Togoder security

npm package security report

jayson npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 4.2.0 Files reviewed 32 Size 75.7 KB Scanned

Summary

Togoder Security scanned the npm package jayson@4.2.0 on Oct 4, 2026. An AI review of 32 source files produced 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
3
low

Findings 3

low

Unsanitized parameter parsing

NPS-93BB5E8D9C5F

Parameters passed via --params are parsed with JSON.parse and forwarded to the remote endpoint. Not an internal vulnerability, but part of the expected network request behavior.

bin/jayson.js:15
low

Network request capability

NPS-DA98C9D7048E

The CLI acts as a JSON-RPC client that can connect to arbitrary HTTP, HTTPS, or TCP endpoints specified via --url or --socket. While expected for this tool, it could be abused to send requests to attacker-controlled servers if invoked maliciously.

bin/jayson.js:37
low

Dynamic socket address parsing

NPS-94CCAF762424

parseSocket tokenizes user input with ':' and can construct TCP socket connections to arbitrary IP/host addresses. No external data is harvested, but unrestricted outbound connection targets are supported.

bin/jayson.js:66

Files reviewed

FileVerdictWhat the reviewer saw
bin/jayson.js medium The script is a legitimate JSON-RPC client CLI with no signs of data exfiltration, credential harvesting, obfuscation, backdoors, or install-time execution; only expected outbound network request capabilities are present.
index.js safe Cleared by Jev triage; no further analysis needed
lib/client/browser/index.js safe No malicious patterns detected
lib/client/http.js safe No malicious patterns detected
lib/client/https.js safe No malicious patterns detected
lib/client/index.js safe No malicious patterns detected in the analyzed client module.
lib/client/tcp.js safe No malicious patterns detected; the file implements a standard Jayson TCP client using net.connect and no suspicious data exfiltration, credential harvesting, or dynamic code execution.
lib/client/tls.js safe No malicious patterns detected
lib/client/websocket.js safe No malicious patterns detected; the code is a legitimate JSON-RPC WebSocket client implementation for the Jayson library.
lib/generateRequest.js safe No malicious patterns detected; the code is a standard JSON-RPC request generator with no network, filesystem, or process activity.
lib/index.js safe Cleared by Jev triage; no further analysis needed
lib/method.js safe No malicious patterns detected in the Method constructor and execution logic; it is a benign RPC method wrapper with no network, filesystem, process, or dynamic code execution activity.
lib/server/http.js safe Cleared by Jev triage; no further analysis needed
lib/server/https.js safe Cleared by Jev triage; no further analysis needed
lib/server/index.js safe No malicious patterns detected in the server implementation; it is a standard JSON-RPC server module with no data exfiltration, credential harvesting, obfuscation, or process spawning.
lib/server/middleware.js safe No malicious patterns detected; the middleware is a standard JSON-RPC over HTTP handler with no data exfiltration, obfuscation, process spawning, or filesystem access.
lib/server/tcp.js safe No malicious patterns detected; the code is a standard Jayson TCP server implementation with no data exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
lib/server/tls.js safe No malicious patterns detected
lib/server/websocket.js safe No malicious patterns detected; the code implements a standard JSON-RPC WebSocket server without any suspicious behavior.
lib/utils.js safe The code is a JSON-RPC utility module that parses streams, handles HTTP requests, and serializes JSON without any suspicious network, filesystem, process, credential-harvesting, or dynamic-code-execution patterns.
promise/index.js safe Cleared by Jev triage; no further analysis needed
promise/lib/client/browser/index.js safe No malicious patterns detected; the code is a standard Promise wrapper for a Jayson browser client with no external data transmission, credential harvesting, obfuscation, or install-time execution.
promise/lib/client/http.js safe No malicious patterns detected in the promise client HTTP wrapper.
promise/lib/client/https.js safe No malicious patterns detected; the file is a simple promisified wrapper around Jayson's HTTPS client and contains no exfiltration, obfuscation, process spawning, or suspicious filesystem/network activity.
promise/lib/client/index.js safe No malicious patterns detected; the code is a standard promise wrapper for a JSON-RPC client library.
Show 7 more files
FileVerdictWhat the reviewer saw
promise/lib/client/tcp.js safe No malicious patterns detected; the file is a straightforward promise wrapper for a Jayson TCP client with no exfiltration, credential harvesting, obfuscation, or dynamic code execution.
promise/lib/client/tls.js safe No malicious patterns detected; the file is a standard promisified TLS client wrapper for the Jayson library.
promise/lib/client/websocket.js safe No malicious patterns detected
promise/lib/index.js safe Cleared by Jev triage; no further analysis needed
promise/lib/method.js safe No malicious patterns detected
promise/lib/server.js safe Cleared by Jev triage; no further analysis needed
promise/lib/utils.js safe Cleared by Jev triage; no further analysis needed

Scanned versions of jayson

VersionVerdictFilesScanned
4.2.0 Needs review 32 Oct 4, 2026

Frequently asked questions

Is jayson safe to use?

No confirmed malware was found in jayson@4.2.0, but the review flagged 3 low severity findings for risky patterns worth checking before you rely on it.

Does jayson contain malware?

No malware was identified in jayson@4.2.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was jayson checked?

Togoder Security downloaded the published npm package and had an AI model read its 32 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan jayson together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in jayson@4.2.0, cost nothing.

Related security reports