Togoder security

npm package security report

@metamask/json-rpc-middleware-stream@7.0.2 security report

Risky patterns found that deserve a look.

Needs review Version 7.0.2 Files reviewed 10 Size 7.0 KB Scanned

Summary

Togoder Security scanned the npm package @metamask/json-rpc-middleware-stream@7.0.2 on Oct 4, 2026. An AI review of 10 source files produced 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
2
low

Findings 2

low

dynamic module loading

NPS-814285098C52

The file requires two local chunk files (./chunk-IDTAZSDC.js and ./chunk-3SFZPJR3.js). While these paths are static and local, the actual implementation of createEngineStream and createStreamMiddleware is hidden in those chunks and cannot be verified from this entry point. This pattern is common in bundled npm packages but could conceal malicious code if the chunks were tampered with.

dist/index.js:3
low

source map reference

NPS-D0A12180E714

Includes a sourceMappingURL reference (index.js.map). Source maps can occasionally expose original source code, internal paths, or proprietary logic if published unintentionally, though this is not inherently malicious.

dist/index.js:10

Files reviewed

FileVerdictWhat the reviewer saw
dist/index.js medium The entry point itself contains only re-exports of two local chunks with no direct suspicious behavior, but the actual logic is hidden in the required chunk files and should be reviewed to fully assess risk.
dist/chunk-2YBP3PJ2.mjs safe No malicious patterns detected
dist/chunk-3SFZPJR3.js safe No malicious patterns detected; the code implements a stream middleware for handling JSON-RPC requests/responses with retry logic and safe event emission.
dist/chunk-446QYOBP.mjs safe No malicious patterns detected; the code implements a standard stream-based middleware for JSON-RPC request/response handling.
dist/chunk-IDTAZSDC.js safe The file contains only a simple utility to create a Duplex stream from an engine object with no suspicious network, filesystem, or process activity.
dist/createEngineStream.js safe No malicious patterns detected
dist/createEngineStream.mjs safe No malicious patterns detected
dist/createStreamMiddleware.js safe The file is a simple re-export module that imports createStreamMiddleware from a local chunk and exports it as default, with no suspicious behavior.
dist/createStreamMiddleware.mjs safe No malicious patterns detected
dist/index.mjs safe The file is a simple ESM re-export module importing two named functions from local chunk files and re-exporting them; no malicious patterns, network calls, process spawning, obfuscation, or install-time execution were detected.

Frequently asked questions

Is @metamask/json-rpc-middleware-stream safe to use?

No confirmed malware was found in @metamask/json-rpc-middleware-stream@7.0.2, but the review flagged 2 low severity findings for risky patterns worth checking before you rely on it.

Does @metamask/json-rpc-middleware-stream contain malware?

No malware was identified in @metamask/json-rpc-middleware-stream@7.0.2 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @metamask/json-rpc-middleware-stream checked?

Togoder Security downloaded the published npm package and had an AI model read its 10 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @metamask/json-rpc-middleware-stream together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @metamask/json-rpc-middleware-stream@7.0.2, cost nothing.

Related security reports