Togoder security

npm package security report

@base-org/account@2.4.0 security report

Risky patterns found that deserve a look.

Needs review Version 2.4.0 Files reviewed 105 Size 464.3 KB Scanned

Summary

Togoder Security scanned the npm package @base-org/account@2.4.0 on Oct 4, 2026. An AI review of 105 source files produced 25 medium, 32 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
25
medium
32
low

Findings 57

medium

Sensitive data logged to telemetry

NPS-348172CCC95A

logSubscriptionCompleted writes data.permissionHash into a 'status' telemetry field. If permissionHash is a cryptographic secret or authorization token, this would transmit sensitive material to an analytics backend. The intentional comment 'Using status field to store permission hash' indicates this is deliberate.

dist/core/telemetry/events/subscription.js:31
medium

Dynamic code execution

NPS-8B86C4FB851F

The script content from TELEMETRY_SCRIPT_CONTENT is injected into a dynamically created <script> element via script.textContent, effectively executing arbitrary inlined JavaScript in the page context. While the content is imported from a local module, this pattern is a vector for hidden code and makes the executed payload invisible to static analysis of this file alone.

dist/core/telemetry/initCCA.js:17
medium

Telemetry performed without consent / at import/run time

NPS-D0221AD2D77E

loadTelemetryScript is exported and executed by consumers, and initCCA runs immediately when invoked, initializing tracking and identifying the user without any user consent check or opt-out mechanism in this module. The deviceId is also written into the store, enabling cross-session tracking.

dist/core/telemetry/initCCA.js:30
medium

Data exfiltration / external network request

NPS-3D5FB946769F

The code initializes the Coinbase ClientAnalytics (CCA) telemetry SDK and sends a device identifier plus usage telemetry to the hardcoded external endpoint https://cca-lite.coinbase.com with an embedded Amplitude API key. It uses identify({ deviceId }) and generates a persistent deviceId via crypto.randomUUID() if absent, then persists it in store config. This is silent telemetry data transmission to a third-party server.

dist/core/telemetry/initCCA.js:32
medium

Telemetry/Data collection

NPS-6C9564CA0125

The logEvent function silently sends event data to a global window.ClientAnalytics object when present in the browser. It attaches appName, appOrigin (window.location.origin), SDK name and version to every event. If ClientAnalytics is provided by a third party, this constitutes telemetry/data exfiltration from the host application without explicit user consent.

dist/core/telemetry/logEvent.js:45
medium

No input sanitization on telemetry payload

NPS-E0EA1CC41BB2

The spread of the caller-supplied event object with no filtering or size limits may leak arbitrary application state (PII, tokens, internal data) into the analytics sink. There is no audit of what fields call sites pass.

dist/core/telemetry/logEvent.js:47
medium

Data exfiltration / telemetry collection

NPS-BA931E5EA3EF

The bundled script (Coinbase ClientAnalytics SDK) collects extensive user/device telemetry—device memory, hardware concurrency, network information (effectiveType, RTT, downlink, saveData), user agent/OS/browser fingerprint, storage estimates, session data, referrer/UTM parameters, and user IDs—and transmits it to Coinbase-controlled analytics endpoints (e.g., analytics-service-dev.cbhq.net, as.coinbase.com). This is intentional analytics behavior but represents a privacy-sensitive data collection pattern that should be scrutinized in a third-party dependency.

dist/core/telemetry/telemetry-content.js
medium

Environment / user data harvesting via IndexedDB and cookies

NPS-219B0A3651F1

The code reads/sets persistent data in IndexedDB ('keyval-store'), reads referrer and UTM/campaign params from the URL, and references an auth cookie ('logged_in') plus a JWT ('authorization' header). This is a broad harvesting of user-identifying and session data, though it targets the SDK's own storage rather than credential files like ~/.npmrc or ~/.ssh.

dist/core/telemetry/telemetry-content.js
medium

Suspicious network requests (sendBeacon / XHR / fetch to external endpoints)

NPS-F538FC6E2BE7

Telemetry is exfiltrated via navigator.sendBeacon, XMLHttpRequest, and fetch() to configurable API endpoints, with checksum of the payload signed using the amplitude API key. Endpoint is hardcoded to Coinbase domains but configurable via setConfig, meaning any consumer of this package could redirect telemetry.

dist/core/telemetry/telemetry-content.js
medium

Minified/obfuscated content in embedded string

NPS-1921212D3DB4

The exported TELEMETRY_SCRIPT_CONTENT is a large minified JavaScript blob auto-generated by compile-assets.cjs. While this is a legitimate build artifact, embedding minified third-party code as a string reduces auditability and is a common vector for supply-chain attacks if the generator is compromised.

