Summary
Togoder Security scanned the npm package @coinbase/cdp-sdk@1.39.0 on Oct 4, 2026. An AI review of 317 source files produced 2 high, 43 medium, 53 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 98
Unsafe ERC20 approval pattern
NPS-3477351717A2
The function calls 'approve' with the full transfer amount before executing 'transfer'. This is functionally redundant (a direct ERC20 transfer does not require prior approval) and creates an unnecessary allowance. If the 'to' address is an externally controlled contract, the approved amount could be spent via transferFrom, potentially draining the approved tokens. Although not overtly malicious, this pattern is suspicious and could be part of a wallet drainer or allow unintended token spending.
Private key / account material exposure risk
NPS-6E24E053E7F1
toAccount(options.account) converts an EvmAccount (likely containing a private key or signer) into a viem Account and binds it to a user-supplied RPC URL via walletClient. If the URL is attacker-controlled, the wallet client could be used to sign/send transactions to a malicious RPC endpoint, enabling asset loss.
Dynamic URL construction from configuration
NPS-1D48599B60FB
The request host/path and final RPC URL are built dynamically from cdpApiClient.config.basePath and the network parameter without validation. A tampered basePath could redirect authenticated requests (including the JWT bearer token) to an attacker-controlled endpoint, leaking API credentials.
Credential usage in network request
NPS-C2ADE3175736
The function reads API key ID and secret from a global config object, generates a JWT, and sends it in an Authorization header to a remote URL derived from config.basePath. While this appears to be legitimate authentication against a known CDP (Coinbase Developer Platform) API, it demonstrates handling of secrets and outbound authenticated requests. If config.basePath is attacker-controlled (e.g., via environment or misconfiguration), credentials could be exfiltrated to an arbitrary server.
Telemetry/Analytics data collection
NPS-1B5F94B80ACD
The code integrates an Analytics.trackAction(...) call in every single one of the account's methods (transfer, listTokenBalances, sendUserOperation, waitForUserOperation, getUserOperation, requestFaucet, quoteSwap, swap, signTypedData, useSpendPermission, useNetwork). Each call collects behavioral/usage metadata including action names, account type, and network details. While this appears to be first-party telemetry from the SDK itself (not an obvious exfiltration to an attacker-controlled endpoint in this file), it silently profiles user actions on EVM smart accounts and may be phoned home to a remote server. Users should verify the implementation of the referenced Analytics module (../../analytics.js) to confirm whether it sends data externally and if it is appropriately disclosed/opt-out. This is a privacy/tracking concern rather than a clear malicious payload.
Potential lack of input validation
NPS-2E6637FCA637
The 'to' address and 'value' are used directly without validation or sanitization. If called with attacker-controlled input, it could result in transfers to malicious addresses. However, no direct exfiltration or backdoor is present.
Data exfiltration / Analytics telemetry
NPS-744506BB9962
The module sends potentially sensitive data to an external analytics endpoint at https://cca-lite.coinbase.com/amp. This includes error messages, stack traces, method names, user identifiers (Analytics.identifier), and arbitrary 'action' properties that may contain RPC URLs (trackAction extracts hostname from network URLs). This telemetry is enabled by default and can only be disabled via environment variables (DISABLE_CDP_ERROR_REPORTING, DISABLE_CDP_USAGE_TRACKING). Sending stack traces and application identifiers to a third-party server represents a privacy/security concern, though it appears to be legitimate SDK telemetry for Coinbase.
Sensitive data logging
NPS-5FBBFD23C51B
When the debug option is enabled, the interceptor logs the complete request configuration including headers (which will contain the JWT Authorization header) and request/response bodies. This can leak API key secrets, wallet secrets, and JWT tokens to logs or console output.
Telemetry/Analytics data collection
NPS-B7695AD71DA0
The client configures analytics with the API key ID and wraps core classes with error tracking, sending usage and error data to external servers (Coinbase CDP analytics). This is opt-out via environment variables but enabled by default.
