Summary
Togoder Security scanned the Go package github.com/grpc-ecosystem/go-grpc-middleware@v1.4.0 on Oct 5, 2026. An AI review of 70 source files produced 5 medium, 7 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 12
Sensitive data logging
NPS-45331EA7534B
The interceptors log full gRPC request and response payloads (including any credentials, tokens, PII, or secrets in protobuf messages) to the configured logger via logProtoMessageAsJson. This is a data-exposure risk if loggers are aggregated, shipped, or accessible to unauthorized parties. Mitigated somewhat by the decider callback, but logging full payloads by default is dangerous.
Mutable Global Marshaller
NPS-43C659957269
JsonPbMarshaller is an exported package-level variable that can be reassigned by any importing code. A malicious or compromised dependency could replace it with a custom marshaller that exfiltrates payload contents or performs side effects during marshaling.
Sensitive Data Logging
NPS-F1175FDA3164
The interceptors log full gRPC request and response payloads as JSON. Payloads can contain credentials, tokens, PII, or other secrets, and these are written to log destinations in cleartext. This is a design-level data exposure concern rather than malicious code.
Unredacted Payload Capture
NPS-247F086FC55C
logProtoMessageAsJson and the stream wrappers blindly serialize any proto.Message without field redaction or masking, ensuring all message content is logged regardless of sensitivity.
Sensitive Data Logging
NPS-2C94CB1D23A7
The interceptors intentionally log full gRPC request and response payloads (including potentially sensitive data like credentials, tokens, PII) using JsonPbMarshaller. This could lead to sensitive information disclosure in log files if the decider is misconfigured or too permissive.
Potential secret leakage via dynamic marshaller
NPS-909B849C095C
JsonPbMarshaller is a mutable package-level variable that can be reassigned at runtime. If a malicious or compromised package reassigns it to an attacker-controlled marshaler, it could exfiltrate serialized payload data. Since this is set at the package level with no synchronization, any imported code can replace it.
Error content logged as request key
NPS-949F75EF2FB2
In logProtoMessageAsJson, when JSON marshaling fails, the error object is logged under the same key intended for the payload. Depending on the error, this could inadvertently leak internal details, though this is minor.
Global Mutable State
NPS-1C5E5190399C
JsonPbMarshaller is an exported package-level variable that can be reassigned at runtime by any code importing this package. An attacker with code execution could replace it with a malicious marshaler to exfiltrate protobuf contents or inject data into logs, though this is not malicious on its own.
Reflection-Based Serialization
NPS-71CE5515BDBC
Use of AddReflected and custom MarshalJSON alongside proto.Message type assertion means arbitrary protobuf message contents are serialized into logs. Combined with a permissive decider, this amplifies the sensitive-data-logging risk.
Local network listener for tests
NPS-58BC70791E72
The suite binds to 127.0.0.1:0 and serves gRPC for test purposes only. No external network communication or data exfiltration is present.
Insecure gRPC client option behind test flag
NPS-148868CAF7B7
When the -use_tls flag is false, the client uses grpc.WithInsecure(). This is a test-only convenience flag and does not represent malicious behavior, though it disables transport security in test environments.
Test-only self-signed certificate generation
NPS-EF9F5A8FD1CD
generateCertAndKey generates a self-signed RSA certificate/key pair for TLS testing. It is used only within the test suite to create in-memory TLS credentials for a localhost gRPC server and client. No private key is exfiltrated or persisted to disk.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| logging/kit/payload_interceptors.go | medium | The code is a legitimate gRPC logging interceptor but logs full request/response payloads, which can expose sensitive data if not carefully gated by the decider; no outright malicious patterns (exfiltration, backdoors, exec, credential harvesting) are present. |
| logging/logrus/payload_interceptors.go | medium | No overt malicious patterns (exfiltration, exec, credential harvesting, backdoors) were found, but the library deliberately logs full gRPC payloads in JSON form and exposes a mutable global marshaller, creating significant sensitive-data-exposure risk in production deployments. |
| logging/zap/payload_interceptors.go | medium | Legitimate gRPC logging middleware with no malicious code, but it intentionally logs full request/response payloads which can leak sensitive data if not carefully gated by the decider. |
| auth/auth.go | safe | Cleared by Jev triage; no further analysis needed |
| auth/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| auth/metadata.go | safe | No malicious patterns detected |
| chain.go | safe | Cleared by Jev triage; no further analysis needed |
| doc.go | safe | Cleared by Jev triage; no further analysis needed |
| logging/common.go | safe | Cleared by Jev triage; no further analysis needed |
| logging/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| logging/kit/client_interceptors.go | safe | No malicious patterns detected; the code is a standard gRPC logging interceptor that only logs call metadata and does not perform any suspicious operations. |
| logging/kit/ctxkit/context.go | safe | Cleared by Jev triage; no further analysis needed |
| logging/kit/ctxkit/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| logging/kit/doc.go | safe | No malicious patterns detected; the file contains only package documentation comments and a package declaration. |
| logging/kit/options.go | safe | Cleared by Jev triage; no further analysis needed |
| logging/kit/server_interceptors.go | safe | Cleared by Jev triage; no further analysis needed |
| logging/logrus/client_interceptors.go | safe | No malicious patterns detected |
| logging/logrus/context.go | safe | Cleared by Jev triage; no further analysis needed |
| logging/logrus/ctxlogrus/context.go | safe | Cleared by Jev triage; no further analysis needed |