dist/core/telemetry/telemetry-content.js:4
medium

Telemetry data collection

NPS-CB4815CD30FE

The SDK loads a telemetry script via loadTelemetryScript() when telemetry preference is not disabled. This script may collect usage data and send it to external servers. While telemetry is common, it represents potential data exfiltration that users should be aware of.

dist/interface/builder/core/createBaseAccountSDK.js:44
medium

External script loading

NPS-6E387F36DC8B

loadTelemetryScript() dynamically loads an external telemetry script at runtime. The implementation of this function is not shown, so the exact source and data collected cannot be verified from this file alone.

dist/interface/builder/core/createBaseAccountSDK.js:44
medium

Injected provider detection logic

NPS-524C552BE0F8

The code inspects window.top.ethereum and window.ethereum to detect a specific injected provider referenced by 'isCoinbaseBrowser'. While the identifier itself is benign, this pattern is commonly associated with wallet-related code and should be reviewed in context of the wider package to ensure it is not being used to intercept or manipulate wallet interactions.

dist/interface/builder/core/getInjectedProvider.js:3
medium

Potential wallet interaction surface

NPS-5B1595656213

Returning an injected Ethereum provider object grants callers the ability to interact with the user's wallet. If this module is consumed by malicious code elsewhere in the package, it could facilitate wallet draining or unauthorized transactions. The file itself does not perform dangerous operations, but its purpose is security-sensitive.

dist/interface/builder/core/getInjectedProvider.js:5
medium

Hardcoded API Key

NPS-4DFEEFB8C225

A hardcoded API key 'S-fOd2n2Oi4fl4e1Crm83XeDXZ7tkg8O' is embedded directly in the source code within the Coinbase Developer Platform bundler URLs. This is a credential exposure risk: the key could be extracted from the package and abused to consume the developer's API quota, incur costs, or be used to probe the RPC endpoint. While not immediate remote code execution, it is a significant security hygiene issue and represents leaked credentials in a public package.

dist/interface/payment/getPaymentStatus.js:53
medium

External dependencies with undisclosed implementation

NPS-4DBEE550E82B

The file imports several internal modules (translatePaymentToSendCalls, executePaymentWithSDK, normalizeAddress, validateStringAmount) whose implementations are not shown. These are the actual components that construct the transaction (potentially including an arbitrary 'to' address) and submit it. Malicious logic (e.g., address rewriting or silent data exfiltration) could reside in those imported files and would not be visible from this snippet alone.

dist/interface/payment/pay.js
medium

Payer information callback / optional data collection

NPS-A6BEC3F24273

The 'payerInfo' option and 'executePaymentWithSDK' return 'payerInfoResponses', implying user data may be collected and transmitted. Combined with 'walletUrl' (a configurable URL), this could be used to send sensitive user information to an attacker-controlled endpoint if the passed-in walletUrl is malicious or if downstream SDK code includes exfiltration.

dist/interface/payment/pay.js:41
medium

Telemetry data collection

NPS-847080082B71

The code collects and logs telemetry data (subscription details, addresses, amounts, error messages, correlation IDs) via imported logging functions from '../../core/telemetry/events/subscription.js'. While telemetry can be benign, it represents data exfiltration risk if the telemetry implementation sends data to external servers without user awareness. The actual destinations are unknown from this file alone.

dist/interface/payment/subscribe.js:1
medium

Recipient address injection / unauthorized token transfer

NPS-200BDD9530DD

The recipient parameter is passed directly into an ERC20 transfer(to, amount) call without any validation, allowlisting, or access control. A caller (or any code path controlling this parameter) can specify an arbitrary address, causing the user's spender account to transfer the spent tokens to an attacker-chosen destination. This is a meaningful authorization/asset-routing risk in a wallet/spend-permission context, even though the function itself is a library helper.

dist/interface/public-utilities/spend-permission/methods/prepareSpendCallData.js:157
medium

Key storage in browser storage

NPS-91E8FFA4340B

The code stores private key material (keypair object) in browser storage via createStorage. This is a standard pattern for WebCrypto non-extractable keys, but still represents a security-sensitive operation because the Storage API is accessible to other scripts on the same origin.

dist/kms/crypto-key/index.js:17
medium

Local persistence of sensitive data

NPS-50B85570ED51

The createStorage function stores arbitrary key-value pairs in IndexedDB without encryption. If callers use it to persist cryptographic keys or other secrets, they will be stored in plaintext and remain accessible to any script running on the same origin (including third-party scripts and XSS).

dist/kms/crypto-key/storage.js:3
medium

Cryptographic key handling

NPS-CC26BBF55862

The code handles cryptographic keys (importing/exporting public keys, managing shared secrets) for encrypted communication with a popup. This is legitimate for a wallet signer, but any compromise of the key manager or shared secret could lead to signing unauthorized transactions. No key exfiltration to external servers was observed.

