Summary
Togoder Security scanned the npm package @base-org/account@2.4.0 on Oct 4, 2026. An AI review of 105 source files produced 25 medium, 32 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 57
Sensitive data logged to telemetry
NPS-348172CCC95A
logSubscriptionCompleted writes data.permissionHash into a 'status' telemetry field. If permissionHash is a cryptographic secret or authorization token, this would transmit sensitive material to an analytics backend. The intentional comment 'Using status field to store permission hash' indicates this is deliberate.
Dynamic code execution
NPS-8B86C4FB851F
The script content from TELEMETRY_SCRIPT_CONTENT is injected into a dynamically created <script> element via script.textContent, effectively executing arbitrary inlined JavaScript in the page context. While the content is imported from a local module, this pattern is a vector for hidden code and makes the executed payload invisible to static analysis of this file alone.
Telemetry performed without consent / at import/run time
NPS-D0221AD2D77E
loadTelemetryScript is exported and executed by consumers, and initCCA runs immediately when invoked, initializing tracking and identifying the user without any user consent check or opt-out mechanism in this module. The deviceId is also written into the store, enabling cross-session tracking.
Data exfiltration / external network request
NPS-3D5FB946769F
The code initializes the Coinbase ClientAnalytics (CCA) telemetry SDK and sends a device identifier plus usage telemetry to the hardcoded external endpoint https://cca-lite.coinbase.com with an embedded Amplitude API key. It uses identify({ deviceId }) and generates a persistent deviceId via crypto.randomUUID() if absent, then persists it in store config. This is silent telemetry data transmission to a third-party server.
Telemetry/Data collection
NPS-6C9564CA0125
The logEvent function silently sends event data to a global window.ClientAnalytics object when present in the browser. It attaches appName, appOrigin (window.location.origin), SDK name and version to every event. If ClientAnalytics is provided by a third party, this constitutes telemetry/data exfiltration from the host application without explicit user consent.
No input sanitization on telemetry payload
NPS-E0EA1CC41BB2
The spread of the caller-supplied event object with no filtering or size limits may leak arbitrary application state (PII, tokens, internal data) into the analytics sink. There is no audit of what fields call sites pass.
Data exfiltration / telemetry collection
NPS-BA931E5EA3EF
The bundled script (Coinbase ClientAnalytics SDK) collects extensive user/device telemetry—device memory, hardware concurrency, network information (effectiveType, RTT, downlink, saveData), user agent/OS/browser fingerprint, storage estimates, session data, referrer/UTM parameters, and user IDs—and transmits it to Coinbase-controlled analytics endpoints (e.g., analytics-service-dev.cbhq.net, as.coinbase.com). This is intentional analytics behavior but represents a privacy-sensitive data collection pattern that should be scrutinized in a third-party dependency.
Environment / user data harvesting via IndexedDB and cookies
NPS-219B0A3651F1
The code reads/sets persistent data in IndexedDB ('keyval-store'), reads referrer and UTM/campaign params from the URL, and references an auth cookie ('logged_in') plus a JWT ('authorization' header). This is a broad harvesting of user-identifying and session data, though it targets the SDK's own storage rather than credential files like ~/.npmrc or ~/.ssh.
Suspicious network requests (sendBeacon / XHR / fetch to external endpoints)
NPS-F538FC6E2BE7
Telemetry is exfiltrated via navigator.sendBeacon, XMLHttpRequest, and fetch() to configurable API endpoints, with checksum of the payload signed using the amplitude API key. Endpoint is hardcoded to Coinbase domains but configurable via setConfig, meaning any consumer of this package could redirect telemetry.
Minified/obfuscated content in embedded string
NPS-1921212D3DB4
The exported TELEMETRY_SCRIPT_CONTENT is a large minified JavaScript blob auto-generated by compile-assets.cjs. While this is a legitimate build artifact, embedding minified third-party code as a string reduces auditability and is a common vector for supply-chain attacks if the generator is compromised.
Telemetry data collection
NPS-CB4815CD30FE
The SDK loads a telemetry script via loadTelemetryScript() when telemetry preference is not disabled. This script may collect usage data and send it to external servers. While telemetry is common, it represents potential data exfiltration that users should be aware of.
External script loading
NPS-6E387F36DC8B
loadTelemetryScript() dynamically loads an external telemetry script at runtime. The implementation of this function is not shown, so the exact source and data collected cannot be verified from this file alone.