Cryptographic/key handling
NPS-6AAA89C74ABC
exportAccount retrieves a private key from the remote Coinbase CDP API and decrypts it locally using an RSA private key generated in-process. The private key is returned to the caller. Legitimate for this SDK, but any exposure path for the decrypted private key is sensitive.
Cryptographic/key handling
NPS-041B6BC7FF1A
importAccount accepts a user-supplied private key (base58 or raw bytes), encrypts it with a public encryption key (either user-provided or a hardcoded ImportAccountPublicRSAKey constant), and ships the encrypted private key to the remote API. Legitimate for the SDK's purpose but represents private-key material explicitly routed off-device.
Sensitive private key material handling
NPS-7BCFA1011AC7
The module includes API functions for exporting EVM account private keys (exportEvmAccount, exportEvmAccountByName) and importing existing private keys (importEvmAccount), as well as transaction signing and sending endpoints. While these are legitimate documented Coinbase CDP SDK operations, the presence of private key export/import functionality represents inherently sensitive operations that could be abused if this package were trojanized or if credentials were exfiltrated. No actual exfiltration occurs within this file.
Sensitive key material handling
NPS-88345C419481
The module decrypts and formats Solana private keys. While standard cryptographic operations, handling plaintext private keys increases risk if the module or its consumers are compromised, and misuse can enable wallet key extraction.
User-controlled RPC endpoint executed as network request
NPS-DF42BE8BEDBB
resolveViemClients accepts an arbitrary networkOrNodeUrl string and, when it is not a known network identifier, passes it directly into http(nodeUrl) and immediately calls tempPublicClient.getChainId(). Any caller who controls that input can force outbound HTTP requests to an attacker-chosen host, enabling SSRF-style probing and leaking of the node's IP/User-Agent to arbitrary endpoints. Expected for a wallet library but worth noting given the arbitrary host.
Dynamic chain resolution from remote response
NPS-4C72849AE811
The chain used to build the wallet/public clients is derived from the remote RPC's chainId response (resolveNodeUrlToChain). If the attacker controls the RPC URL, they can return a chainId mapping to a legitimate viem chain but serve malicious chain metadata (e.g., altered contract addresses used by the wallet client).
Unvalidated External Input Passed to Signing
NPS-16D08A8ACF32
signTypedData spreads untrusted parameters.types into the EIP712 types object and forwards arbitrary domain/message to the apiClient without validation. A malicious caller could supply crafted typed-data payloads (e.g., Permit signatures) that, if confirmed by the user, could authorize token approvals. This is an API design concern rather than an installed backdoor.
Arbitrary user operation execution
NPS-614D5AC84792
useSpendPermission constructs and sends a user operation (sendUserOperation) using caller-supplied spendPermission and value. If spendPermission is not validated, an attacker controlling options could craft calldata that leads to unauthorized spending or interaction with the spend permission manager. This is a standard DeFi transaction path but lacks visible validation in this file.
Hardcoded contract address
NPS-046EE9387CF6
SPEND_PERMISSION_MANAGER_ADDRESS is imported from constants rather than being provided by the caller. The function sends a user operation to this hardcoded address with calldata that includes a caller-supplied spendPermission and value. If this address were malicious or compromised, funds/permissions could be redirected. While the address is not shown in this file, hardcoded target addresses in transaction-sending utilities warrant review.
approve-then-transfer pattern
NPS-98E5F0B85138
For ERC20 tokens, the code first sends an approve transaction allowing the recipient (to) to spend the sender's tokens, then immediately performs a transfer. This is unnecessary for a simple transfer and creates a temporary allowance for the recipient. If the recipient is malicious or the approval is not revoked, they could later drain the approved amount. This is a potentially dangerous anti-pattern, though common in some libraries.
Data exfiltration / analytics tracking
NPS-182000D40D6D
The module automatically sends analytics events (including error messages, stack traces, user_id, and arbitrary event properties) to an external server at https://cca-lite.coinbase.com/amp. While this appears to be an intentional SDK telemetry feature with an opt-out via DISABLE_CDP_ERROR_REPORTING / DISABLE_CDP_USAGE_TRACKING environment variables, it silently collects and transmits potentially sensitive error details and user identifiers to a third-party endpoint.
