Summary
Togoder Security scanned the npm package @solana/web3.js@1.98.4 on Oct 4, 2026. An AI review of 59 source files produced 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 3
Potential type confusion / prototype pollution
NPS-AE34CA55C3F5
The Struct constructor uses Object.assign(this, properties) with an arbitrary properties object. If untrusted data is used to construct a Struct, an attacker could include special keys like __proto__ or constructor to pollute the prototype or alter behavior of the instance.
Unsafe deserialization
NPS-662F2DE8A27A
The class exposes decodeUnchecked which calls deserializeUnchecked from the borsh library. This function performs deserialization without validating the input against the schema, which can allow attackers to craft malicious payloads that bypass expected data structures, potentially leading to prototype pollution, unexpected object shapes, or other deserialization-based attacks if untrusted data is passed to it.
Protocol-relative URL handling
NPS-734C3BB692E6
The polyfill rewrites protocol-relative URLs (starting with '//') to 'https:' prefix. While this is a legitimate normalization for fetch semantics, it silently changes the scheme of the URL. This could be used to decrypt/send data over HTTPS when a caller intended a relative path, though it is standard behavior and not inherently malicious.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| src/fetch-impl.ts | medium | No malicious patterns detected; the code is a straightforward fetch polyfill using node-fetch with a harmless protocol-relative URL normalization, though that normalization warrants a low-severity note. |
| src/utils/borsh-schema.ts | medium | The file is a utility wrapper around borsh serialization for Solana; it contains no obvious malicious code but exposes an unchecked deserialization method and an unsafe Object.assign pattern that could be dangerous if fed untrusted input. |
| src/__forks__/browser/fetch-impl.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/__forks__/react-native/fetch-impl.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/account-data.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/account.ts | safe | No malicious patterns detected |
| src/blockhash.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/bpf-loader-deprecated.ts | safe | No malicious patterns detected |
| src/bpf-loader.ts | safe | No malicious patterns detected |
| src/epoch-schedule.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/errors.ts | safe | No malicious patterns detected |
| src/fee-calculator.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/index.ts | safe | No malicious patterns detected in this barrel export file, which only re-exports modules and defines a constant. |
| src/instruction.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/keypair.ts | safe | No malicious patterns detected; the code is a standard Ed25519 keypair implementation without network, file system, or process manipulation. |
| src/layout.ts | safe | No malicious patterns detected; this is a standard Solana buffer layout utility file with no network, filesystem, process, or obfuscated code. |
| src/loader.ts | safe | No malicious patterns detected; this is legitimate Solana blockchain program loader code performing on-chain program deployment operations. |
| src/message/account-keys.ts | safe | No malicious patterns detected; the code is a standard Solana SDK account key utility with no network, filesystem, or dynamic execution activity. |
| src/message/compiled-keys.ts | safe | No malicious patterns detected; the code is a legitimate Solana web3.js CompiledKeys implementation with no network, filesystem, process execution, or obfuscation concerns. |
| src/message/index.ts | safe | No malicious patterns detected |
| src/message/legacy.ts | safe | This is legitimate Solana legacy message serialization/deserialization code with no malicious patterns detected. |
| src/message/v0.ts | safe | No malicious patterns detected; the code implements Solana transaction message serialization/deserialization with proper bounds checking and no external calls or dynamic execution. |
| src/message/versioned.ts | safe | No malicious patterns detected |
| src/nonce-account.ts | safe | No malicious patterns detected; the code is a standard Solana SDK nonce account deserializer with only legitimate local imports and no network, filesystem, or process activity. |
| src/programs/address-lookup-table/index.ts | safe | This is a legitimate Solana Address Lookup Table instruction builder library with no malicious patterns, no network calls, no file system access, and no credential harvesting. |
Show 34 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| src/programs/address-lookup-table/state.ts | safe | No malicious patterns detected |
| src/programs/compute-budget.ts | safe | No malicious patterns detected; the file contains standard Solana Compute Budget program instruction encoding/decoding logic with no network, filesystem, process, or obfuscated code. |
| src/programs/ed25519.ts | safe | No malicious patterns detected; the code is a straightforward Solana Ed25519 program instruction builder with no network, filesystem, process, or dynamic execution behavior. |
| src/programs/index.ts | safe | No malicious patterns detected; the file only contains re-exports of local Solana program modules. |
| src/programs/secp256k1.ts | safe | No malicious patterns detected; the code is a standard implementation of Solana's Secp256k1Program for creating secp256k1 instructions without any exfiltration, code execution, or other suspicious behavior. |
| src/programs/stake.ts | safe | This is a legitimate Solana stake program SDK with no malicious patterns, network calls, exfiltration, or dynamic code execution. |
| src/programs/system.ts | safe | No malicious patterns detected in the Solana system program instruction encoding/decoding code. |
| src/programs/vote.ts | safe | No malicious patterns detected; the code is a legitimate Solana vote program SDK implementation. |
| src/publickey.ts | safe | This is a legitimate Solana PublicKey implementation with no malicious patterns such as exfiltration, credential harvesting, obfuscation, or shell execution. |
| src/rpc-websocket.ts | safe | No malicious patterns detected in the RPC WebSocket client implementation. |
| src/sysvar.ts | safe | No malicious patterns detected |
| src/timing.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/transaction/constants.ts | safe | No malicious patterns detected |
| src/transaction/expiry-custom-errors.ts | safe | No malicious patterns detected |
| src/transaction/index.ts | safe | No malicious patterns detected; the file only re-exports members from sibling modules without any executable logic. |
| src/transaction/legacy.ts | safe | No malicious patterns detected; this is a legitimate Solana legacy transaction implementation with no data exfiltration, credential harvesting, obfuscated code, or dynamic code execution. |
| src/transaction/message.ts | safe | No malicious patterns detected in the analyzed TypeScript file. |
| src/transaction/versioned.ts | safe | No malicious patterns detected; the file implements standard Solana versioned transaction serialization and signing logic without any security concerns. |
| src/utils/assert.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/utils/bigint.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/utils/cluster.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/utils/ed25519.ts | safe | No malicious patterns detected; the code is a straightforward Ed25519 utility wrapper with no exfiltration, obfuscation, or suspicious runtime behavior. |
| src/utils/guarded-array-utils.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/utils/index.ts | safe | No malicious patterns detected in the re-export barrel file; all exports are static and no suspicious code is present. |
| src/utils/makeWebsocketUrl.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/utils/promise-timeout.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/utils/secp256k1.ts | safe | The code is a straightforward wrapper around @noble/curves secp256k1 for ECDSA signing and key validation with no malicious patterns, network calls, or environment access. |
| src/utils/send-and-confirm-raw-transaction.ts | safe | No malicious patterns detected in this Solana web3.js utility function that sends and confirms raw transactions. |
| src/utils/send-and-confirm-transaction.ts | safe | No malicious patterns detected |
| src/utils/shortvec-encoding.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/utils/sleep.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/utils/to-buffer.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/validator-info.ts | safe | No malicious patterns detected; the code is a legitimate validator info deserializer for Solana with no network, filesystem, process, or eval activity. |
| src/vote-account.ts | safe | No malicious patterns detected |
Frequently asked questions
Is @solana/web3.js safe to use?
No confirmed malware was found in @solana/web3.js@1.98.4, but the review flagged 2 medium, 1 low severity findings for risky patterns worth checking before you rely on it.
Does @solana/web3.js contain malware?
No malware was identified in @solana/web3.js@1.98.4 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @solana/web3.js checked?
Togoder Security downloaded the published npm package and had an AI model read its 59 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @solana/web3.js together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @solana/web3.js@1.98.4, cost nothing.