Injected provider detection logic
NPS-524C552BE0F8
The code inspects window.top.ethereum and window.ethereum to detect a specific injected provider referenced by 'isCoinbaseBrowser'. While the identifier itself is benign, this pattern is commonly associated with wallet-related code and should be reviewed in context of the wider package to ensure it is not being used to intercept or manipulate wallet interactions.
Potential wallet interaction surface
NPS-5B1595656213
Returning an injected Ethereum provider object grants callers the ability to interact with the user's wallet. If this module is consumed by malicious code elsewhere in the package, it could facilitate wallet draining or unauthorized transactions. The file itself does not perform dangerous operations, but its purpose is security-sensitive.
Hardcoded API Key
NPS-4DFEEFB8C225
A hardcoded API key 'S-fOd2n2Oi4fl4e1Crm83XeDXZ7tkg8O' is embedded directly in the source code within the Coinbase Developer Platform bundler URLs. This is a credential exposure risk: the key could be extracted from the package and abused to consume the developer's API quota, incur costs, or be used to probe the RPC endpoint. While not immediate remote code execution, it is a significant security hygiene issue and represents leaked credentials in a public package.
External dependencies with undisclosed implementation
NPS-4DBEE550E82B
The file imports several internal modules (translatePaymentToSendCalls, executePaymentWithSDK, normalizeAddress, validateStringAmount) whose implementations are not shown. These are the actual components that construct the transaction (potentially including an arbitrary 'to' address) and submit it. Malicious logic (e.g., address rewriting or silent data exfiltration) could reside in those imported files and would not be visible from this snippet alone.
Payer information callback / optional data collection
NPS-A6BEC3F24273
The 'payerInfo' option and 'executePaymentWithSDK' return 'payerInfoResponses', implying user data may be collected and transmitted. Combined with 'walletUrl' (a configurable URL), this could be used to send sensitive user information to an attacker-controlled endpoint if the passed-in walletUrl is malicious or if downstream SDK code includes exfiltration.
Telemetry data collection
NPS-847080082B71
The code collects and logs telemetry data (subscription details, addresses, amounts, error messages, correlation IDs) via imported logging functions from '../../core/telemetry/events/subscription.js'. While telemetry can be benign, it represents data exfiltration risk if the telemetry implementation sends data to external servers without user awareness. The actual destinations are unknown from this file alone.
Recipient address injection / unauthorized token transfer
NPS-200BDD9530DD
The recipient parameter is passed directly into an ERC20 transfer(to, amount) call without any validation, allowlisting, or access control. A caller (or any code path controlling this parameter) can specify an arbitrary address, causing the user's spender account to transfer the spent tokens to an attacker-chosen destination. This is a meaningful authorization/asset-routing risk in a wallet/spend-permission context, even though the function itself is a library helper.
Key storage in browser storage
NPS-91E8FFA4340B
The code stores private key material (keypair object) in browser storage via createStorage. This is a standard pattern for WebCrypto non-extractable keys, but still represents a security-sensitive operation because the Storage API is accessible to other scripts on the same origin.
Local persistence of sensitive data
NPS-50B85570ED51
The createStorage function stores arbitrary key-value pairs in IndexedDB without encryption. If callers use it to persist cryptographic keys or other secrets, they will be stored in plaintext and remain accessible to any script running on the same origin (including third-party scripts and XSS).
Cryptographic key handling
NPS-CC26BBF55862
The code handles cryptographic keys (importing/exporting public keys, managing shared secrets) for encrypted communication with a popup. This is legitimate for a wallet signer, but any compromise of the key manager or shared secret could lead to signing unauthorized transactions. No key exfiltration to external servers was observed.
ECDSA/WebAuthn key handling
NPS-54ED99753ABE
initSubAccountConfig retrieves an owner account via getCryptoKeyAccount() and uses its address or publicKey to create sub-account keys. This code touches cryptographic key material and sub-account delegation, which is sensitive functionality in a wallet context.
Paymaster URL injection
NPS-771C4B0C13FD
createWalletSendCallsRequest reads paymasterUrls from config and injects a paymasterService capability with an externally configured URL into wallet_sendCalls requests. If the config source is untrusted, this could route transactions through an attacker-controlled paymaster.
Sensitive data persistence in localStorage
NPS-92585BFAEEC5
The store persists 'keys', 'account', 'subAccount', and 'spendPermissions' to localStorage via zustand's persist middleware. These fields likely contain cryptographic key material, account credentials, and permission data. Storing such sensitive data in localStorage exposes it to any XSS vulnerability on the same origin, and it persists indefinitely on disk. The 'keys' slice in particular stores an object of key/value pairs that in an account SDK context typically hold private keys or signing material.