dist/sign/base-account/Signer.js
medium

ECDSA/WebAuthn key handling

NPS-54ED99753ABE

initSubAccountConfig retrieves an owner account via getCryptoKeyAccount() and uses its address or publicKey to create sub-account keys. This code touches cryptographic key material and sub-account delegation, which is sensitive functionality in a wallet context.

dist/sign/base-account/utils.js
medium

Paymaster URL injection

NPS-771C4B0C13FD

createWalletSendCallsRequest reads paymasterUrls from config and injects a paymasterService capability with an externally configured URL into wallet_sendCalls requests. If the config source is untrusted, this could route transactions through an attacker-controlled paymaster.

dist/sign/base-account/utils.js
medium

Sensitive data persistence in localStorage

NPS-92585BFAEEC5

The store persists 'keys', 'account', 'subAccount', and 'spendPermissions' to localStorage via zustand's persist middleware. These fields likely contain cryptographic key material, account credentials, and permission data. Storing such sensitive data in localStorage exposes it to any XSS vulnerability on the same origin, and it persists indefinitely on disk. The 'keys' slice in particular stores an object of key/value pairs that in an account SDK context typically hold private keys or signing material.

dist/store/store.js:53
low

Data exfiltration via URL parameters

NPS-6643F1F9BFC6

The serializeError function includes the full error message (serialized.message) and error code as query parameters in a docUrl pointing to an external domain (docs.cloud.coinbase.com). If this error is later logged, sent to analytics, or shared, sensitive information from the error message could leak to third parties. While likely benign (intended for documentation links), it constitutes an outbound data flow containing potentially sensitive error details.

dist/core/error/serialize.js:15
low

Error message leakage in URL

NPS-8B20027BBEF3

Setting the serialized error message into a URL query parameter (docUrl.searchParams.set('message', serialized.message)) can expose arbitrary error content (which may include secrets, paths, or user data) in logs, referrers, or browser history. This is a privacy/security concern despite no direct malicious intent.

dist/core/error/serialize.js:15
low

External data transmission

NPS-F8547117D4D5

All three functions transmit subscription metadata (correlationId, amount, permissionHash, errorMessage, testnet flag, periods) to an external analytics endpoint via logEvent. This is expected telemetry behavior but constitutes outbound data flow that should be reviewed for what fields are permitted.

dist/core/telemetry/events/subscription.js
low

Potential PII/secrets in error telemetry

NPS-7115A5A233AD

logSubscriptionError forwards data.errorMessage verbatim to logEvent. Error messages frequently contain sensitive values (keys, hashes, tokens, URLs) and could exfiltrate them to the analytics endpoint without sanitization.

dist/core/telemetry/events/subscription.js:47
low

Hardcoded credential / secret

NPS-78BAD533D890

A hardcoded Amplitude API key ('c66737ad47ec354ced777935b0af822e') is embedded directly in the source. Even public telemetry keys should not be hardcoded, as it enables unauthorized telemetry injection or abuse.

dist/core/telemetry/initCCA.js:38
low

Global namespace pollution / external dependency injection

NPS-AE06F93ABF24

The code trusts any object named window.ClientAnalytics and calls logEvent/identify on it. This creates a hook point where external scripts (browser extensions, compromised dependencies, or injected code) could intercept analytics data or trigger side effects. No allowlist or integrity check exists.

dist/core/telemetry/logEvent.js:44
low

Dynamic module loading with computed input

NPS-C8C9CE2655ED

The bundle uses a custom webpack-style module loader with runtime-computed requires (n(2), n(353), n(762), etc.) and dynamic export assignment, plus UMD-style fallback attaching ClientAnalytics to the global object. This is normal bundler output but makes auditing harder and could mask malicious payloads in minified form.

dist/core/telemetry/telemetry-content.js
low

Persistent configuration storage

NPS-33BBE27F56F6

The code stores configuration (including metadata, preferences, and paymaster URLs) in a persistent store (store.config.set + store.persist.rehydrate). This persists user-supplied configuration across sessions, which is expected but worth noting for the privacy-sensitive nature of crypto SDK data.

dist/interface/builder/core/createBaseAccountSDK.js:37
low

Injected provider usage

NPS-6B90130E7FC5

getInjectedProvider() may return a browser-injected provider (e.g., window.ethereum). This allows third-party code to be used as the provider, which is standard for wallet SDKs but means the actual signing/request handling is outsourced to whatever provider is injected.

dist/interface/builder/core/createBaseAccountSDK.js:52
low

Cross-origin window access

NPS-0F8CEC09F780

The function accesses window.top, which may throw a SecurityError when the script runs inside a cross-origin iframe. This can cause runtime exceptions and could be used to probe or infer frame hierarchy relationships. It is not inherently malicious but is a fragile and potentially risky pattern.

