Togoder security

npm package security report

rpc-websockets@9.3.2 security report

No malicious code found.

No issues Version 9.3.2 Files reviewed 5 Size 120.7 KB Scanned

Summary

Togoder Security scanned the npm package rpc-websockets@9.3.2 on Oct 4, 2026. An AI review of 5 source files produced 4 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
4
low

Findings 4

low

Dynamic code execution risk

NPS-5E3438629B05

The bundle includes JSPM core polyfills and a bundled EventEmitter implementation. No eval, new Function, or dynamic eval-like constructs were found. The code uses JSON.parse for decoding and standard WebSocket/RPC logic.

dist/index.browser-bundle.js
low

Environment variable access

NPS-1A6E59A5138F

The code includes a browser shim for Node.js process.env with hardcoded values (PATH, LANG, PWD, HOME, TMP) and does not read or transmit real environment variables.

dist/index.browser-bundle.js
low

Network communication

NPS-F2F2188AE840

The library establishes WebSocket connections and performs RPC calls (login, listMethods, subscribe, etc.). This is expected behavior for an RPC-WebSocket client and no exfiltration to hardcoded external servers is present. Users control the target URL.

dist/index.browser-bundle.js
low

No install or import-time execution

NPS-D58101B36898

The bundle contains no top-level code that executes shell commands, writes files, spawns processes, or performs network requests upon import. All actions are triggered by explicit method calls on the client class.

dist/index.browser-bundle.js

Files reviewed

FileVerdictWhat the reviewer saw
dist/index.browser-bundle.js safe The bundled code is a standard WebSocket RPC client with Node.js browser shims; no malicious patterns, exfiltration, or backdoors were detected.
dist/index.browser.cjs safe No malicious patterns detected in this WebSocket JSON-RPC client implementation
dist/index.browser.mjs safe No malicious patterns detected; the code implements a standard JSON-RPC WebSocket client with expected browser WebSocket usage and no suspicious data exfiltration, credential harvesting, or dynamic code execution.
dist/index.cjs safe No malicious patterns detected; the code is a legitimate JSON-RPC WebSocket client/server library using standard dependencies (ws, eventemitter3, uuid) without data exfiltration, obfuscation, or suspicious system/network access.
dist/index.mjs safe No malicious patterns detected; this is a legitimate JSON-RPC WebSocket client/server library without data exfiltration, credential harvesting, obfuscation, or shell execution.

Frequently asked questions

Is rpc-websockets safe to use?

Our AI source review of rpc-websockets@9.3.2 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does rpc-websockets contain malware?

No malware was identified in rpc-websockets@9.3.2 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was rpc-websockets checked?

Togoder Security downloaded the published npm package and had an AI model read its 5 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan rpc-websockets together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in rpc-websockets@9.3.2, cost nothing.

Related security reports