Data exfiltration via URL parameters
NPS-6643F1F9BFC6
The serializeError function includes the full error message (serialized.message) and error code as query parameters in a docUrl pointing to an external domain (docs.cloud.coinbase.com). If this error is later logged, sent to analytics, or shared, sensitive information from the error message could leak to third parties. While likely benign (intended for documentation links), it constitutes an outbound data flow containing potentially sensitive error details.
Error message leakage in URL
NPS-8B20027BBEF3
Setting the serialized error message into a URL query parameter (docUrl.searchParams.set('message', serialized.message)) can expose arbitrary error content (which may include secrets, paths, or user data) in logs, referrers, or browser history. This is a privacy/security concern despite no direct malicious intent.
External data transmission
NPS-F8547117D4D5
All three functions transmit subscription metadata (correlationId, amount, permissionHash, errorMessage, testnet flag, periods) to an external analytics endpoint via logEvent. This is expected telemetry behavior but constitutes outbound data flow that should be reviewed for what fields are permitted.
Potential PII/secrets in error telemetry
NPS-7115A5A233AD
logSubscriptionError forwards data.errorMessage verbatim to logEvent. Error messages frequently contain sensitive values (keys, hashes, tokens, URLs) and could exfiltrate them to the analytics endpoint without sanitization.
Hardcoded credential / secret
NPS-78BAD533D890
A hardcoded Amplitude API key ('c66737ad47ec354ced777935b0af822e') is embedded directly in the source. Even public telemetry keys should not be hardcoded, as it enables unauthorized telemetry injection or abuse.
Global namespace pollution / external dependency injection
NPS-AE06F93ABF24
The code trusts any object named window.ClientAnalytics and calls logEvent/identify on it. This creates a hook point where external scripts (browser extensions, compromised dependencies, or injected code) could intercept analytics data or trigger side effects. No allowlist or integrity check exists.
Dynamic module loading with computed input
NPS-C8C9CE2655ED
The bundle uses a custom webpack-style module loader with runtime-computed requires (n(2), n(353), n(762), etc.) and dynamic export assignment, plus UMD-style fallback attaching ClientAnalytics to the global object. This is normal bundler output but makes auditing harder and could mask malicious payloads in minified form.
Persistent configuration storage
NPS-33BBE27F56F6
The code stores configuration (including metadata, preferences, and paymaster URLs) in a persistent store (store.config.set + store.persist.rehydrate). This persists user-supplied configuration across sessions, which is expected but worth noting for the privacy-sensitive nature of crypto SDK data.
Injected provider usage
NPS-6B90130E7FC5
getInjectedProvider() may return a browser-injected provider (e.g., window.ethereum). This allows third-party code to be used as the provider, which is standard for wallet SDKs but means the actual signing/request handling is outsourced to whatever provider is injected.
Cross-origin window access
NPS-0F8CEC09F780
The function accesses window.top, which may throw a SecurityError when the script runs inside a cross-origin iframe. This can cause runtime exceptions and could be used to probe or infer frame hierarchy relationships. It is not inherently malicious but is a fragile and potentially risky pattern.
Minor Information Disclosure via Error Messages
NPS-5DEBFD5BBD43
Error messages leak internal details such as the sender wallet address and details of all USDC transfers found (Found ${usdcTransfers.length} USDC transfer(s)..., transfer details including recipient addresses). While not exploitable on its own, verbose error content could aid reconnaissance in multi-tenant or sensitive contexts.
Telemetry with user-controlled payloads
NPS-74AD7F7399D1
Telemetry calls (logPaymentStarted/logPaymentCompleted/logPaymentError) pass the payment amount, address, and error messages. While these appear to be local event loggers, if the underlying telemetry module forwards events to a remote server, it constitutes data exfiltration of financial details. The implementation of '../../core/telemetry/events/payment.js' is not visible.
Wallet interaction via custom RPC method
NPS-94F69D62A7DB
Uses a non-standard 'wallet_sign' method through provider.request() with mutableData fields, requesting signatures for spend permissions. While this appears to be a legitimate subscription flow using EIP-712 typed data, the custom method and placeholder address replacement mechanism could be abused if the wallet implementation is compromised or if the signing flow is manipulated.