dist/interface/builder/core/getInjectedProvider.js:3
low

Minor Information Disclosure via Error Messages

NPS-5DEBFD5BBD43

Error messages leak internal details such as the sender wallet address and details of all USDC transfers found (Found ${usdcTransfers.length} USDC transfer(s)..., transfer details including recipient addresses). While not exploitable on its own, verbose error content could aid reconnaissance in multi-tenant or sensitive contexts.

dist/interface/payment/getPaymentStatus.js:178
low

Telemetry with user-controlled payloads

NPS-74AD7F7399D1

Telemetry calls (logPaymentStarted/logPaymentCompleted/logPaymentError) pass the payment amount, address, and error messages. While these appear to be local event loggers, if the underlying telemetry module forwards events to a remote server, it constitutes data exfiltration of financial details. The implementation of '../../core/telemetry/events/payment.js' is not visible.

dist/interface/payment/pay.js:40
low

Wallet interaction via custom RPC method

NPS-94F69D62A7DB

Uses a non-standard 'wallet_sign' method through provider.request() with mutableData fields, requesting signatures for spend permissions. While this appears to be a legitimate subscription flow using EIP-712 typed data, the custom method and placeholder address replacement mechanism could be abused if the wallet implementation is compromised or if the signing flow is manipulated.

dist/interface/payment/subscribe.js
low

External dependency usage

NPS-07F023475C69

Imports from multiple internal modules (telemetry, spend-permission utilities, SDK manager) whose implementations are not visible in this file. These could contain malicious code. The telemetry module in particular could perform network requests.

dist/interface/payment/subscribe.js:1
low

Client-side allowance trust / TOCTOU

NPS-4BD39C47D7EC

The function relies on getPermissionStatus (likely an RPC/offchain read) to decide whether to include approveWithSignature, then constructs spend and transfer calls locally. There is no cryptographic binding preventing a race between status check and execution, but this is inherent to the approval flow rather than a direct malicious pattern.

dist/interface/public-utilities/spend-permission/methods/prepareSpendCallData.js:131
low

Missing recipient address validation

NPS-11E7C1AB717C

The optional recipient is used as a raw address argument to encodeFunctionData for ERC20 transfer without checksum validation, zero-address check, or confirmation that it relates to the intended permission flow. Malformed or malicious addresses supplied by callers could misroute funds.

dist/interface/public-utilities/spend-permission/methods/prepareSpendCallData.js:146
low

Non-extractable key generation

NPS-9A2363641D11

Keys are generated with extractable:false, which is a positive security control. No exfiltration, obfuscation, dynamic execution, network calls, or process spawning was detected. The only external interactions are imports from trusted libraries (ox, viem) and local storage operations.

dist/kms/crypto-key/index.js:20
low

Implicit credential origin binding

NPS-996B34D4A546

Signing payloads are bound to the hardcoded origin 'https://keys.coinbase.com'. This is intentional WebAuthn origin binding, but it means signatures are only valid for that origin and could be leveraged in phishing scenarios if the user is misled about the relying party.

dist/kms/crypto-key/index.js:42
low

Missing error handling / silent failure

NPS-D81064722A49

getItem, setItem, and removeItem do not handle errors from idb-keyval. In a key-management context, a failed write or delete could leave stale or inconsistent key material, but no error is surfaced to the caller.

dist/kms/crypto-key/storage.js
low

Unvalidated storage scope and name

NPS-8EB46AAE082E

The scope and name arguments are passed directly to createStore without validation, allowing callers to choose arbitrary IndexedDB database/object store names. This could be abused to interfere with other components or to persist data in unexpected locations.

dist/kms/crypto-key/storage.js:3
low

Cryptographic Key Storage

NPS-98D0A1BB8247

The class stores cryptographic keys (private and public) in a local store. While this is expected for key management, private keys stored in plaintext within the application store could be exposed if the store is compromised or if storage is not properly secured. This is a common pattern in wallet/SDK implementations and does not itself indicate malicious behavior.

dist/sign/base-account/SCWKeyManager.js
low

Network communication with external RPC endpoints

NPS-DB30CF6CC523

The code fetches data from external RPC URLs (e.g., CB_WALLET_RPC_URL and this.chain.rpcUrl) via fetchRPCRequest. While this is expected for a wallet signer (communicating with blockchain RPC nodes), the constant CB_WALLET_RPC_URL is imported from core/constants.js and its value is not visible here; if it pointed to an attacker-controlled endpoint, it could exfiltrate data. This warrants inspection of that constant.

dist/sign/base-account/Signer.js
low

Access to window.location.origin

NPS-0753F207A044

The code reads window.location.origin to build a data suffix for attribution. This is a benign use for dapp attribution but demonstrates access to browser environment data.

dist/sign/base-account/Signer.js
low

Dynamic code execution (none)