Error stack trace exfiltration
NPS-02723BC90368
handleMethodError destructures message and stack from caught errors and forwards them to the external analytics endpoint, potentially leaking file paths, internal code structure, and sensitive runtime information.
Credential/Secret Logging
NPS-41CA0BDFC0D4
When options.debug is enabled, the interceptor logs request and response details including all headers (which include Authorization/JWT and API key headers), request bodies, and response data to the console. This can leak credentials and sensitive data into logs, CI output, or shared terminals.
Sensitive Data Exposure in Error Logging
NPS-498A2A47B526
The response error interceptor logs response headers and data on errors when debug is enabled, which may expose authentication tokens, API keys, or sensitive payload/response content.
Credential / Environment Variable Access
NPS-63302A120C8C
Reads CDP_API_KEY_ID, CDP_API_KEY_SECRET, CDP_API_KEY_NAME, and CDP_WALLET_SECRET from process.env and passes them to CdpOpenApiClient.configure(). This is expected for an SDK that needs to authenticate against the CDP API, but it does mean the package has direct access to sensitive credential environment variables.
Usage / Error Telemetry
NPS-AF2FF8677570
When DISABLE_CDP_ERROR_REPORTING and DISABLE_CDP_USAGE_TRACKING are not explicitly set to 'true', the code assigns the API key ID to Analytics.identifier and wraps CdpClient, EvmClient, SolanaClient, and PoliciesClient with error tracking. This enables telemetry that attaches the API key ID to analytics events and reports runtime errors to Coinbase. While this appears to be vendor-official coinbase/cdp-sdk behavior, it is data collection that occurs by default without explicit opt-in and should be reviewed for privacy/compliance implications.
Signing/transaction endpoints exposed
NPS-4F6E6AC5B343
Functions such as sendEvmTransaction, signEvmTransaction, signEvmHash, and signEvmTypedData allow arbitrary transaction signing and broadcasting via the remote API. While expected for a wallet SDK, compromise of the API client or credentials could enable unauthorized signing of value-bearing transactions.
Sensitive private key export functions
NPS-EE3907FB669D
The module exposes exportEvmAccount and exportEvmAccountByName functions that retrieve an EVM account's private key from a remote API. If misused, these endpoints could facilitate private key exfiltration, though the functions themselves are legitimate CDP SDK API wrappers.
Cryptographic key handling with Solana wallet
NPS-E1D98AAF05BE
The code imports @solana/web3.js and manipulates Solana keypairs. The formatSolanaPrivateKey function takes a hex private key, derives a Solana Keypair, and encodes the full keypair (seed + public key) in base58 for import into wallet apps. While this may be legitimate for wallet export functionality, handling private keys in this manner is inherently sensitive and could be used to facilitate key theft or wallet draining if the private key source is attacker-controlled or exfiltrated.
Potential SSRF via config.basePath
NPS-9631D3AB8C35
The basePath is taken from a shared config object and directly interpolated into fetch URL without validation of scheme, host, or trust boundary. If an attacker can influence config.basePath, sensitive JWT (derived from apiKeySecret) could be sent to an attacker-controlled endpoint. The subsequent response (json.id) is also interpolated into a returned URL without validation.
SSRF / outbound request to user-supplied URL
NPS-F84491FA7D15
resolveNodeUrlToChain creates a public client with http(nodeUrl) and immediately calls getChainId(), causing a server-side request to any user-supplied URL that passes isValidUrl. This can be abused for SSRF to internal services if input originates from untrusted sources.
Dynamic chain resolution from remote data
NPS-454A2E2995DD
The chain is derived from getChainId() returned by a user-supplied RPC endpoint. A malicious RPC can return any chain ID, causing the wallet client to operate on an unintended chain, potentially leading to cross-chain replay or sending funds to the wrong network.