External dependency usage
NPS-07F023475C69
Imports from multiple internal modules (telemetry, spend-permission utilities, SDK manager) whose implementations are not visible in this file. These could contain malicious code. The telemetry module in particular could perform network requests.
Client-side allowance trust / TOCTOU
NPS-4BD39C47D7EC
The function relies on getPermissionStatus (likely an RPC/offchain read) to decide whether to include approveWithSignature, then constructs spend and transfer calls locally. There is no cryptographic binding preventing a race between status check and execution, but this is inherent to the approval flow rather than a direct malicious pattern.
Missing recipient address validation
NPS-11E7C1AB717C
The optional recipient is used as a raw address argument to encodeFunctionData for ERC20 transfer without checksum validation, zero-address check, or confirmation that it relates to the intended permission flow. Malformed or malicious addresses supplied by callers could misroute funds.
Non-extractable key generation
NPS-9A2363641D11
Keys are generated with extractable:false, which is a positive security control. No exfiltration, obfuscation, dynamic execution, network calls, or process spawning was detected. The only external interactions are imports from trusted libraries (ox, viem) and local storage operations.
Implicit credential origin binding
NPS-996B34D4A546
Signing payloads are bound to the hardcoded origin 'https://keys.coinbase.com'. This is intentional WebAuthn origin binding, but it means signatures are only valid for that origin and could be leveraged in phishing scenarios if the user is misled about the relying party.
Missing error handling / silent failure
NPS-D81064722A49
getItem, setItem, and removeItem do not handle errors from idb-keyval. In a key-management context, a failed write or delete could leave stale or inconsistent key material, but no error is surfaced to the caller.
Unvalidated storage scope and name
NPS-8EB46AAE082E
The scope and name arguments are passed directly to createStore without validation, allowing callers to choose arbitrary IndexedDB database/object store names. This could be abused to interfere with other components or to persist data in unexpected locations.
Cryptographic Key Storage
NPS-98D0A1BB8247
The class stores cryptographic keys (private and public) in a local store. While this is expected for key management, private keys stored in plaintext within the application store could be exposed if the store is compromised or if storage is not properly secured. This is a common pattern in wallet/SDK implementations and does not itself indicate malicious behavior.
Network communication with external RPC endpoints
NPS-DB30CF6CC523
The code fetches data from external RPC URLs (e.g., CB_WALLET_RPC_URL and this.chain.rpcUrl) via fetchRPCRequest. While this is expected for a wallet signer (communicating with blockchain RPC nodes), the constant CB_WALLET_RPC_URL is imported from core/constants.js and its value is not visible here; if it pointed to an attacker-controlled endpoint, it could exfiltrate data. This warrants inspection of that constant.
Access to window.location.origin
NPS-0753F207A044
The code reads window.location.origin to build a data suffix for attribution. This is a benign use for dapp attribution but demonstrates access to browser environment data.
Dynamic code execution (none)
NPS-EBFF3F76C2FA
No eval, new Function, or dynamic import from untrusted input is present. Module imports are static.
Process spawning or shell commands (none)
NPS-64897B45642C
No child_process or shell command execution is present.
Credential/secret harvesting (none)
NPS-A883404A6872
No access to .npmrc, ~/.ssh, ~/.aws, or other credential files is present.
Telemetry/data collection
NPS-85EFBC58AE08
Functions logDialogActionClicked, logDialogDismissed, and logDialogShown are imported from telemetry modules and invoked when displaying dialogs. This suggests user interaction data (dialog context, action) is being recorded/transmitted. While common in legitimate analytics, it constitutes data collection from the user environment.
External address/spender handling
NPS-F0666E901C2E
assertFetchPermissionsRequest and fillMissingParamsForFetchPermissions construct spend permission requests using a spender address from the store. This is legitimate wallet functionality but represents sensitive approval-granting logic that should be carefully validated.
Broad key-value storage API without validation
NPS-C93DE96FDA18
The exported 'keys.set(key, value)' accepts arbitrary string keys and values and stores them directly into the persisted store without any validation, allow-list, or encryption. A caller (or any code with access to the imported module) could write arbitrary data into localStorage under the 'base-acc-sdk.store' namespace, and the same accessor could be used to read back whatever was stored.
Popup-based redirect / window.open usage
NPS-AA8567B3A615
The openPopup function uses window.open with a computed popupId and URL that receives appended query parameters. While common for OAuth/wallet flows, an attacker controlling the URL argument could potentially craft a malicious popup if the caller does not validate the URL. This is a design risk rather than an active malicious pattern.
