# @metamask/json-rpc-middleware-stream@7.0.2 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:07:24.000Z
- Files reviewed: 10
- Findings: 2 low severity findings
- Report: https://security.togoder.click/npm/@metamask/json-rpc-middleware-stream
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @metamask/json-rpc-middleware-stream@7.0.2 on Oct 4, 2026. An AI review of 10 source files produced 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] dynamic module loading

Finding ID: `NPS-814285098C52`

File: `dist/index.js:3`

The file requires two local chunk files (./chunk-IDTAZSDC.js and ./chunk-3SFZPJR3.js). While these paths are static and local, the actual implementation of createEngineStream and createStreamMiddleware is hidden in those chunks and cannot be verified from this entry point. This pattern is common in bundled npm packages but could conceal malicious code if the chunks were tampered with.

### [low] source map reference

Finding ID: `NPS-D0A12180E714`

File: `dist/index.js:10`

Includes a sourceMappingURL reference (index.js.map). Source maps can occasionally expose original source code, internal paths, or proprietary logic if published unintentionally, though this is not inherently malicious.

## Files reviewed

- `dist/index.js` (medium): The entry point itself contains only re-exports of two local chunks with no direct suspicious behavior, but the actual logic is hidden in the required chunk files and should be reviewed to fully assess risk.
- `dist/chunk-2YBP3PJ2.mjs` (safe): No malicious patterns detected
- `dist/chunk-3SFZPJR3.js` (safe): No malicious patterns detected; the code implements a stream middleware for handling JSON-RPC requests/responses with retry logic and safe event emission.
- `dist/chunk-446QYOBP.mjs` (safe): No malicious patterns detected; the code implements a standard stream-based middleware for JSON-RPC request/response handling.
- `dist/chunk-IDTAZSDC.js` (safe): The file contains only a simple utility to create a Duplex stream from an engine object with no suspicious network, filesystem, or process activity.
- `dist/createEngineStream.js` (safe): No malicious patterns detected
- `dist/createEngineStream.mjs` (safe): No malicious patterns detected
- `dist/createStreamMiddleware.js` (safe): The file is a simple re-export module that imports createStreamMiddleware from a local chunk and exports it as default, with no suspicious behavior.
- `dist/createStreamMiddleware.mjs` (safe): No malicious patterns detected
- `dist/index.mjs` (safe): The file is a simple ESM re-export module importing two named functions from local chunk files and re-exporting them; no malicious patterns, network calls, process spawning, obfuscation, or install-time execution were detected.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
