# eth-json-rpc-filters@6.0.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:29:27.000Z
- Files reviewed: 9
- Findings: 2 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/eth-json-rpc-filters
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package eth-json-rpc-filters@6.0.1 on Oct 4, 2026. An AI review of 9 source files produced 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Insecure randomness

Finding ID: `NPS-4C48B4C836D5`

File: `hexUtils.js:45`

The function unsafeRandomBytes explicitly uses Math.random() to generate random bytes. Math.random() is not cryptographically secure and its output is predictable. If this function is used for security-sensitive purposes such as generating private keys, nonces, or session tokens, it could lead to vulnerabilities. The naming 'unsafeRandomBytes' suggests awareness, but the presence of such a function in a utility module may encourage misuse.

### [medium] Weak random number generation for subscription IDs

Finding ID: `NPS-C2AFCDE5B054`

File: `subscriptionManager.js:33`

The code uses `unsafeRandomBytes(16)` to generate subscription IDs. If `unsafeRandomBytes` is not cryptographically secure (e.g., uses Math.random or a weak PRNG), it could allow attackers to predict or brute-force subscription IDs, leading to unauthorized access to subscription data or denial of service. The name 'unsafe' suggests it may intentionally use a non-cryptographic source.

### [low] Potential unhandled promise rejection / async destroy calls

Finding ID: `NPS-B1A11E7315A3`

File: `subscriptionManager.js:115`

The `destroy` function calls `subscriptions[id].destroy()` without awaiting or catching errors. While not a direct security issue, it could lead to resource leaks or unhandled rejections if destroy fails. More importantly, the asynchronous destroy in `createSubNewHeads` removes a listener, but if the blockTracker emits events during the async gap, it might cause unexpected behavior.

## Files reviewed

- `hexUtils.js` (medium): The code provides utility functions for hex and block reference manipulation, but includes an insecure random byte generator using Math.random(), which is cryptographically weak and could be dangerous if misused for security purposes.
- `subscriptionManager.js` (medium): The code appears to be a legitimate Ethereum subscription manager, but uses a function named 'unsafeRandomBytes' for generating subscription IDs, which may introduce predictability risks.
- `base-filter-history.js` (safe): Cleared by Jev triage; no further analysis needed
- `base-filter.js` (safe): Cleared by Jev triage; no further analysis needed
- `block-filter.js` (safe): No malicious patterns detected
- `getBlocksForRange.js` (safe): No malicious patterns detected; the code performs standard Ethereum JSON-RPC block queries with retry logic and no exfiltration, credential access, obfuscation, or suspicious system operations.
- `index.js` (safe): No malicious patterns detected; the code is a legitimate Ethereum JSON-RPC filter middleware implementation.
- `log-filter.js` (safe): No malicious patterns detected
- `tx-filter.js` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
