Summary
Togoder Security scanned the npm package @metamask/json-rpc-engine@8.0.2 on Oct 4, 2026. An AI review of 28 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings
No findings. The reviewer saw nothing malicious or risky in this version.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/JsonRpcEngine.js | safe | This file is a simple CommonJS re-export shim that only requires local bundled chunks and exposes JsonRpcEngine; no malicious patterns detected. |
| dist/JsonRpcEngine.mjs | safe | This is a simple re-export shim for the JsonRpcEngine class with no executable logic, network activity, or suspicious patterns. |
| dist/chunk-2LXAFMJD.js | safe | No malicious patterns detected; this is a legitimate JSON-RPC engine implementation with no data exfiltration, credential harvesting, obfuscation, or other suspicious behavior. |
| dist/chunk-3AC2MIND.js | safe | No malicious patterns detected |
| dist/chunk-5HCYV4FV.mjs | safe | The code is a legitimate JSON-RPC engine implementation from MetaMask with no malicious patterns, network calls, or data exfiltration. |
| dist/chunk-6XXPTZV6.mjs | safe | No malicious patterns detected |
| dist/chunk-KFRJCTOQ.mjs | safe | No malicious patterns detected; the file only re-exports a simple middleware merging utility that relies on JsonRpcEngine. |
| dist/chunk-KNT3O2VO.mjs | safe | No malicious patterns detected |
| dist/chunk-KZ5RA76F.mjs | safe | No malicious patterns detected; the code is a simple middleware factory with no external I/O, execution, or obfuscation. |
| dist/chunk-PBQXMZM5.js | safe | No malicious patterns detected; the code is a benign middleware utility for remapping request/response IDs. |
| dist/chunk-R7LKI5H5.mjs | safe | No malicious patterns detected |
| dist/chunk-VK4MHWJV.js | safe | No malicious patterns detected |
| dist/chunk-XDGWQHNY.js | safe | No malicious patterns detected |
| dist/chunk-XUI43LEZ.mjs | safe | This file contains only standard TypeScript/JavaScript helper functions for private field access and no malicious patterns. |
| dist/chunk-Z4BLTVTB.js | safe | No malicious patterns detected; the file contains only standard transpiled helper functions for private field access. |
| dist/chunk-ZYXL5TCS.js | safe | No malicious patterns detected |
| dist/createAsyncMiddleware.js | safe | No malicious patterns detected in the re-export shim; it only requires local chunks and exports a function. |
| dist/createAsyncMiddleware.mjs | safe | This is a simple ES module re-export file that imports and re-exports createAsyncMiddleware from an internal chunk, with no suspicious patterns detected. |
| dist/createScaffoldMiddleware.js | safe | This is a simple re-export module with no malicious patterns detected. |
| dist/createScaffoldMiddleware.mjs | safe | No malicious patterns detected |
| dist/getUniqueId.js | safe | No malicious patterns detected; the file is a simple re-export of a function from a local chunk. |
| dist/getUniqueId.mjs | safe | No malicious patterns detected |
| dist/idRemapMiddleware.js | safe | No malicious patterns detected; the file is a simple re-export of modules without suspicious behavior. |
| dist/idRemapMiddleware.mjs | safe | The file is a simple re-export module that imports createIdRemapMiddleware from a local chunk and re-exports it, with no malicious patterns detected. |
| dist/index.js | safe | No malicious patterns detected; the file is a standard entry point that re-exports modules from local chunks. |
Show 3 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/index.mjs | safe | No malicious patterns detected |
| dist/mergeMiddleware.js | safe | No malicious patterns detected; the file is a simple re-export of mergeMiddleware from an internal chunk. |
| dist/mergeMiddleware.mjs | safe | No malicious patterns detected; the file is a simple ES module re-export wrapper with static imports and no suspicious behavior. |
Affected version ranges
None of the 2 scanned versions of @metamask/json-rpc-engine are flagged high or critical. The latest scanned version, 11.0.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 9.0.3 – 11.0.0 | Not scanned | 3 | >=9.0.3 <=11.0.0 | |
| 7.3.3 – 8.0.2 | No issues | 2 | >=7.3.3 <=8.0.2 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of @metamask/json-rpc-engine
Frequently asked questions
Is @metamask/json-rpc-engine safe to use?
Our AI source review of @metamask/json-rpc-engine@8.0.2 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does @metamask/json-rpc-engine contain malware?
No malware was identified in @metamask/json-rpc-engine@8.0.2 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @metamask/json-rpc-engine checked?
Togoder Security downloaded the published npm package and had an AI model read its 28 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @metamask/json-rpc-engine together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @metamask/json-rpc-engine@8.0.2, cost nothing.