NPS-EBFF3F76C2FA

No eval, new Function, or dynamic import from untrusted input is present. Module imports are static.

dist/sign/base-account/Signer.js
low

Process spawning or shell commands (none)

NPS-64897B45642C

No child_process or shell command execution is present.

dist/sign/base-account/Signer.js
low

Credential/secret harvesting (none)

NPS-A883404A6872

No access to .npmrc, ~/.ssh, ~/.aws, or other credential files is present.

dist/sign/base-account/Signer.js
low

Telemetry/data collection

NPS-85EFBC58AE08

Functions logDialogActionClicked, logDialogDismissed, and logDialogShown are imported from telemetry modules and invoked when displaying dialogs. This suggests user interaction data (dialog context, action) is being recorded/transmitted. While common in legitimate analytics, it constitutes data collection from the user environment.

dist/sign/base-account/utils.js
low

External address/spender handling

NPS-F0666E901C2E

assertFetchPermissionsRequest and fillMissingParamsForFetchPermissions construct spend permission requests using a spender address from the store. This is legitimate wallet functionality but represents sensitive approval-granting logic that should be carefully validated.

dist/sign/base-account/utils.js
low

Broad key-value storage API without validation

NPS-C93DE96FDA18

The exported 'keys.set(key, value)' accepts arbitrary string keys and values and stores them directly into the persisted store without any validation, allow-list, or encryption. A caller (or any code with access to the imported module) could write arbitrary data into localStorage under the 'base-acc-sdk.store' namespace, and the same accessor could be used to read back whatever was stored.

dist/store/store.js:148
low

Popup-based redirect / window.open usage

NPS-AA8567B3A615

The openPopup function uses window.open with a computed popupId and URL that receives appended query parameters. While common for OAuth/wallet flows, an attacker controlling the URL argument could potentially craft a malicious popup if the caller does not validate the URL. This is a design risk rather than an active malicious pattern.

dist/util/web.js:14
low

Sensitive data leakage via URL parameters

NPS-61011E332E61

The appendAppInfoQueryParams function appends origin (window.location.origin) and Cross-Origin-Opener-Policy (coop) values to the popup URL. While this is used to pass SDK metadata (name, version) for compatibility/diagnostics, it also leaks the dapp's origin and COOP state to the URL target. If the URL is later logged, cached, or redirected, this information could be exposed. However, the URL is used with window.open in the same context and the values are expected for wallet SDK operations, so this is a low-severity information disclosure rather than exfiltration.

dist/util/web.js:44
low

Telemetry collection

NPS-6B0BB655FF47

The code calls logDialogShown and logDialogActionClicked to send telemetry events about dialog interactions. These functions are imported from the package's own telemetry module, which may transmit user interaction data to a remote endpoint. While standard for SDK analytics, without inspecting the telemetry implementation, this could be a privacy concern.

