The currently recommended replacement is the double-csrf package
https://www.npmjs.com/package/csrf-csrf