Summary
Togoder Security scanned the npm package @metamask/json-rpc-middleware-stream@7.0.2 on Oct 4, 2026. An AI review of 10 source files produced 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 2
dynamic module loading
NPS-814285098C52
The file requires two local chunk files (./chunk-IDTAZSDC.js and ./chunk-3SFZPJR3.js). While these paths are static and local, the actual implementation of createEngineStream and createStreamMiddleware is hidden in those chunks and cannot be verified from this entry point. This pattern is common in bundled npm packages but could conceal malicious code if the chunks were tampered with.
source map reference
NPS-D0A12180E714
Includes a sourceMappingURL reference (index.js.map). Source maps can occasionally expose original source code, internal paths, or proprietary logic if published unintentionally, though this is not inherently malicious.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/index.js | medium | The entry point itself contains only re-exports of two local chunks with no direct suspicious behavior, but the actual logic is hidden in the required chunk files and should be reviewed to fully assess risk. |
| dist/chunk-2YBP3PJ2.mjs | safe | No malicious patterns detected |
| dist/chunk-3SFZPJR3.js | safe | No malicious patterns detected; the code implements a stream middleware for handling JSON-RPC requests/responses with retry logic and safe event emission. |
| dist/chunk-446QYOBP.mjs | safe | No malicious patterns detected; the code implements a standard stream-based middleware for JSON-RPC request/response handling. |
| dist/chunk-IDTAZSDC.js | safe | The file contains only a simple utility to create a Duplex stream from an engine object with no suspicious network, filesystem, or process activity. |
| dist/createEngineStream.js | safe | No malicious patterns detected |
| dist/createEngineStream.mjs | safe | No malicious patterns detected |
| dist/createStreamMiddleware.js | safe | The file is a simple re-export module that imports createStreamMiddleware from a local chunk and exports it as default, with no suspicious behavior. |
| dist/createStreamMiddleware.mjs | safe | No malicious patterns detected |
| dist/index.mjs | safe | The file is a simple ESM re-export module importing two named functions from local chunk files and re-exporting them; no malicious patterns, network calls, process spawning, obfuscation, or install-time execution were detected. |
Frequently asked questions
Is @metamask/json-rpc-middleware-stream safe to use?
No confirmed malware was found in @metamask/json-rpc-middleware-stream@7.0.2, but the review flagged 2 low severity findings for risky patterns worth checking before you rely on it.
Does @metamask/json-rpc-middleware-stream contain malware?
No malware was identified in @metamask/json-rpc-middleware-stream@7.0.2 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @metamask/json-rpc-middleware-stream checked?
Togoder Security downloaded the published npm package and had an AI model read its 10 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @metamask/json-rpc-middleware-stream together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @metamask/json-rpc-middleware-stream@7.0.2, cost nothing.