Arbitrary RPC URL usage
NPS-0E67F47BAE4C
The function accepts arbitrary Node URLs via networkOrNodeUrl and constructs viem HTTP transports to those URLs. This allows the caller to direct RPC traffic and, more importantly, wallet-client signing/transaction submission to an attacker-controlled endpoint. While this is a legitimate feature for an EVM client resolver, it can enable phishing/traffic interception if the input is not strictly validated elsewhere.
Unlimited token approval
NPS-F857BAB9A186
The code calls the ERC20 'approve' function with the user-supplied 'value' as the allowance before executing a 'transfer'. This grants the recipient (or spender) the approved amount directly on the token contract, creating an unnecessary and potentially dangerous approval window. In a standard transfer flow, 'approve' is not required and allowing an arbitrary spender to pull tokens is a common attack vector if the address or amount is not strictly controlled. This could be exploited to drain tokens if the transfer target is manipulated.
data_exfiltration
NPS-13845B388620
The module sends telemetry data to an external endpoint 'https://cca-lite.coinbase.com/amp' via fetch POST. It transmits error messages, stack traces, method names, action names, account types, arbitrary 'properties' objects, project name, SDK version, and a user/identifier value. While this appears to be legitimate analytics, it is hidden/automatic in nature and captures potentially sensitive runtime data (including full stack traces and arbitrary user-provided properties).
automatic_monkey_patching / method wrapping
NPS-7FDA1C4001E8
wrapClassWithErrorTracking and wrapObjectMethodsWithErrorTracking mutate prototypes and object methods at runtime, replacing user-supplied methods with wrappers that automatically report errors (including stack traces and arguments context) to an external service without explicit user consent per-call. This is a form of automatic surveillance hooking.
sensitive_data_collection
NPS-8AA41983A9CD
Tracked error events include stack traces ('stack') which may contain file paths, function names, and other sensitive context. Action tracking passes through arbitrary properties (minus customRpcHost normalization), potentially leaking user-controlled data (e.g., amounts, addresses, tokens) to the external analytics service.
env_variable_opt_out_only
NPS-CE74C5211007
Telemetry is enabled by default and only disabled via environment variables (DISABLE_CDP_ERROR_REPORTING, DISABLE_CDP_USAGE_TRACKING). This means the package phone-homes silently unless the user takes explicit action.
URL Construction
NPS-52BE035A93AB
The fully qualified URL is built by string concatenation (axiosClient.getUri() + axiosConfig.url) before parsing with URL. If axiosConfig.url is an absolute URL, this could produce an unexpected host, potentially causing the Authorization header to be sent to an unintended destination (auth header leakage via SSRF-like behavior).
Sensitive Data Logging
NPS-43B8E4C9122F
When debug mode is enabled, the request interceptor logs the full request config including Authorization headers (which contain JWT signed with the apiKeySecret) and the request body. Response interceptor likewise logs response headers and body. This can leak API keys, wallet secrets, and sensitive payloads to console/logs in production if debug is mistakenly enabled.
Re-export of unknown modules
NPS-2340D8A15E6B
The file re-exports all members from ./utils/http.js, ./utils/jwt.js, and ./utils/ws.js, as well as importing ./hooks/axios/index.js. The actual content of these modules is not provided, so their behavior cannot be verified. If any of these modules contain malicious code (e.g., data exfiltration, credential harvesting, backdoors), it would be exposed via this barrel file. This pattern is common in supply chain attacks where a benign-looking index re-exports malicious submodules.
Telemetry / analytics data reporting
NPS-9F54D3A71ECB
The code uses Analytics.identifier, setting it to the apiKeyId (a sensitive credential) and wraps multiple classes with error tracking. It sends usage/error data to external analytics servers unless explicitly disabled via DISABLE_CDP_ERROR_REPORTING or DISABLE_CDP_USAGE_TRACKING environment variables. Using the API key ID as an analytics identifier could leak credential-adjacent data to external endpoints. This is the official Coinbase SDK's known telemetry mechanism, so it is documented but still worth noting.
