Summary
Togoder Security scanned the npm package jayson@4.2.0 on Oct 4, 2026. An AI review of 32 source files produced 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 3
Unsanitized parameter parsing
NPS-93BB5E8D9C5F
Parameters passed via --params are parsed with JSON.parse and forwarded to the remote endpoint. Not an internal vulnerability, but part of the expected network request behavior.
Network request capability
NPS-DA98C9D7048E
The CLI acts as a JSON-RPC client that can connect to arbitrary HTTP, HTTPS, or TCP endpoints specified via --url or --socket. While expected for this tool, it could be abused to send requests to attacker-controlled servers if invoked maliciously.
Dynamic socket address parsing
NPS-94CCAF762424
parseSocket tokenizes user input with ':' and can construct TCP socket connections to arbitrary IP/host addresses. No external data is harvested, but unrestricted outbound connection targets are supported.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| bin/jayson.js | medium | The script is a legitimate JSON-RPC client CLI with no signs of data exfiltration, credential harvesting, obfuscation, backdoors, or install-time execution; only expected outbound network request capabilities are present. |
| index.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/client/browser/index.js | safe | No malicious patterns detected |
| lib/client/http.js | safe | No malicious patterns detected |
| lib/client/https.js | safe | No malicious patterns detected |
| lib/client/index.js | safe | No malicious patterns detected in the analyzed client module. |
| lib/client/tcp.js | safe | No malicious patterns detected; the file implements a standard Jayson TCP client using net.connect and no suspicious data exfiltration, credential harvesting, or dynamic code execution. |
| lib/client/tls.js | safe | No malicious patterns detected |
| lib/client/websocket.js | safe | No malicious patterns detected; the code is a legitimate JSON-RPC WebSocket client implementation for the Jayson library. |
| lib/generateRequest.js | safe | No malicious patterns detected; the code is a standard JSON-RPC request generator with no network, filesystem, or process activity. |
| lib/index.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/method.js | safe | No malicious patterns detected in the Method constructor and execution logic; it is a benign RPC method wrapper with no network, filesystem, process, or dynamic code execution activity. |
| lib/server/http.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/server/https.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/server/index.js | safe | No malicious patterns detected in the server implementation; it is a standard JSON-RPC server module with no data exfiltration, credential harvesting, obfuscation, or process spawning. |
| lib/server/middleware.js | safe | No malicious patterns detected; the middleware is a standard JSON-RPC over HTTP handler with no data exfiltration, obfuscation, process spawning, or filesystem access. |
| lib/server/tcp.js | safe | No malicious patterns detected; the code is a standard Jayson TCP server implementation with no data exfiltration, credential harvesting, obfuscation, or other suspicious behavior. |
| lib/server/tls.js | safe | No malicious patterns detected |
| lib/server/websocket.js | safe | No malicious patterns detected; the code implements a standard JSON-RPC WebSocket server without any suspicious behavior. |
| lib/utils.js | safe | The code is a JSON-RPC utility module that parses streams, handles HTTP requests, and serializes JSON without any suspicious network, filesystem, process, credential-harvesting, or dynamic-code-execution patterns. |
| promise/index.js | safe | Cleared by Jev triage; no further analysis needed |
| promise/lib/client/browser/index.js | safe | No malicious patterns detected; the code is a standard Promise wrapper for a Jayson browser client with no external data transmission, credential harvesting, obfuscation, or install-time execution. |
| promise/lib/client/http.js | safe | No malicious patterns detected in the promise client HTTP wrapper. |
| promise/lib/client/https.js | safe | No malicious patterns detected; the file is a simple promisified wrapper around Jayson's HTTPS client and contains no exfiltration, obfuscation, process spawning, or suspicious filesystem/network activity. |
| promise/lib/client/index.js | safe | No malicious patterns detected; the code is a standard promise wrapper for a JSON-RPC client library. |
Show 7 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| promise/lib/client/tcp.js | safe | No malicious patterns detected; the file is a straightforward promise wrapper for a Jayson TCP client with no exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
| promise/lib/client/tls.js | safe | No malicious patterns detected; the file is a standard promisified TLS client wrapper for the Jayson library. |
| promise/lib/client/websocket.js | safe | No malicious patterns detected |
| promise/lib/index.js | safe | Cleared by Jev triage; no further analysis needed |
| promise/lib/method.js | safe | No malicious patterns detected |
| promise/lib/server.js | safe | Cleared by Jev triage; no further analysis needed |
| promise/lib/utils.js | safe | Cleared by Jev triage; no further analysis needed |
Scanned versions of jayson
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 4.2.0 | Needs review | 32 | Oct 4, 2026 |
Frequently asked questions
Is jayson safe to use?
No confirmed malware was found in jayson@4.2.0, but the review flagged 3 low severity findings for risky patterns worth checking before you rely on it.
Does jayson contain malware?
No malware was identified in jayson@4.2.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was jayson checked?
Togoder Security downloaded the published npm package and had an AI model read its 32 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan jayson together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in jayson@4.2.0, cost nothing.