Summary
Togoder Security scanned the npm package rpc-websockets@9.3.2 on Oct 4, 2026. An AI review of 5 source files produced 4 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings 4
Dynamic code execution risk
NPS-5E3438629B05
The bundle includes JSPM core polyfills and a bundled EventEmitter implementation. No eval, new Function, or dynamic eval-like constructs were found. The code uses JSON.parse for decoding and standard WebSocket/RPC logic.
Environment variable access
NPS-1A6E59A5138F
The code includes a browser shim for Node.js process.env with hardcoded values (PATH, LANG, PWD, HOME, TMP) and does not read or transmit real environment variables.
Network communication
NPS-F2F2188AE840
The library establishes WebSocket connections and performs RPC calls (login, listMethods, subscribe, etc.). This is expected behavior for an RPC-WebSocket client and no exfiltration to hardcoded external servers is present. Users control the target URL.
No install or import-time execution
NPS-D58101B36898
The bundle contains no top-level code that executes shell commands, writes files, spawns processes, or performs network requests upon import. All actions are triggered by explicit method calls on the client class.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/index.browser-bundle.js | safe | The bundled code is a standard WebSocket RPC client with Node.js browser shims; no malicious patterns, exfiltration, or backdoors were detected. |
| dist/index.browser.cjs | safe | No malicious patterns detected in this WebSocket JSON-RPC client implementation |
| dist/index.browser.mjs | safe | No malicious patterns detected; the code implements a standard JSON-RPC WebSocket client with expected browser WebSocket usage and no suspicious data exfiltration, credential harvesting, or dynamic code execution. |
| dist/index.cjs | safe | No malicious patterns detected; the code is a legitimate JSON-RPC WebSocket client/server library using standard dependencies (ws, eventemitter3, uuid) without data exfiltration, obfuscation, or suspicious system/network access. |
| dist/index.mjs | safe | No malicious patterns detected; this is a legitimate JSON-RPC WebSocket client/server library without data exfiltration, credential harvesting, obfuscation, or shell execution. |
Scanned versions of rpc-websockets
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 9.3.2 | No issues | 5 | Oct 4, 2026 |
Frequently asked questions
Is rpc-websockets safe to use?
Our AI source review of rpc-websockets@9.3.2 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does rpc-websockets contain malware?
No malware was identified in rpc-websockets@9.3.2 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was rpc-websockets checked?
Togoder Security downloaded the published npm package and had an AI model read its 5 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan rpc-websockets together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in rpc-websockets@9.3.2, cost nothing.