Togoder security

npm package security report

@solana/web3.js@1.98.4 security report

Risky patterns found that deserve a look.

Needs review Version 1.98.4 Files reviewed 59 Size 2.9 MB Scanned

Summary

Togoder Security scanned the npm package @solana/web3.js@1.98.4 on Oct 4, 2026. An AI review of 59 source files produced 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
1
low

Findings 3

medium

Potential type confusion / prototype pollution

NPS-AE34CA55C3F5

The Struct constructor uses Object.assign(this, properties) with an arbitrary properties object. If untrusted data is used to construct a Struct, an attacker could include special keys like __proto__ or constructor to pollute the prototype or alter behavior of the instance.

src/utils/borsh-schema.ts:6
medium

Unsafe deserialization

NPS-662F2DE8A27A

The class exposes decodeUnchecked which calls deserializeUnchecked from the borsh library. This function performs deserialization without validating the input against the schema, which can allow attackers to craft malicious payloads that bypass expected data structures, potentially leading to prototype pollution, unexpected object shapes, or other deserialization-based attacks if untrusted data is passed to it.

src/utils/borsh-schema.ts:19
low

Protocol-relative URL handling

NPS-734C3BB692E6

The polyfill rewrites protocol-relative URLs (starting with '//') to 'https:' prefix. While this is a legitimate normalization for fetch semantics, it silently changes the scheme of the URL. This could be used to decrypt/send data over HTTPS when a caller intended a relative path, though it is standard behavior and not inherently malicious.

