# @solana/web3.js@1.98.4 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:54:43.000Z
- Files reviewed: 59
- Findings: 2 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/@solana/web3.js
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @solana/web3.js@1.98.4 on Oct 4, 2026. An AI review of 59 source files produced 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Potential type confusion / prototype pollution

Finding ID: `NPS-AE34CA55C3F5`

File: `src/utils/borsh-schema.ts:6`

The `Struct` constructor uses `Object.assign(this, properties)` with an arbitrary `properties` object. If untrusted data is used to construct a Struct, an attacker could include special keys like `__proto__` or `constructor` to pollute the prototype or alter behavior of the instance.

### [medium] Unsafe deserialization

Finding ID: `NPS-662F2DE8A27A`

File: `src/utils/borsh-schema.ts:19`

The class exposes `decodeUnchecked` which calls `deserializeUnchecked` from the borsh library. This function performs deserialization without validating the input against the schema, which can allow attackers to craft malicious payloads that bypass expected data structures, potentially leading to prototype pollution, unexpected object shapes, or other deserialization-based attacks if untrusted data is passed to it.

### [low] Protocol-relative URL handling

Finding ID: `NPS-734C3BB692E6`

File: `src/fetch-impl.ts:10`

The polyfill rewrites protocol-relative URLs (starting with '//') to 'https:' prefix. While this is a legitimate normalization for fetch semantics, it silently changes the scheme of the URL. This could be used to decrypt/send data over HTTPS when a caller intended a relative path, though it is standard behavior and not inherently malicious.

## Files reviewed

- `src/fetch-impl.ts` (medium): No malicious patterns detected; the code is a straightforward fetch polyfill using node-fetch with a harmless protocol-relative URL normalization, though that normalization warrants a low-severity note.
- `src/utils/borsh-schema.ts` (medium): The file is a utility wrapper around borsh serialization for Solana; it contains no obvious malicious code but exposes an unchecked deserialization method and an unsafe Object.assign pattern that could be dangerous if fed untrusted input.
- `src/__forks__/browser/fetch-impl.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/__forks__/react-native/fetch-impl.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/account-data.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/account.ts` (safe): No malicious patterns detected
- `src/blockhash.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/bpf-loader-deprecated.ts` (safe): No malicious patterns detected
- `src/bpf-loader.ts` (safe): No malicious patterns detected
- `src/epoch-schedule.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/errors.ts` (safe): No malicious patterns detected
- `src/fee-calculator.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/index.ts` (safe): No malicious patterns detected in this barrel export file, which only re-exports modules and defines a constant.
- `src/instruction.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/keypair.ts` (safe): No malicious patterns detected; the code is a standard Ed25519 keypair implementation without network, file system, or process manipulation.
- `src/layout.ts` (safe): No malicious patterns detected; this is a standard Solana buffer layout utility file with no network, filesystem, process, or obfuscated code.
- `src/loader.ts` (safe): No malicious patterns detected; this is legitimate Solana blockchain program loader code performing on-chain program deployment operations.
- `src/message/account-keys.ts` (safe): No malicious patterns detected; the code is a standard Solana SDK account key utility with no network, filesystem, or dynamic execution activity.
- `src/message/compiled-keys.ts` (safe): No malicious patterns detected; the code is a legitimate Solana web3.js CompiledKeys implementation with no network, filesystem, process execution, or obfuscation concerns.
- `src/message/index.ts` (safe): No malicious patterns detected
- `src/message/legacy.ts` (safe): This is legitimate Solana legacy message serialization/deserialization code with no malicious patterns detected.
- `src/message/v0.ts` (safe): No malicious patterns detected; the code implements Solana transaction message serialization/deserialization with proper bounds checking and no external calls or dynamic execution.
- `src/message/versioned.ts` (safe): No malicious patterns detected
- `src/nonce-account.ts` (safe): No malicious patterns detected; the code is a standard Solana SDK nonce account deserializer with only legitimate local imports and no network, filesystem, or process activity.
- `src/programs/address-lookup-table/index.ts` (safe): This is a legitimate Solana Address Lookup Table instruction builder library with no malicious patterns, no network calls, no file system access, and no credential harvesting.
- `src/programs/address-lookup-table/state.ts` (safe): No malicious patterns detected
- `src/programs/compute-budget.ts` (safe): No malicious patterns detected; the file contains standard Solana Compute Budget program instruction encoding/decoding logic with no network, filesystem, process, or obfuscated code.
- `src/programs/ed25519.ts` (safe): No malicious patterns detected; the code is a straightforward Solana Ed25519 program instruction builder with no network, filesystem, process, or dynamic execution behavior.
- `src/programs/index.ts` (safe): No malicious patterns detected; the file only contains re-exports of local Solana program modules.
- `src/programs/secp256k1.ts` (safe): No malicious patterns detected; the code is a standard implementation of Solana's Secp256k1Program for creating secp256k1 instructions without any exfiltration, code execution, or other suspicious behavior.
- `src/programs/stake.ts` (safe): This is a legitimate Solana stake program SDK with no malicious patterns, network calls, exfiltration, or dynamic code execution.
- `src/programs/system.ts` (safe): No malicious patterns detected in the Solana system program instruction encoding/decoding code.
- `src/programs/vote.ts` (safe): No malicious patterns detected; the code is a legitimate Solana vote program SDK implementation.
- `src/publickey.ts` (safe): This is a legitimate Solana PublicKey implementation with no malicious patterns such as exfiltration, credential harvesting, obfuscation, or shell execution.
- `src/rpc-websocket.ts` (safe): No malicious patterns detected in the RPC WebSocket client implementation.
- `src/sysvar.ts` (safe): No malicious patterns detected
- `src/timing.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/transaction/constants.ts` (safe): No malicious patterns detected
- `src/transaction/expiry-custom-errors.ts` (safe): No malicious patterns detected
- `src/transaction/index.ts` (safe): No malicious patterns detected; the file only re-exports members from sibling modules without any executable logic.
- `src/transaction/legacy.ts` (safe): No malicious patterns detected; this is a legitimate Solana legacy transaction implementation with no data exfiltration, credential harvesting, obfuscated code, or dynamic code execution.
- `src/transaction/message.ts` (safe): No malicious patterns detected in the analyzed TypeScript file.
- `src/transaction/versioned.ts` (safe): No malicious patterns detected; the file implements standard Solana versioned transaction serialization and signing logic without any security concerns.
- `src/utils/assert.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/utils/bigint.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/utils/cluster.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/utils/ed25519.ts` (safe): No malicious patterns detected; the code is a straightforward Ed25519 utility wrapper with no exfiltration, obfuscation, or suspicious runtime behavior.
- `src/utils/guarded-array-utils.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/utils/index.ts` (safe): No malicious patterns detected in the re-export barrel file; all exports are static and no suspicious code is present.
- `src/utils/makeWebsocketUrl.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/utils/promise-timeout.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/utils/secp256k1.ts` (safe): The code is a straightforward wrapper around @noble/curves secp256k1 for ECDSA signing and key validation with no malicious patterns, network calls, or environment access.
- `src/utils/send-and-confirm-raw-transaction.ts` (safe): No malicious patterns detected in this Solana web3.js utility function that sends and confirms raw transactions.
- `src/utils/send-and-confirm-transaction.ts` (safe): No malicious patterns detected
- `src/utils/shortvec-encoding.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/utils/sleep.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/utils/to-buffer.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/validator-info.ts` (safe): No malicious patterns detected; the code is a legitimate validator info deserializer for Solana with no network, filesystem, process, or eval activity.
- `src/vote-account.ts` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