dist/util/web.js:70

Files reviewed

FileVerdictWhat the reviewer saw
dist/core/error/serialize.js medium The code appears to be a benign error serialization utility with no malicious patterns, but it embeds potentially sensitive error messages into an external documentation URL, posing a minor information leakage risk.
dist/core/telemetry/events/subscription.js medium No malicious code patterns (exfiltration of credentials, obfuscation, shelling out, or install-time execution) were found, but the module deliberately routes sensitive-looking values such as permissionHash and raw error messages into third-party telemetry events.
dist/core/telemetry/initCCA.js medium The file silently injects and executes an inlined telemetry script that sends device-identifying telemetry and a hardcoded API key to an external Coinbase/Amplitude endpoint without consent, warranting warning-level scrutiny despite the apparent legitimate SDK origin.
dist/core/telemetry/logEvent.js medium No overt malicious code, but the module silently forwards application metadata (name, origin, SDK version) and caller-supplied event payloads to a global ClientAnalytics sink, creating a telemetry data-exfiltration surface and a supply-chain hook point that warrants review of how ClientAnalytics is populated.
dist/core/telemetry/telemetry-content.js medium This is a bundled Coinbase analytics/telemetry SDK that intentionally collects extensive user, device, session and network data and transmits it to Coinbase endpoints; it is not overtly malicious (no credential theft, shells, crypto miners, or eval), but its aggressive telemetry, persistent storage, and embedded minified payload warrant caution as a third-party dependency.
dist/interface/builder/core/createBaseAccountSDK.js medium The file contains no obvious malicious patterns such as credential harvesting, reverse shells, or obfuscated code, but it does perform telemetry loading and external script execution, which warrants user awareness regarding data collection.
dist/interface/builder/core/getInjectedProvider.js medium This file contains no direct malicious behavior such as exfiltration, code execution, or persistence, but it accesses cross-origin window properties and returns an injected Ethereum provider, which warrants caution due to wallet-related security implications.
dist/interface/payment/getPaymentStatus.js medium The code is a legitimate payment status checker, but it contains a hardcoded Coinbase API key in the bundler URL, which is a credential exposure risk, and some verbose error messages that leak transaction details.
dist/interface/payment/pay.js medium pay.js itself contains no obfuscation, shell execution, or credential harvesting, but its behavior depends entirely on unshown imported modules for transaction construction, wallet interaction, and telemetry, which are the likely locations of any malicious logic.
dist/interface/payment/subscribe.js medium The code appears to implement a legitimate cryptocurrency subscription creation flow using spend permissions on Base network, but includes telemetry logging of sensitive subscription data and relies on internal modules whose behavior cannot be verified from this file alone.
dist/interface/public-utilities/spend-permission/methods/prepareSpendCallData.js medium No overt malicious patterns (exfiltration, backdoors, shell execution, obfuscation) are present, but the unvalidated recipient parameter permits arbitrary ERC20 token transfers and warrants a warning.
dist/kms/crypto-key/index.js medium No malicious patterns detected; the module only manages locally stored WebCrypto P-256 keypairs and signs messages for a fixed Coinbase WebAuthn origin, with minor security considerations around browser storage of private key material.
dist/kms/crypto-key/storage.js medium The code is a simple IndexedDB wrapper with no exfiltration, code execution, or credential harvesting, but it stores key-value data in plaintext and lacks validation and error handling, which is a moderate concern for a crypto-key storage module.
dist/sign/base-account/Signer.js medium The code appears to be a legitimate Ethereum wallet signer component with standard RPC communication and cryptographic key handling; no obvious malicious patterns were detected, but external RPC endpoint constants (CB_WALLET_RPC_URL) should be verified as trusted.
dist/sign/base-account/utils.js medium No overt malicious patterns (exfiltration, shell execution, obfuscation, credential harvesting) were found; the file contains legitimate wallet SDK utilities with telemetry dialogs and paymaster URL injection worth monitoring.
dist/store/store.js medium The SDK store persists sensitive account/key/permission data to localStorage and exposes an unrestricted key-value setter, creating credential-exposure risk via XSS or same-origin scripts, but no active exfiltration, code execution, or other malicious patterns were found.
dist/util/web.js medium The file appears to implement legitimate popup and dialog handling for a wallet SDK (Base Account), with no malicious patterns such as exfiltration, credential harvesting, or code execution detected, though it does append origin/COOP metadata to popup URLs and emits telemetry.
dist/browser-entry.js safe No malicious patterns detected
dist/core/communicator/Communicator.js safe No malicious patterns detected; the code is a standard popup communication handler with proper origin validation.
dist/core/constants.js safe No malicious patterns detected
dist/core/error/constants.js safe No malicious patterns detected
dist/core/error/errors.js safe No malicious patterns detected; the code only defines Ethereum JSON-RPC error classes and validation helpers with no exfiltration, obfuscation, network, filesystem, or process activity.
dist/core/error/utils.js safe Cleared by Jev triage; no further analysis needed
dist/core/message/ConfigMessage.js safe No malicious patterns detected; the file is an empty module export with only a source map reference.
dist/core/message/Message.js safe The file contains only an empty export statement and a source map reference, with no executable or malicious code.
Show 80 more files
FileVerdictWhat the reviewer saw
dist/core/message/RPCMessage.js safe No malicious patterns detected
dist/core/message/RPCRequest.js safe No malicious patterns detected
dist/core/message/RPCResponse.js safe No malicious patterns detected