Error tracking wrappers on client classes
NPS-11C52BF6E9D8
Analytics.wrapClassWithErrorTracking is applied to CdpClient, EvmClient, SolanaClient, and PoliciesClient. This likely intercepts method calls and reports errors (and possibly arguments) to external analytics endpoints. Detailed error context could inadvertently include sensitive data such as API keys or wallet operation details.
Cryptographic operation with external/public key
NPS-82FAC6121776
The importAccount method encrypts a user-supplied private key using an RSA public key that can be overridden via the options parameter (options.encryptionPublicKey). An attacker who can control this parameter could specify their own public key and capture the user's private key. While the default key is a package constant, this override capability introduces a risk of key exfiltration if the caller is tricked or if the API is misused.
Private key export functionality
NPS-75010190D795
The file exposes functions exportEvmAccount and exportEvmAccountByName that export EVM account private keys. While this is expected CDP API functionality, it represents a high-value attack surface and should be documented with a clear security warning. The generated comments do mention storing the private key securely, but any code path able to call these functions could exfiltrate private keys if the surrounding client is compromised.
Sensitive key material handling
NPS-64358F0A78EF
The formatSolanaPrivateKey function accepts a hex private key and constructs a full Solana secret key (seed + public key) for wallet import. While this is a legitimate utility, it processes raw private key material in memory and outputs it as base58. If this function is invoked with untrusted input or the resulting string is logged/transmitted, it could facilitate private key exposure. No exfiltration is present, but the function is a high-value target for misuse.
Silent error swallowing
NPS-CB7274523D4C
All exceptions in the try/catch are silently ignored with a bare catch returning undefined. This can hide network or authentication failures and complicate security monitoring, though it is not itself malicious.
analytics telemetry
NPS-DBC29B9BF3C6
The code sends analytics events (action names and account type) to an internal analytics module. This is expected telemetry for a wallet SDK, not data exfiltration to an external attacker-controlled server.
No install/import-time execution or dynamic code execution
NPS-1EE50DF5649D
No top-level side effects, eval/new Function, child_process/exec, filesystem manipulation, environment/credential harvesting, network calls outside the SDK's stated purpose, or dynamic require with computed input were found. Requires are static and refer to internal modules (.js relative paths).
Implicit default-owner signing authority
NPS-DD3517E4D290
Several methods (quoteSwap, swap) hardcode signerAddress: this.owners[0].address and taker: this.address. If an attacker can influence options.owner at account creation time (e.g., via a supply-chain or config injection), the first owner becomes the implicit signing authority for all future swap/sign operations. This is a design risk worth scrutinizing in the surrounding toNetworkScopedEvmSmartAccount / sendSwapOperation modules.
Telemetry/Analytics
NPS-2E8277C27A5E
The code calls Analytics.trackAction at various points (send_transaction, transfer, wait_for_transaction_receipt, list_token_balances, request_faucet, quote_swap, swap, use_spend_permission). This is telemetry that sends usage data to an external analytics service. While not inherently malicious, it is data exfiltration of operational metadata and may be a privacy concern depending on the package's policies.
External network/API call to a third party
NPS-92926FC5908D
The function calls client.prepareUserOperation and client.sendUserOperation, which may ultimately route to Coinbase CDP API endpoints. The default paymasterUrl for 'base' network is resolved via getBaseNodeRpcUrl. This is expected SDK behavior for a blockchain user operation sender, but the paymasterUrl is supplied by the caller and could point to an attacker-controlled endpoint, though it is not exfiltration by itself.
Cryptographic signing operation
NPS-39E3396678C7
Owner private key material (owner.sign) is used to sign a userOpHash. This is normal for a wallet SDK but implies access to signing keys. No key exfiltration is observed; only a hash signature is produced.
Network request with mode: no-cors
NPS-2912F172DCCF
The fetch call uses mode: 'no-cors', which prevents the caller from reading responses and can be used to bypass CORS restrictions. While commonly used for fire-and-forget analytics, it can also be used for covert data transmission without visibility into the response. Combined with the external endpoint, this is a notable pattern.
