# @solana/rpc-transport-http@5.0.0 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:17:04.000Z
- Files reviewed: 5
- Findings: 3 low severity findings
- Report: https://security.togoder.click/npm/@solana/rpc-transport-http
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @solana/rpc-transport-http@5.0.0 on Oct 4, 2026. An AI review of 5 source files produced 3 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] environment variable access

Finding ID: `NPS-20FACBCF5674`

File: `dist/index.native.mjs:72`

Reads process.env.NODE_ENV to conditionally enable development-mode header validation warnings. This is standard practice and not credential harvesting.

### [low] network request

Finding ID: `NPS-4861300FFBE0`

File: `dist/index.native.mjs:100`

The code performs HTTP POST requests to a user-configured RPC URL via fetch. This is expected behavior for a Solana RPC HTTP transport and does not constitute exfiltration.

### [low] Header Validation Logic

Finding ID: `NPS-C2769E4A426A`

File: `dist/index.node.mjs`

The code implements a header validation function that blocks forbidden HTTP headers (e.g., cookie, host, proxy-*, sec-*). This is a security feature, not a vulnerability. However, it only runs in non-production environments (process.env.NODE_ENV !== 'production'), which may allow header injection in production if custom headers are user-controlled. This is a low-severity design consideration, not a malicious pattern.

## Files reviewed

- `dist/index.browser.cjs` (safe): No malicious patterns detected; the code is a legitimate HTTP transport implementation for Solana RPC with proper header validation and no exfiltration, credential harvesting, or dynamic code execution.
- `dist/index.browser.mjs` (safe): No malicious patterns detected; the code is a legitimate Solana RPC HTTP transport implementation with proper header validation and no exfiltration, credential harvesting, or dynamic code execution.
- `dist/index.native.mjs` (safe): The code is a legitimate Solana RPC HTTP transport implementation with no malicious patterns; it only makes user-configured RPC requests.
- `dist/index.node.cjs` (safe): No malicious patterns detected; the code is a standard Solana RPC HTTP transport implementation with only defensive header validation and no exfiltration, credential harvesting, obfuscation, or backdoor behavior.
- `dist/index.node.mjs` (safe): The code is a legitimate Solana RPC HTTP transport client with no malicious patterns; it performs standard JSON-RPC requests and includes header validation as a security measure.

## Version ranges

None of the 2 scanned versions of @solana/rpc-transport-http are flagged high or critical. The latest scanned version, 5.0.0, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 3.0.3 – 5.0.0 (`>=3.0.3 <=5.0.0`): clean
- 2.1.1 (`2.1.1`): not scanned

## Scanned versions

- [5.0.0](https://security.togoder.click/npm/@solana/rpc-transport-http@5.0.0): safe, 2026-10-04T16:17:04.000Z
- [3.0.3](https://security.togoder.click/npm/@solana/rpc-transport-http@3.0.3): safe, 2026-10-04T16:05:11.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