dist/core/provider/interface.js safe Cleared by Jev triage; no further analysis needed
dist/core/rpc/coinbase_fetchPermission.js safe The file contains only an empty export statement and a source map reference, with no executable or suspicious code.
dist/core/rpc/coinbase_fetchSpendPermissions.js safe No malicious patterns detected
dist/core/rpc/wallet_addSubAccount.js safe No malicious patterns detected
dist/core/rpc/wallet_connect.js safe No malicious patterns detected
dist/core/rpc/wallet_getSubAccount.js safe The file contains only an empty export and a source map reference, with no executable code or malicious patterns.
dist/core/rpc/wallet_prepareCalls.js safe No malicious patterns detected
dist/core/rpc/wallet_sendPreparedCalls.js safe This file is an empty ES module re-export with only a source map comment, containing no executable or suspicious code.
dist/core/telemetry/events/communicator.js safe The file only logs telemetry events via an internal logEvent helper and contains no malicious patterns, external network calls, credential harvesting, or dynamic execution.
dist/core/telemetry/events/dialog.js safe Cleared by Jev triage; no further analysis needed
dist/core/telemetry/events/payment.js safe No malicious patterns detected; the file contains only telemetry event logging functions with no data exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
dist/core/telemetry/events/provider.js safe No malicious patterns detected; the file only contains telemetry logging functions that call an internal logEvent utility with request metadata.
dist/core/telemetry/events/scw-signer.js safe No malicious patterns detected; the module only logs analytics events with internal state, without exfiltration, obfuscation, or credential access.
dist/core/telemetry/events/scw-sub-account.js safe No malicious patterns detected; the file only contains telemetry logging functions that use a local store and logEvent utility.
dist/core/telemetry/events/spend-permission.js safe No malicious patterns detected; the file only logs telemetry events through an internal logEvent wrapper with no external calls, credential access, or dynamic execution.
dist/core/telemetry/utils.js safe Cleared by Jev triage; no further analysis needed
dist/core/type/index.js safe No malicious patterns detected; the code only defines simple type/utility functions with no I/O, network, process, or dynamic execution behavior.
dist/core/type/util.js safe No malicious patterns detected; the code is a standard Coinbase utility module for hex/buffer/BigInt conversions and validation with no network, filesystem, process, or obfuscated behavior.
dist/core/username/getDisplayableUsername.js safe Cleared by Jev triage; no further analysis needed
dist/index.js safe No malicious patterns detected; the file only contains standard ES module re-exports.
dist/index.node.js safe No malicious patterns detected
dist/interface/builder/core/BaseAccountProvider.js safe The analyzed file contains standard wallet provider logic with no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, crypto mining, backdoors, or suspicious network/file/process operations.
dist/interface/payment/base.browser.js safe No malicious patterns detected
dist/interface/payment/base.js safe Cleared by Jev triage; no further analysis needed
dist/interface/payment/base.node.js safe No malicious patterns detected
dist/interface/payment/charge.js safe The code appears to be a legitimate payment charge function using the Coinbase CDP SDK, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or unauthorized system access.
dist/interface/payment/constants.js safe No malicious patterns detected; the file only contains static payment token configuration, chain IDs, and an ERC20 ABI definition.
dist/interface/payment/getOrCreateSubscriptionOwnerWallet.js safe No malicious patterns detected; code uses the official @coinbase/cdp-sdk to create/retrieve wallet accounts with provided or environment-based credentials, which is expected behavior for this module.
dist/interface/payment/getSubscriptionStatus.js safe No malicious patterns detected
dist/interface/payment/index.js safe No malicious patterns detected; the file only re-exports browser-safe payment-related modules without any obfuscation, network calls, credential access, or process execution.
dist/interface/payment/index.node.js safe No malicious patterns detected; the file only re-exports payment-related modules without any suspicious behavior.
dist/interface/payment/prepareCharge.js safe No malicious patterns detected; the code performs legitimate subscription charge preparation with input validation and no external data exfiltration, dynamic execution, or system commands.
dist/interface/payment/types.js safe No malicious patterns detected
dist/interface/payment/utils/sdkManager.js safe No malicious patterns detected; the code is a straightforward SDK wrapper for payment execution without exfiltration, obfuscation, or process/network abuse.
dist/interface/payment/utils/translatePayment.js safe No malicious patterns detected
dist/interface/payment/utils/validation.js safe No malicious patterns detected
dist/interface/public-utilities/spend-permission/index.js safe The file is a simple barrel export module with no executable code or malicious patterns.
dist/interface/public-utilities/spend-permission/index.node.js safe No malicious patterns detected
dist/interface/public-utilities/spend-permission/methods/fetchPermission.js safe No malicious patterns detected
dist/interface/public-utilities/spend-permission/methods/fetchPermissions.js safe No malicious patterns detected; the code is a straightforward RPC-based spend-permission fetcher with no exfiltration, credential harvesting, dynamic execution, or other red flags.
dist/interface/public-utilities/spend-permission/methods/getHash.js safe No malicious patterns detected
dist/interface/public-utilities/spend-permission/methods/getPermissionStatus.js safe No malicious patterns detected; the file is a legitimate blockchain permission status helper without data exfiltration, credential harvesting, obfuscation, or dynamic execution.
dist/interface/public-utilities/spend-permission/methods/prepareRevokeCallData.js safe The code is a straightforward helper for encoding spend permission revocation call data and contains no malicious patterns.