Monkey-patching / method interception at import/usage time
NPS-FF256D7E0DDD
wrapClassWithErrorTracking and wrapObjectMethodsWithErrorTracking dynamically replace all prototype/object methods with wrapped functions via Object.getOwnPropertyNames. This is executed when consumers call these functions, and the wrapped functions automatically capture errors (including stack traces and messages) and forward them to the external analytics service. This interception behavior could be abused to exfiltrate error context, though here it appears to be for legitimate error reporting.
Sensitive data logging on errors
NPS-FAD1C9FDF5B9
Debug mode also logs response error details including headers and data, which may contain authentication tokens or sensitive response payloads in error scenarios.
Environment variable harvesting
NPS-5D2B1B6A9108
The constructor reads sensitive credentials from environment variables (CDP_API_KEY_ID, CDP_API_KEY_SECRET, CDP_WALLET_SECRET, CDP_API_KEY_NAME) and passes them to the API client configuration. While this is expected for an SDK, it involves handling sensitive keys.
Analytics/telemetry
NPS-442D2EA98C30
Every public client method calls Analytics.trackAction(...) before performing the operation, and accounts returned are wrapped with Analytics.wrapObjectMethodsWithErrorTracking(account). This transmits usage telemetry to remote analytics infrastructure, which may include method names, account types, and network identifiers.
External network dependency
NPS-268A78E86223
All key operations (createAccount, exportAccount, importAccount, signMessage, signTransaction, sendTransaction) delegate to CdpOpenApiClient, which communicates with an external Coinbase endpoint. Since this file handles private keys, users should be aware that key material and/or signing requests flow to a remote service.
User-controlled URL path segments without encoding
NPS-B19D1EE29456
Address and name parameters are interpolated directly into URL paths (e.g., /v2/evm/accounts/${address}) without encodeURIComponent. While this is a common pattern in generated API clients, it could allow path traversal or request forgery against unintended endpoints if untrusted input is passed. This is a minor input-handling concern, not malicious.
Potential insecure RSA key generation
NPS-24D6277AC9B3
Generates 4096-bit RSA keys and returns base64-encoded PKCS1 DER private keys. Although not inherently malicious, exporting private keys as strings from a utility module can facilitate credential leakage if logs, telemetry, or error paths capture them.
Private key / account material passed into wallet client
NPS-AECFABFC4585
options.account is converted via toAccount() and embedded into createWalletClient. This is standard for signing flows, but if the account object contains a raw private key, this module would be a convenient sink for credential theft in a compromised dependency. No local exfiltration is present, but the acceptance surface is broad.
Analytics/Telemetry
NPS-4C9523CF2DC2
Every signing and transaction method calls Analytics.trackAction, sending operational metadata (action type, account type, network, and account address implicitly via the account object) to an analytics endpoint. While not inherently malicious and consistent with legitimate SDK telemetry, it constitutes data collection that may be undesirable depending on the threat model.
Credential/Key Handling via Remote API
NPS-C728DCC83627
All cryptographic signing operations (signMessage, sign, signTransaction, signTypedData) delegate to a remote apiClient rather than local key storage. This is a server-managed account design, not a drainer, but it means sensitive operations depend on a trusted external service and the code does not itself expose private keys.
Telemetry / analytics tracking
NPS-EC3D962DE305
The module calls Analytics.trackAction() on every account method invocation, reporting action names and network properties. This appears to be first-party product telemetry (Coinbase CDP SDK), not exfiltration of secrets; no credentials, keys, or user data beyond account type and network are collected.
Network scoping logic
NPS-D80FFE40AC3C
The function resolves viem clients from a user-supplied network or RPC URL and delegates signing/sending to the underlying account. This is expected behavior for a network-scoped account wrapper and does not itself exfiltrate data or execute untrusted code.
Analytics tracking
NPS-4C65BB676548
The code calls Analytics.trackAction with action names, account type, and network properties before performing operations. This is telemetry, not credential/secret exfiltration, and does not transmit private keys, seed phrases, or sensitive file contents.