| logging/logrus/ctxlogrus/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| logging/logrus/ctxlogrus/noop.go | safe | Cleared by Jev triage; no further analysis needed |
| logging/logrus/doc.go | safe | No malicious patterns detected in the provided Go documentation file. |
| logging/logrus/grpclogger.go | safe | No malicious patterns detected |
| logging/logrus/options.go | safe | Cleared by Jev triage; no further analysis needed |
| logging/logrus/server_interceptors.go | safe | Cleared by Jev triage; no further analysis needed |
Show 45 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| logging/settable/doc.go | safe | No malicious patterns detected |
| logging/settable/logsettable.go | safe | No malicious patterns detected; the code is a benign thread-safe gRPC logger wrapper. |
| logging/zap/client_interceptors.go | safe | No malicious patterns detected; the code is a standard gRPC logging interceptor with no data exfiltration, credential harvesting, or dynamic code execution. |
| logging/zap/context.go | safe | Cleared by Jev triage; no further analysis needed |
| logging/zap/ctxzap/context.go | safe | Cleared by Jev triage; no further analysis needed |
| logging/zap/ctxzap/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| logging/zap/doc.go | safe | No malicious patterns detected |
| logging/zap/grpclogger.go | safe | No malicious patterns detected; the code is a benign gRPC logging adapter for zap with no data exfiltration, credential harvesting, or dynamic code execution. |
| logging/zap/options.go | safe | Cleared by Jev triage; no further analysis needed |
| logging/zap/server_interceptors.go | safe | Cleared by Jev triage; no further analysis needed |
| ratelimit/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| ratelimit/ratelimit.go | safe | Cleared by Jev triage; no further analysis needed |
| recovery/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| recovery/interceptors.go | safe | No malicious patterns detected |
| recovery/options.go | safe | Cleared by Jev triage; no further analysis needed |
| retry/backoff.go | safe | Cleared by Jev triage; no further analysis needed |
| retry/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| retry/options.go | safe | Cleared by Jev triage; no further analysis needed |
| retry/retry.go | safe | No malicious patterns detected; this is a legitimate gRPC retry middleware library with standard client interceptor logic. |
| tags/context.go | safe | Cleared by Jev triage; no further analysis needed |
| tags/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| tags/fieldextractor.go | safe | The code is a benign gRPC context tags field extractor using reflection; no malicious patterns such as data exfiltration, command execution, or obfuscation were found. |
| tags/interceptors.go | safe | No malicious patterns detected |
| tags/logrus/context.go | safe | Cleared by Jev triage; no further analysis needed |
| tags/options.go | safe | Cleared by Jev triage; no further analysis needed |
| tags/zap/context.go | safe | Cleared by Jev triage; no further analysis needed |
| testing/gogotestproto/fields.pb.go | safe | Generated Go protobuf code with no malicious patterns, network calls, or install-time side effects |
| testing/interceptor_suite.go | safe | The file is a standard gRPC interceptor test suite that generates an in-memory self-signed certificate for local TLS testing and contains no malicious patterns. |
| testing/mutex_readerwriter.go | safe | Cleared by Jev triage; no further analysis needed |
| testing/pingservice.go | safe | Cleared by Jev triage; no further analysis needed |
| testing/testproto/test.manual_extractfields.pb.go | safe | Cleared by Jev triage; no further analysis needed |
| testing/testproto/test.manual_validator.pb.go | safe | Cleared by Jev triage; no further analysis needed |
| testing/testproto/test.pb.go | safe | Standard protoc-gen-go generated gRPC service definitions and message types with no malicious patterns, obfuscated code, network calls, file access, or command execution. |
| tracing/opentracing/client_interceptors.go | safe | No malicious patterns detected |
| tracing/opentracing/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| tracing/opentracing/id_extract.go | safe | No malicious patterns detected; the code is a benign gRPC OpenTracing middleware utility that extracts trace IDs into context tags without any exfiltration, execution, or credential-harvesting behavior. |
| tracing/opentracing/metadata.go | safe | Cleared by Jev triage; no further analysis needed |
| tracing/opentracing/options.go | safe | Cleared by Jev triage; no further analysis needed |
| tracing/opentracing/server_interceptors.go | safe | This is a legitimate OpenTracing gRPC middleware interceptor with no malicious patterns, no data exfiltration, no credential harvesting, and no dynamic code execution. |
| util/backoffutils/backoff.go | safe | Cleared by Jev triage; no further analysis needed |
| util/metautils/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| util/metautils/nicemd.go | safe | Cleared by Jev triage; no further analysis needed |
| validator/doc.go | safe | Cleared by Jev triage; no further analysis needed |
| validator/validator.go | safe | Cleared by Jev triage; no further analysis needed |
| wrappers.go | safe | Cleared by Jev triage; no further analysis needed |
Frequently asked questions
Is github.com/grpc-ecosystem/go-grpc-middleware safe to use?
No confirmed malware was found in github.com/grpc-ecosystem/go-grpc-middleware@v1.4.0, but the review flagged 5 medium, 7 low severity findings for risky patterns worth checking before you rely on it.
Does github.com/grpc-ecosystem/go-grpc-middleware contain malware?
No malware was identified in github.com/grpc-ecosystem/go-grpc-middleware@v1.4.0 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was github.com/grpc-ecosystem/go-grpc-middleware checked?
Togoder Security downloaded the published Go package and had an AI model read its 70 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan github.com/grpc-ecosystem/go-grpc-middleware together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/grpc-ecosystem/go-grpc-middleware@v1.4.0, cost nothing.