Sensitive data leakage via URL parameters
NPS-61011E332E61
The appendAppInfoQueryParams function appends origin (window.location.origin) and Cross-Origin-Opener-Policy (coop) values to the popup URL. While this is used to pass SDK metadata (name, version) for compatibility/diagnostics, it also leaks the dapp's origin and COOP state to the URL target. If the URL is later logged, cached, or redirected, this information could be exposed. However, the URL is used with window.open in the same context and the values are expected for wallet SDK operations, so this is a low-severity information disclosure rather than exfiltration.
Telemetry collection
NPS-6B0BB655FF47
The code calls logDialogShown and logDialogActionClicked to send telemetry events about dialog interactions. These functions are imported from the package's own telemetry module, which may transmit user interaction data to a remote endpoint. While standard for SDK analytics, without inspecting the telemetry implementation, this could be a privacy concern.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/core/error/serialize.js | medium | The code appears to be a benign error serialization utility with no malicious patterns, but it embeds potentially sensitive error messages into an external documentation URL, posing a minor information leakage risk. |
| dist/core/telemetry/events/subscription.js | medium | No malicious code patterns (exfiltration of credentials, obfuscation, shelling out, or install-time execution) were found, but the module deliberately routes sensitive-looking values such as permissionHash and raw error messages into third-party telemetry events. |
| dist/core/telemetry/initCCA.js | medium | The file silently injects and executes an inlined telemetry script that sends device-identifying telemetry and a hardcoded API key to an external Coinbase/Amplitude endpoint without consent, warranting warning-level scrutiny despite the apparent legitimate SDK origin. |
| dist/core/telemetry/logEvent.js | medium | No overt malicious code, but the module silently forwards application metadata (name, origin, SDK version) and caller-supplied event payloads to a global ClientAnalytics sink, creating a telemetry data-exfiltration surface and a supply-chain hook point that warrants review of how ClientAnalytics is populated. |
| dist/core/telemetry/telemetry-content.js | medium | This is a bundled Coinbase analytics/telemetry SDK that intentionally collects extensive user, device, session and network data and transmits it to Coinbase endpoints; it is not overtly malicious (no credential theft, shells, crypto miners, or eval), but its aggressive telemetry, persistent storage, and embedded minified payload warrant caution as a third-party dependency. |
| dist/interface/builder/core/createBaseAccountSDK.js | medium | The file contains no obvious malicious patterns such as credential harvesting, reverse shells, or obfuscated code, but it does perform telemetry loading and external script execution, which warrants user awareness regarding data collection. |
| dist/interface/builder/core/getInjectedProvider.js | medium | This file contains no direct malicious behavior such as exfiltration, code execution, or persistence, but it accesses cross-origin window properties and returns an injected Ethereum provider, which warrants caution due to wallet-related security implications. |
| dist/interface/payment/getPaymentStatus.js | medium | The code is a legitimate payment status checker, but it contains a hardcoded Coinbase API key in the bundler URL, which is a credential exposure risk, and some verbose error messages that leak transaction details. |
| dist/interface/payment/pay.js | medium | pay.js itself contains no obfuscation, shell execution, or credential harvesting, but its behavior depends entirely on unshown imported modules for transaction construction, wallet interaction, and telemetry, which are the likely locations of any malicious logic. |
| dist/interface/payment/subscribe.js | medium | The code appears to implement a legitimate cryptocurrency subscription creation flow using spend permissions on Base network, but includes telemetry logging of sensitive subscription data and relies on internal modules whose behavior cannot be verified from this file alone. |
| dist/interface/public-utilities/spend-permission/methods/prepareSpendCallData.js | medium | No overt malicious patterns (exfiltration, backdoors, shell execution, obfuscation) are present, but the unvalidated recipient parameter permits arbitrary ERC20 token transfers and warrants a warning. |
| dist/kms/crypto-key/index.js | medium | No malicious patterns detected; the module only manages locally stored WebCrypto P-256 keypairs and signs messages for a fixed Coinbase WebAuthn origin, with minor security considerations around browser storage of private key material. |
| dist/kms/crypto-key/storage.js | medium | The code is a simple IndexedDB wrapper with no exfiltration, code execution, or credential harvesting, but it stores key-value data in plaintext and lacks validation and error handling, which is a moderate concern for a crypto-key storage module. |
