Togoder security

npm package security report

@solana/rpc@3.0.3 security report

Risky patterns found that deserve a look.

Needs review Version 3.0.3 Files reviewed 5 Size 30.6 KB Scanned

Summary

Togoder Security scanned the npm package @solana/rpc@3.0.3 on Oct 4, 2026. An AI review of 5 source files produced 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
4
low

Findings 4

low

Environment variable access

NPS-1DCD2FDA1053

The code reads process.env.NODE_ENV to determine whether to include a debugging token in error objects. This is a standard Node.js pattern, but it does access environment variables at runtime.

dist/index.node.cjs:57
low

Suspicious network configuration

NPS-2AB2108A2504

The transport layer constructs HTTP headers for Solana RPC communication including a 'solana-client' identifier. While expected for a Solana RPC client, the code does establish network connections and sends request payloads and headers to configured endpoints. Third-party packages should be vetted to ensure endpoints remain user-controlled and no hidden data is appended to requests.

dist/index.node.cjs:138
low

Module loading behavior

NPS-0B236BC36669

The module performs property enumeration and re-exporting of all keys from @solana/rpc-api and @solana/rpc-spec at import time using Object.keys().forEach(). While this is a standard re-export pattern and not inherently malicious, it does execute code at import time and could expose unexpected API surface or mask intentional malicious exports if those dependencies are compromised.

dist/index.node.cjs:150
low

No malicious patterns

NPS-E9E669C1AE68

Code is a legitimate Solana RPC client library. It imports standard Solana packages, implements request coalescing, RPC transport with HTTP headers, and error handling. No data exfiltration, credential harvesting, obfuscation, dynamic code execution, mining, backdoors, suspicious network requests, file system manipulation, process spawning, or dynamic imports detected. The only network activity is standard RPC transport to user-configured cluster URL. The setMaxListeners call is for AbortController signals, not malicious. Headers include solana-client identifier and accept-encoding, which are normal.

dist/index.node.mjs

Files reviewed

FileVerdictWhat the reviewer saw
dist/index.node.cjs medium This appears to be a legitimate Solana JSON-RPC client library with standard import-time re-export behavior and network transport configuration; no malicious patterns such as credential harvesting, code execution, or exfiltration were detected, though the import-time module enumeration and ambient network capability warrant low-severity caution.
dist/index.browser.cjs safe No malicious patterns detected; this is legitimate @solana/web3.js RPC transport code with standard request coalescing, header normalization, and error handling.
dist/index.browser.mjs safe No malicious patterns detected
dist/index.native.mjs safe No malicious patterns detected; the file is a legitimate Solana RPC client library using standard imports, error handling, and HTTP transport logic without data exfiltration, credential harvesting, obfuscation, or code execution.
dist/index.node.mjs safe The code appears to be a legitimate Solana RPC client library with no malicious patterns detected.

Affected version ranges

None of the 2 scanned versions of @solana/rpc are flagged high or critical. The latest scanned version, 5.0.0, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

2.1.15.0.0
VersionsVerdictCountRangeTop findings
5.0.0 No issues 1 5.0.0
3.0.3 Needs review 1 3.0.3
2.1.1 Not scanned 1 2.1.1

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of @solana/rpc

VersionVerdictFilesScanned
5.0.0 No issues 5 Oct 4, 2026
3.0.3 Needs review 5 Oct 4, 2026

Frequently asked questions

Is @solana/rpc safe to use?

No confirmed malware was found in @solana/rpc@3.0.3, but the review flagged 4 low severity findings for risky patterns worth checking before you rely on it.

Does @solana/rpc contain malware?

No malware was identified in @solana/rpc@3.0.3 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @solana/rpc checked?

Togoder Security downloaded the published npm package and had an AI model read its 5 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @solana/rpc together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @solana/rpc@3.0.3, cost nothing.

Related security reports