Analytics data collection
NPS-3C71D8013FDB
The code calls Analytics.trackAction for each operation, sending action names and account type properties to an analytics endpoint. This is a common, non-malicious pattern for usage telemetry but does constitute data exfiltration if the endpoint is external and not disclosed. However, no sensitive data like credentials or keys is included.
User behavior tracking
NPS-3D2C2AB56350
The code uses an Analytics.trackAction function to track user actions (request_faucet, sign_message, sign_transaction, send_transaction, transfer) along with account type and network information. While this may be a legitimate analytics feature, it constitutes telemetry data collection that could be considered a privacy concern depending on how the collected data is used.
Import-time side effects / method wrapping
NPS-0E6696CC56F1
The module export objects (Analytics, AnalyticsDeprecated) and the wrapping functions modify prototypes and object methods at call sites. No top-level execution occurs beyond symbol/constant definitions, but the wrapping utilities intercept and redirect every class/object method through error-reporting wrappers that call sendEvent, effectively instrumenting arbitrary user classes for telemetry.
Potential SSRF / Unvalidated Request Targeting
NPS-9DC602A56799
The interceptor builds a fully qualified URL from axiosClient.getUri() concatenated with axiosConfig.url and sends authentication headers to the resulting host/path. If the axios client base URL or request URL is attacker-influenced, credentials could be sent to an unintended host. No allow-listing or host validation is present.
Import-time Side Effects
NPS-5E25666B19B2
The module imports Analytics and openapi-client modules which may perform network/telemetry side effects. The constructor also performs environment and version checks and modifies shared static configuration (CdpOpenApiClient.configure) as a side effect of instantiation.
Telemetry/Analytics tracking
NPS-27EA7DA97AAF
The code imports and calls an internal Analytics.trackAction() function on every public method invocation (createEndUser, listEndUsers, validateAccessToken). While the analytics module is part of the same package and no data exfiltration to an external server is directly visible here, sending usage telemetry from a client-side SDK is a privacy concern that should be scrutinized (what data is collected and where it is sent).
Random identifier generation
NPS-9C88ABCB94C8
randomUUID() from Node's crypto module is used to generate user IDs. This is cryptographically appropriate and not a security concern.
Credential handling
NPS-DD49F5FBD361
validateAccessToken forwards the provided accessToken directly to the backend API client. The token is not logged or persisted in this file, which is good practice, but it does get passed through to CdpOpenApiClient without any local redaction or validation, so any weakness in that layer could expose credentials.
Data collection for analytics
NPS-073EC9D08939
The code sends action names and limited context (e.g., scope) to an internal Analytics module. This appears to be first-party telemetry for the CDP SDK, not exfiltration to an attacker-controlled server. No credentials, environment variables, or sensitive user data are collected.
Input validation using Zod
NPS-2BA574910557
CreatePolicyBodySchema.parse and UpdatePolicyBodySchema.parse are called to validate input; this is legitimate input validation and not dynamic code execution.
Path parameter interpolation without encoding
NPS-7BE0F23C14CA
Address and name values are interpolated directly into URL paths (e.g. /v2/evm/accounts/${address}) without URL encoding. A malicious or malformed address/name containing path traversal or special characters could alter the request target, potentially leading to unexpected API endpoints being hit.
No obvious malicious patterns
NPS-D487270A8802
The code performs standard RSA key generation and decryption, and Solana key formatting. There is no evidence of data exfiltration, environment variable harvesting, obfuscation, dynamic code execution, mining, backdoors, suspicious network requests, file system manipulation, or process spawning. The cryptographic operations appear to be for legitimate export/decryption purposes.
Credential-Based Network Request
NPS-7DA45DBE8D38
The function constructs an API key-based JWT (using apiKeyId and apiKeySecret from the config) and sends it via an Authorization header to a dynamically-derived URL from config.basePath. While this appears to be legitimate authentication to the CDP API, it represents credential usage in outbound network requests that could become exfiltration if config is attacker-controlled or basePath is tampered with.
Silent Error Swallowing
NPS-17D0DA53DF69
The catch block silently returns undefined, hiding failures including network errors or auth errors. This is not malicious per se but can mask misbehavior and complicate security auditing of the credential flow.