| dist/sign/base-account/Signer.js | medium | The code appears to be a legitimate Ethereum wallet signer component with standard RPC communication and cryptographic key handling; no obvious malicious patterns were detected, but external RPC endpoint constants (CB_WALLET_RPC_URL) should be verified as trusted. |
| dist/sign/base-account/utils.js | medium | No overt malicious patterns (exfiltration, shell execution, obfuscation, credential harvesting) were found; the file contains legitimate wallet SDK utilities with telemetry dialogs and paymaster URL injection worth monitoring. |
| dist/store/store.js | medium | The SDK store persists sensitive account/key/permission data to localStorage and exposes an unrestricted key-value setter, creating credential-exposure risk via XSS or same-origin scripts, but no active exfiltration, code execution, or other malicious patterns were found. |
| dist/util/web.js | medium | The file appears to implement legitimate popup and dialog handling for a wallet SDK (Base Account), with no malicious patterns such as exfiltration, credential harvesting, or code execution detected, though it does append origin/COOP metadata to popup URLs and emits telemetry. |
| dist/browser-entry.js | safe | No malicious patterns detected |
| dist/core/communicator/Communicator.js | safe | No malicious patterns detected; the code is a standard popup communication handler with proper origin validation. |
| dist/core/constants.js | safe | No malicious patterns detected |
| dist/core/error/constants.js | safe | No malicious patterns detected |
| dist/core/error/errors.js | safe | No malicious patterns detected; the code only defines Ethereum JSON-RPC error classes and validation helpers with no exfiltration, obfuscation, network, filesystem, or process activity. |
| dist/core/error/utils.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/core/message/ConfigMessage.js | safe | No malicious patterns detected; the file is an empty module export with only a source map reference. |
| dist/core/message/Message.js | safe | The file contains only an empty export statement and a source map reference, with no executable or malicious code. |
Show 80 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/core/message/RPCMessage.js | safe | No malicious patterns detected |
| dist/core/message/RPCRequest.js | safe | No malicious patterns detected |
| dist/core/message/RPCResponse.js | safe | No malicious patterns detected |
| dist/core/provider/interface.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/core/rpc/coinbase_fetchPermission.js | safe | The file contains only an empty export statement and a source map reference, with no executable or suspicious code. |
| dist/core/rpc/coinbase_fetchSpendPermissions.js | safe | No malicious patterns detected |
| dist/core/rpc/wallet_addSubAccount.js | safe | No malicious patterns detected |
| dist/core/rpc/wallet_connect.js | safe | No malicious patterns detected |
| dist/core/rpc/wallet_getSubAccount.js | safe | The file contains only an empty export and a source map reference, with no executable code or malicious patterns. |
| dist/core/rpc/wallet_prepareCalls.js | safe | No malicious patterns detected |
| dist/core/rpc/wallet_sendPreparedCalls.js | safe | This file is an empty ES module re-export with only a source map comment, containing no executable or suspicious code. |
| dist/core/telemetry/events/communicator.js | safe | The file only logs telemetry events via an internal logEvent helper and contains no malicious patterns, external network calls, credential harvesting, or dynamic execution. |
| dist/core/telemetry/events/dialog.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/core/telemetry/events/payment.js | safe | No malicious patterns detected; the file contains only telemetry event logging functions with no data exfiltration, credential harvesting, obfuscation, or other suspicious behavior. |
| dist/core/telemetry/events/provider.js | safe | No malicious patterns detected; the file only contains telemetry logging functions that call an internal logEvent utility with request metadata. |
| dist/core/telemetry/events/scw-signer.js | safe | No malicious patterns detected; the module only logs analytics events with internal state, without exfiltration, obfuscation, or credential access. |
| dist/core/telemetry/events/scw-sub-account.js | safe | No malicious patterns detected; the file only contains telemetry logging functions that use a local store and logEvent utility. |
| dist/core/telemetry/events/spend-permission.js | safe | No malicious patterns detected; the file only logs telemetry events through an internal logEvent wrapper with no external calls, credential access, or dynamic execution. |
| dist/core/telemetry/utils.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/core/type/index.js | safe | No malicious patterns detected; the code only defines simple type/utility functions with no I/O, network, process, or dynamic execution behavior. |
| dist/core/type/util.js | safe | No malicious patterns detected; the code is a standard Coinbase utility module for hex/buffer/BigInt conversions and validation with no network, filesystem, process, or obfuscated behavior. |
| dist/core/username/getDisplayableUsername.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/index.js | safe | No malicious patterns detected; the file only contains standard ES module re-exports. |