src/fetch-impl.ts:10

Files reviewed

FileVerdictWhat the reviewer saw
src/fetch-impl.ts medium No malicious patterns detected; the code is a straightforward fetch polyfill using node-fetch with a harmless protocol-relative URL normalization, though that normalization warrants a low-severity note.
src/utils/borsh-schema.ts medium The file is a utility wrapper around borsh serialization for Solana; it contains no obvious malicious code but exposes an unchecked deserialization method and an unsafe Object.assign pattern that could be dangerous if fed untrusted input.
src/__forks__/browser/fetch-impl.ts safe Cleared by Jev triage; no further analysis needed
src/__forks__/react-native/fetch-impl.ts safe Cleared by Jev triage; no further analysis needed
src/account-data.ts safe Cleared by Jev triage; no further analysis needed
src/account.ts safe No malicious patterns detected
src/blockhash.ts safe Cleared by Jev triage; no further analysis needed
src/bpf-loader-deprecated.ts safe No malicious patterns detected
src/bpf-loader.ts safe No malicious patterns detected
src/epoch-schedule.ts safe Cleared by Jev triage; no further analysis needed
src/errors.ts safe No malicious patterns detected
src/fee-calculator.ts safe Cleared by Jev triage; no further analysis needed
src/index.ts safe No malicious patterns detected in this barrel export file, which only re-exports modules and defines a constant.
src/instruction.ts safe Cleared by Jev triage; no further analysis needed
src/keypair.ts safe No malicious patterns detected; the code is a standard Ed25519 keypair implementation without network, file system, or process manipulation.
src/layout.ts safe No malicious patterns detected; this is a standard Solana buffer layout utility file with no network, filesystem, process, or obfuscated code.
src/loader.ts safe No malicious patterns detected; this is legitimate Solana blockchain program loader code performing on-chain program deployment operations.
src/message/account-keys.ts safe No malicious patterns detected; the code is a standard Solana SDK account key utility with no network, filesystem, or dynamic execution activity.
src/message/compiled-keys.ts safe No malicious patterns detected; the code is a legitimate Solana web3.js CompiledKeys implementation with no network, filesystem, process execution, or obfuscation concerns.
src/message/index.ts safe No malicious patterns detected
src/message/legacy.ts safe This is legitimate Solana legacy message serialization/deserialization code with no malicious patterns detected.
src/message/v0.ts safe No malicious patterns detected; the code implements Solana transaction message serialization/deserialization with proper bounds checking and no external calls or dynamic execution.
src/message/versioned.ts safe No malicious patterns detected
src/nonce-account.ts safe No malicious patterns detected; the code is a standard Solana SDK nonce account deserializer with only legitimate local imports and no network, filesystem, or process activity.
src/programs/address-lookup-table/index.ts safe This is a legitimate Solana Address Lookup Table instruction builder library with no malicious patterns, no network calls, no file system access, and no credential harvesting.
Show 34 more files
FileVerdictWhat the reviewer saw
src/programs/address-lookup-table/state.ts safe No malicious patterns detected
src/programs/compute-budget.ts safe No malicious patterns detected; the file contains standard Solana Compute Budget program instruction encoding/decoding logic with no network, filesystem, process, or obfuscated code.
src/programs/ed25519.ts safe No malicious patterns detected; the code is a straightforward Solana Ed25519 program instruction builder with no network, filesystem, process, or dynamic execution behavior.
src/programs/index.ts safe No malicious patterns detected; the file only contains re-exports of local Solana program modules.
src/programs/secp256k1.ts safe No malicious patterns detected; the code is a standard implementation of Solana's Secp256k1Program for creating secp256k1 instructions without any exfiltration, code execution, or other suspicious behavior.
src/programs/stake.ts safe This is a legitimate Solana stake program SDK with no malicious patterns, network calls, exfiltration, or dynamic code execution.
src/programs/system.ts safe No malicious patterns detected in the Solana system program instruction encoding/decoding code.
src/programs/vote.ts safe No malicious patterns detected; the code is a legitimate Solana vote program SDK implementation.
src/publickey.ts safe This is a legitimate Solana PublicKey implementation with no malicious patterns such as exfiltration, credential harvesting, obfuscation, or shell execution.
src/rpc-websocket.ts safe No malicious patterns detected in the RPC WebSocket client implementation.
src/sysvar.ts safe No malicious patterns detected
src/timing.ts safe Cleared by Jev triage; no further analysis needed
src/transaction/constants.ts safe No malicious patterns detected
src/transaction/expiry-custom-errors.ts safe No malicious patterns detected
src/transaction/index.ts safe No malicious patterns detected; the file only re-exports members from sibling modules without any executable logic.
src/transaction/legacy.ts safe No malicious patterns detected; this is a legitimate Solana legacy transaction implementation with no data exfiltration, credential harvesting, obfuscated code, or dynamic code execution.
src/transaction/message.ts safe No malicious patterns detected in the analyzed TypeScript file.
src/transaction/versioned.ts safe No malicious patterns detected; the file implements standard Solana versioned transaction serialization and signing logic without any security concerns.
src/utils/assert.ts safe Cleared by Jev triage; no further analysis needed
src/utils/bigint.ts safe Cleared by Jev triage; no further analysis needed
src/utils/cluster.ts safe Cleared by Jev triage; no further analysis needed
src/utils/ed25519.ts safe No malicious patterns detected; the code is a straightforward Ed25519 utility wrapper with no exfiltration, obfuscation, or suspicious runtime behavior.
src/utils/guarded-array-utils.ts safe Cleared by Jev triage; no further analysis needed
src/utils/index.ts safe No malicious patterns detected in the re-export barrel file; all exports are static and no suspicious code is present.
src/utils/makeWebsocketUrl.ts safe Cleared by Jev triage; no further analysis needed
src/utils/promise-timeout.ts safe Cleared by Jev triage; no further analysis needed
src/utils/secp256k1.ts safe The code is a straightforward wrapper around @noble/curves secp256k1 for ECDSA signing and key validation with no malicious patterns, network calls, or environment access.
src/utils/send-and-confirm-raw-transaction.ts safe No malicious patterns detected in this Solana web3.js utility function that sends and confirms raw transactions.
src/utils/send-and-confirm-transaction.ts safe No malicious patterns detected
src/utils/shortvec-encoding.ts safe Cleared by Jev triage; no further analysis needed
src/utils/sleep.ts safe Cleared by Jev triage; no further analysis needed
src/utils/to-buffer.ts safe Cleared by Jev triage; no further analysis needed
src/validator-info.ts safe No malicious patterns detected; the code is a legitimate validator info deserializer for Solana with no network, filesystem, process, or eval activity.
src/vote-account.ts safe No malicious patterns detected

Frequently asked questions

Is @solana/web3.js safe to use?

No confirmed malware was found in @solana/web3.js@1.98.4, but the review flagged 2 medium, 1 low severity findings for risky patterns worth checking before you rely on it.

Does @solana/web3.js contain malware?

No malware was identified in @solana/web3.js@1.98.4 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @solana/web3.js checked?

Togoder Security downloaded the published npm package and had an AI model read its 59 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @solana/web3.js together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @solana/web3.js@1.98.4, cost nothing.

Related security reports