# @solana/rpc@3.0.3 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:04:48.000Z
- Files reviewed: 5
- Findings: 4 low severity findings
- Report: https://security.togoder.click/npm/@solana/rpc@3.0.3
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @solana/rpc@3.0.3 on Oct 4, 2026. An AI review of 5 source files produced 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] Environment variable access

Finding ID: `NPS-1DCD2FDA1053`

File: `dist/index.node.cjs:57`

The code reads process.env.NODE_ENV to determine whether to include a debugging token in error objects. This is a standard Node.js pattern, but it does access environment variables at runtime.

### [low] Suspicious network configuration

Finding ID: `NPS-2AB2108A2504`

File: `dist/index.node.cjs:138`

The transport layer constructs HTTP headers for Solana RPC communication including a 'solana-client' identifier. While expected for a Solana RPC client, the code does establish network connections and sends request payloads and headers to configured endpoints. Third-party packages should be vetted to ensure endpoints remain user-controlled and no hidden data is appended to requests.

### [low] Module loading behavior

Finding ID: `NPS-0B236BC36669`

File: `dist/index.node.cjs:150`

The module performs property enumeration and re-exporting of all keys from @solana/rpc-api and @solana/rpc-spec at import time using Object.keys().forEach(). While this is a standard re-export pattern and not inherently malicious, it does execute code at import time and could expose unexpected API surface or mask intentional malicious exports if those dependencies are compromised.

### [low] No malicious patterns

Finding ID: `NPS-E9E669C1AE68`

File: `dist/index.node.mjs`

Code is a legitimate Solana RPC client library. It imports standard Solana packages, implements request coalescing, RPC transport with HTTP headers, and error handling. No data exfiltration, credential harvesting, obfuscation, dynamic code execution, mining, backdoors, suspicious network requests, file system manipulation, process spawning, or dynamic imports detected. The only network activity is standard RPC transport to user-configured cluster URL. The setMaxListeners call is for AbortController signals, not malicious. Headers include solana-client identifier and accept-encoding, which are normal.

## Files reviewed

- `dist/index.node.cjs` (medium): This appears to be a legitimate Solana JSON-RPC client library with standard import-time re-export behavior and network transport configuration; no malicious patterns such as credential harvesting, code execution, or exfiltration were detected, though the import-time module enumeration and ambient network capability warrant low-severity caution.
- `dist/index.browser.cjs` (safe): No malicious patterns detected; this is legitimate @solana/web3.js RPC transport code with standard request coalescing, header normalization, and error handling.
- `dist/index.browser.mjs` (safe): No malicious patterns detected
- `dist/index.native.mjs` (safe): No malicious patterns detected; the file is a legitimate Solana RPC client library using standard imports, error handling, and HTTP transport logic without data exfiltration, credential harvesting, obfuscation, or code execution.
- `dist/index.node.mjs` (safe): The code appears to be a legitimate Solana RPC client library with no malicious patterns detected.

## Version ranges

None of the 2 scanned versions of @solana/rpc are flagged high or critical. The latest scanned version, 5.0.0, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 5.0.0 (`5.0.0`): clean
- 3.0.3 (`3.0.3`): medium
- 2.1.1 (`2.1.1`): not scanned

## Scanned versions

- [5.0.0](https://security.togoder.click/npm/@solana/rpc@5.0.0): safe, 2026-10-04T16:17:00.000Z
- [3.0.3](https://security.togoder.click/npm/@solana/rpc@3.0.3): medium, 2026-10-04T16:04:48.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