| dist/index.node.js | safe | No malicious patterns detected |
| dist/interface/builder/core/BaseAccountProvider.js | safe | The analyzed file contains standard wallet provider logic with no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, crypto mining, backdoors, or suspicious network/file/process operations. |
| dist/interface/payment/base.browser.js | safe | No malicious patterns detected |
| dist/interface/payment/base.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/interface/payment/base.node.js | safe | No malicious patterns detected |
| dist/interface/payment/charge.js | safe | The code appears to be a legitimate payment charge function using the Coinbase CDP SDK, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or unauthorized system access. |
| dist/interface/payment/constants.js | safe | No malicious patterns detected; the file only contains static payment token configuration, chain IDs, and an ERC20 ABI definition. |
| dist/interface/payment/getOrCreateSubscriptionOwnerWallet.js | safe | No malicious patterns detected; code uses the official @coinbase/cdp-sdk to create/retrieve wallet accounts with provided or environment-based credentials, which is expected behavior for this module. |
| dist/interface/payment/getSubscriptionStatus.js | safe | No malicious patterns detected |
| dist/interface/payment/index.js | safe | No malicious patterns detected; the file only re-exports browser-safe payment-related modules without any obfuscation, network calls, credential access, or process execution. |
| dist/interface/payment/index.node.js | safe | No malicious patterns detected; the file only re-exports payment-related modules without any suspicious behavior. |
| dist/interface/payment/prepareCharge.js | safe | No malicious patterns detected; the code performs legitimate subscription charge preparation with input validation and no external data exfiltration, dynamic execution, or system commands. |
| dist/interface/payment/types.js | safe | No malicious patterns detected |
| dist/interface/payment/utils/sdkManager.js | safe | No malicious patterns detected; the code is a straightforward SDK wrapper for payment execution without exfiltration, obfuscation, or process/network abuse. |
| dist/interface/payment/utils/translatePayment.js | safe | No malicious patterns detected |
| dist/interface/payment/utils/validation.js | safe | No malicious patterns detected |
| dist/interface/public-utilities/spend-permission/index.js | safe | The file is a simple barrel export module with no executable code or malicious patterns. |
| dist/interface/public-utilities/spend-permission/index.node.js | safe | No malicious patterns detected |
| dist/interface/public-utilities/spend-permission/methods/fetchPermission.js | safe | No malicious patterns detected |
| dist/interface/public-utilities/spend-permission/methods/fetchPermissions.js | safe | No malicious patterns detected; the code is a straightforward RPC-based spend-permission fetcher with no exfiltration, credential harvesting, dynamic execution, or other red flags. |
| dist/interface/public-utilities/spend-permission/methods/getHash.js | safe | No malicious patterns detected |
| dist/interface/public-utilities/spend-permission/methods/getPermissionStatus.js | safe | No malicious patterns detected; the file is a legitimate blockchain permission status helper without data exfiltration, credential harvesting, obfuscation, or dynamic execution. |
| dist/interface/public-utilities/spend-permission/methods/prepareRevokeCallData.js | safe | The code is a straightforward helper for encoding spend permission revocation call data and contains no malicious patterns. |
| dist/interface/public-utilities/spend-permission/methods/requestRevoke.js | safe | No malicious patterns detected; the code performs a standard blockchain wallet call to revoke a spend permission with no data exfiltration, credential harvesting, or dynamic execution. |
| dist/interface/public-utilities/spend-permission/methods/requestSpendPermission.js | safe | The code is a legitimate EIP-712 spend permission request helper that uses the provided wallet provider to sign typed data and computes a local hash; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or process spawning are present. |
| dist/interface/public-utilities/spend-permission/utils.js | safe | No malicious patterns detected; the code is a straightforward utility for creating and manipulating spend permission typed data with no signs of exfiltration, obfuscation, or dynamic execution. |
| dist/interface/public-utilities/spend-permission/utils.node.js | safe | No malicious patterns detected; the code is a straightforward viem client helper with no exfiltration, credential harvesting, or dynamic execution. |
| dist/interface/public-utilities/spend-permission/withTelemetry.js | safe | No malicious patterns detected; the code is a standard telemetry wrapper that respects user preferences and only logs function execution metadata. |
| dist/sign/base-account/SCWKeyManager.js | safe | No malicious patterns detected; the code implements standard cryptographic key management for a smart contract wallet without exfiltration, obfuscation, or suspicious behaviors. |
