility and control without changing a single line of the original library's code.
✨ Key Features
- 🛡️ Hardened Enforcement: Block calls to known-vulnerable methods (Blacklisting).
- 🔍 Zero-Trust Whitelisting: Explicitly allow only the methods your application actually uses.
- 📡 Transparent Telemetry: Stream execution data to Splunk, ELK, or local logs to verify that calls are non-damaging.
- 🚦 Flexible Posture: Switch between
Audit Mode(Detect) andEnforcement Mode(Block) with a single config flag.
📦 Installation & Quick Start
const LibraryInTheMiddle = require('./litm');
const legacyLib = require('vulnerable-legacy-package');
const secured = new LibraryInTheMiddle(legacyLib, {
name: "Legacy-API-Proxy",
transparent: false, // Set to true to just monitor
whitelist: ['safeMethodA', 'safeMethodB'],
onTelemetry: (data) => {
// Route to your SIEM/Collector
console.log(`[SECURITY EVENT]: ${data.action} on ${data.property}`);
}
});
module.exports = secured;
🛡️ Posture Strategy
| Goal | Mechanism |
|---|---|
| Prevent | Use transparent: false and a strict whitelist to stop unauthorized execution at the source. |
| Detect | Use the onTelemetry hook to monitor payload arguments, call frequency, and unexpected access patterns. |
| Correct | Use real-time logs to verify if a call was malicious and audit the impact immediately without downtime. |
🤝 Contributing
Found a bug or have a feature request? Open an issue on the GitHub Repository.