dist/interface/public-utilities/spend-permission/methods/requestRevoke.js safe No malicious patterns detected; the code performs a standard blockchain wallet call to revoke a spend permission with no data exfiltration, credential harvesting, or dynamic execution.
dist/interface/public-utilities/spend-permission/methods/requestSpendPermission.js safe The code is a legitimate EIP-712 spend permission request helper that uses the provided wallet provider to sign typed data and computes a local hash; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or process spawning are present.
dist/interface/public-utilities/spend-permission/utils.js safe No malicious patterns detected; the code is a straightforward utility for creating and manipulating spend permission typed data with no signs of exfiltration, obfuscation, or dynamic execution.
dist/interface/public-utilities/spend-permission/utils.node.js safe No malicious patterns detected; the code is a straightforward viem client helper with no exfiltration, credential harvesting, or dynamic execution.
dist/interface/public-utilities/spend-permission/withTelemetry.js safe No malicious patterns detected; the code is a standard telemetry wrapper that respects user preferences and only logs function execution metadata.
dist/sign/base-account/SCWKeyManager.js safe No malicious patterns detected; the code implements standard cryptographic key management for a smart contract wallet without exfiltration, obfuscation, or suspicious behaviors.
dist/sign/base-account/utils/constants.js safe This file only exports two hardcoded Ethereum contract addresses and several static ABI definitions with no executable, obfuscated, network, filesystem, or process-spawning code.
dist/sign/base-account/utils/createSmartAccount.js safe No malicious patterns detected; the code is a legitimate smart account implementation using viem for Ethereum transaction signing.
dist/sign/base-account/utils/createSubAccountSigner.js safe No malicious patterns detected
dist/sign/base-account/utils/findOwnerIndex.js safe No malicious patterns detected; the code is a legitimate utility for finding an owner index on a smart contract using viem.
dist/sign/base-account/utils/handleAddSubAccountOwner.js safe No malicious patterns detected; the code performs wallet sub-account owner management operations without exfiltration, obfuscation, or credential harvesting.
dist/sign/base-account/utils/handleInsufficientBalance.js safe No malicious patterns detected; the file contains straightforward error-handling logic with internal imports and no exfiltration, obfuscation, or dynamic execution.
dist/sign/base-account/utils/presentAddOwnerDialog.js safe No malicious patterns detected
dist/sign/base-account/utils/routeThroughGlobalAccount.js safe No malicious patterns detected; the file contains legitimate wallet routing logic using viem and internal utilities without any exfiltration, obfuscation, or other security concerns.
dist/store/chain-clients/store.js safe The file simply creates a Zustand vanilla store with an empty object and contains no malicious patterns.
dist/store/chain-clients/utils.js safe No malicious patterns detected; the code uses viem to create RPC clients for supported chains without data exfiltration, credential harvesting, obfuscation, or other red flags.
dist/store/correlation-ids/store.js safe No malicious patterns detected; the code is a simple Zustand store for managing correlation IDs with no external calls, dynamic execution, or file/process access.
dist/ui/Dialog/Dialog-css.js safe The file contains only static CSS-in-JS style definitions for a dialog component with no executable logic, network calls, filesystem access, or malicious patterns.
dist/ui/Dialog/Dialog.js safe This is a standard UI Dialog component for the Coinbase Base Account SDK with no malicious patterns, external data transmission, or suspicious behavior detected.
dist/ui/Dialog/index.js safe No malicious patterns detected; the code only initializes a dialog UI component and injects font styles.
dist/ui/assets/BaseLogo.js safe No malicious patterns detected
dist/ui/assets/BasePayLogo.js safe No malicious patterns detected; the file contains only static SVG logo rendering components with no network, filesystem, process, or dynamic execution behavior.
dist/ui/assets/colors.js safe Cleared by Jev triage; no further analysis needed
dist/ui/assets/fontFaceCSS.js safe No malicious patterns detected; the file only exports a static CSS string containing an embedded base64 font.
dist/ui/assets/index.js safe No malicious patterns detected
dist/ui/assets/injectFontStyle.js safe No malicious patterns detected
dist/util/assertPresence.js safe Cleared by Jev triage; no further analysis needed
dist/util/assertSubAccount.js safe No malicious patterns detected; the file only performs input validation for sub-account fields using trusted viem utilities.
dist/util/checkCrossOriginOpenerPolicy.js safe No malicious patterns detected; the code legitimately checks the Cross-Origin-Opener-Policy header of the current origin without exfiltration, credential harvesting, obfuscation, or unexpected network/process activity.
dist/util/cipher.js safe No malicious patterns detected
dist/util/encoding.js safe No malicious patterns detected; the code is a benign WebAuthn encoding utility with standard cryptographic conversions.
dist/util/get.js safe The file contains a simple utility function for safe property access on objects with no malicious patterns, external calls, or dynamic code execution.
dist/util/provider.js safe No malicious patterns detected in the provider utility code; it performs standard RPC request validation and dispatching.
dist/util/validatePreferences.js safe Cleared by Jev triage; no further analysis needed

Frequently asked questions

Is @base-org/account safe to use?

No confirmed malware was found in @base-org/account@2.4.0, but the review flagged 25 medium, 32 low severity findings for risky patterns worth checking before you rely on it.

Does @base-org/account contain malware?

No malware was identified in @base-org/account@2.4.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @base-org/account checked?

Togoder Security downloaded the published npm package and had an AI model read its 105 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @base-org/account together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @base-org/account@2.4.0, cost nothing.

Related security reports