| dist/sign/base-account/utils/constants.js | safe | This file only exports two hardcoded Ethereum contract addresses and several static ABI definitions with no executable, obfuscated, network, filesystem, or process-spawning code. |
| dist/sign/base-account/utils/createSmartAccount.js | safe | No malicious patterns detected; the code is a legitimate smart account implementation using viem for Ethereum transaction signing. |
| dist/sign/base-account/utils/createSubAccountSigner.js | safe | No malicious patterns detected |
| dist/sign/base-account/utils/findOwnerIndex.js | safe | No malicious patterns detected; the code is a legitimate utility for finding an owner index on a smart contract using viem. |
| dist/sign/base-account/utils/handleAddSubAccountOwner.js | safe | No malicious patterns detected; the code performs wallet sub-account owner management operations without exfiltration, obfuscation, or credential harvesting. |
| dist/sign/base-account/utils/handleInsufficientBalance.js | safe | No malicious patterns detected; the file contains straightforward error-handling logic with internal imports and no exfiltration, obfuscation, or dynamic execution. |
| dist/sign/base-account/utils/presentAddOwnerDialog.js | safe | No malicious patterns detected |
| dist/sign/base-account/utils/routeThroughGlobalAccount.js | safe | No malicious patterns detected; the file contains legitimate wallet routing logic using viem and internal utilities without any exfiltration, obfuscation, or other security concerns. |
| dist/store/chain-clients/store.js | safe | The file simply creates a Zustand vanilla store with an empty object and contains no malicious patterns. |
| dist/store/chain-clients/utils.js | safe | No malicious patterns detected; the code uses viem to create RPC clients for supported chains without data exfiltration, credential harvesting, obfuscation, or other red flags. |
| dist/store/correlation-ids/store.js | safe | No malicious patterns detected; the code is a simple Zustand store for managing correlation IDs with no external calls, dynamic execution, or file/process access. |
| dist/ui/Dialog/Dialog-css.js | safe | The file contains only static CSS-in-JS style definitions for a dialog component with no executable logic, network calls, filesystem access, or malicious patterns. |
| dist/ui/Dialog/Dialog.js | safe | This is a standard UI Dialog component for the Coinbase Base Account SDK with no malicious patterns, external data transmission, or suspicious behavior detected. |
| dist/ui/Dialog/index.js | safe | No malicious patterns detected; the code only initializes a dialog UI component and injects font styles. |
| dist/ui/assets/BaseLogo.js | safe | No malicious patterns detected |
| dist/ui/assets/BasePayLogo.js | safe | No malicious patterns detected; the file contains only static SVG logo rendering components with no network, filesystem, process, or dynamic execution behavior. |
| dist/ui/assets/colors.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/ui/assets/fontFaceCSS.js | safe | No malicious patterns detected; the file only exports a static CSS string containing an embedded base64 font. |
| dist/ui/assets/index.js | safe | No malicious patterns detected |
| dist/ui/assets/injectFontStyle.js | safe | No malicious patterns detected |
| dist/util/assertPresence.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/util/assertSubAccount.js | safe | No malicious patterns detected; the file only performs input validation for sub-account fields using trusted viem utilities. |
| dist/util/checkCrossOriginOpenerPolicy.js | safe | No malicious patterns detected; the code legitimately checks the Cross-Origin-Opener-Policy header of the current origin without exfiltration, credential harvesting, obfuscation, or unexpected network/process activity. |
| dist/util/cipher.js | safe | No malicious patterns detected |
| dist/util/encoding.js | safe | No malicious patterns detected; the code is a benign WebAuthn encoding utility with standard cryptographic conversions. |
| dist/util/get.js | safe | The file contains a simple utility function for safe property access on objects with no malicious patterns, external calls, or dynamic code execution. |
| dist/util/provider.js | safe | No malicious patterns detected in the provider utility code; it performs standard RPC request validation and dispatching. |
| dist/util/validatePreferences.js | safe | Cleared by Jev triage; no further analysis needed |
Scanned versions of @base-org/account
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 2.4.0 | Needs review | 105 | Oct 4, 2026 |
Frequently asked questions
Is @base-org/account safe to use?
No confirmed malware was found in @base-org/account@2.4.0, but the review flagged 25 medium, 32 low severity findings for risky patterns worth checking before you rely on it.
Does @base-org/account contain malware?
No malware was identified in @base-org/account@2.4.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @base-org/account checked?
Togoder Security downloaded the published npm package and had an AI model read its 105 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @base-org/account together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @base-org/account@2.4.0, cost nothing.