# rpc-websockets@9.3.2 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:40:12.000Z
- Files reviewed: 5
- Findings: 4 low severity findings
- Report: https://security.togoder.click/npm/rpc-websockets
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package rpc-websockets@9.3.2 on Oct 4, 2026. An AI review of 5 source files produced 4 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] Dynamic code execution risk

Finding ID: `NPS-5E3438629B05`

File: `dist/index.browser-bundle.js`

The bundle includes JSPM core polyfills and a bundled EventEmitter implementation. No eval, new Function, or dynamic eval-like constructs were found. The code uses JSON.parse for decoding and standard WebSocket/RPC logic.

### [low] Environment variable access

Finding ID: `NPS-1A6E59A5138F`

File: `dist/index.browser-bundle.js`

The code includes a browser shim for Node.js process.env with hardcoded values (PATH, LANG, PWD, HOME, TMP) and does not read or transmit real environment variables.

### [low] Network communication

Finding ID: `NPS-F2F2188AE840`

File: `dist/index.browser-bundle.js`

The library establishes WebSocket connections and performs RPC calls (login, listMethods, subscribe, etc.). This is expected behavior for an RPC-WebSocket client and no exfiltration to hardcoded external servers is present. Users control the target URL.

### [low] No install or import-time execution

Finding ID: `NPS-D58101B36898`

File: `dist/index.browser-bundle.js`

The bundle contains no top-level code that executes shell commands, writes files, spawns processes, or performs network requests upon import. All actions are triggered by explicit method calls on the client class.

## Files reviewed

- `dist/index.browser-bundle.js` (safe): The bundled code is a standard WebSocket RPC client with Node.js browser shims; no malicious patterns, exfiltration, or backdoors were detected.
- `dist/index.browser.cjs` (safe): No malicious patterns detected in this WebSocket JSON-RPC client implementation
- `dist/index.browser.mjs` (safe): No malicious patterns detected; the code implements a standard JSON-RPC WebSocket client with expected browser WebSocket usage and no suspicious data exfiltration, credential harvesting, or dynamic code execution.
- `dist/index.cjs` (safe): No malicious patterns detected; the code is a legitimate JSON-RPC WebSocket client/server library using standard dependencies (ws, eventemitter3, uuid) without data exfiltration, obfuscation, or suspicious system/network access.
- `dist/index.mjs` (safe): No malicious patterns detected; this is a legitimate JSON-RPC WebSocket client/server library without data exfiltration, credential harvesting, obfuscation, or shell execution.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