Analytics/Telemetry
NPS-608ACB1D9865
The code tracks user actions (send_transaction, transfer, wait_for_transaction_receipt, etc.) via an Analytics module. This is common in SDKs but could be a privacy concern if it sends data externally without consent. However, it only tracks action names and network/account type, not sensitive data.
Analytics tracking
NPS-1564DBAA83AA
The code includes Analytics.trackAction calls that report action types and some account metadata (e.g., accountType, network) to an internal analytics system. This is not classic exfiltration of credentials or secrets but is telemetry that could be a privacy concern depending on policy. No external endpoints are hardcoded in this file.
No malicious patterns
NPS-294EA9E95977
No obfuscation, eval/exec, environment variable harvesting, filesystem manipulation outside package scope, process spawning, dynamic imports, or wallet draining logic is present. The code simply constructs an account object with wrapper methods that delegate to imported actions.
Missing validation / user confirmation
NPS-9D36C6CAFAD0
The function takes transfer arguments (recipient address, amount, token) from the caller and immediately submits transactions without any validation or confirmation. While this may be intentional for a library, it enables misuse where an attacker-controlled caller can initiate token approvals and transfers. The code does not verify that the token address is legitimate, that the recipient matches the intended one, or that the amount is within safe limits.
hardcoded_public_client_id
NPS-090F88D1C602
A hardcoded 'publicClientId' (54f2ee2fb3d2b901a829940d70fbfc13) is embedded and used to authenticate to the external analytics endpoint. This is expected for analytics but represents a fixed, non-user-configurable reporting channel.
md5_usage
NPS-A7F29EE36B10
MD5 is used to generate an integrity 'checksum' for telemetry payloads. MD5 is cryptographically broken, though here it is not used for security purposes (just payload integrity), so risk is low.
Credential Handling
NPS-6C0BABD8C9FC
API key secrets and optional wallet secrets are accepted as plain strings and passed through to getAuthHeaders. No validation or zeroization of secrets in memory. This is typical for auth libraries but warrants attention given the wallet secret handling.
Credential harvesting via environment variables
NPS-14401589F979
The constructor reads sensitive credentials (CDP_API_KEY_ID, CDP_API_KEY_NAME, CDP_API_KEY_SECRET, CDP_WALLET_SECRET) from environment variables. While this is a documented design pattern and expected behavior for SDK configuration, it involves accessing sensitive secrets from the process environment, which could be exploited if the package were compromised. This is standard behavior for the official Coinbase CDP SDK, not inherently malicious.
Data exfiltration via analytics
NPS-7C7AE1750532
The client imports an Analytics module and calls Analytics.trackAction for each public method (createEndUser, listEndUsers, validateAccessToken). This collects telemetry about user operations. While this appears to be intentional SDK analytics rather than covert exfiltration, it does transmit usage data alongside operations without an explicit opt-out, and the Analytics implementation is not shown and could contain unexpected behavior.
Cryptographic identifier generation
NPS-A723DCE04196
Uses crypto.randomUUID() to generate user IDs when not supplied. This is standard and safe, but worth noting as it involves identity material generated client-side.
Sensitive data handling (cryptography)
NPS-7006BEB928B7
The module uses Node's crypto primitives (publicEncrypt with RSA-OAEP/SHA-256 and a decryptWithPrivateKey helper) to protect private keys during import/export. This is a legitimate cryptographic design, not a backdoor; no key material is exfiltrated to unintended destinations.
Network communication to external API
NPS-4A51FE9006A8
All network calls go through the CDP OpenApiClient (Coinbase Developer Platform SDK). Endpoints are hardcoded/derived from the SDK configuration; no user-controllable URLs, eval, or dynamic imports are used to redirect traffic.
Analytics tracking
NPS-BFD1BD8CCD56
Multiple methods call Analytics.trackAction, which may transmit usage data to external servers. While not inherently malicious, this constitutes data collection that could include sensitive metadata (e.g., action types, account types, network names). Users should be aware of this telemetry.
Private key handling
NPS-18C65DA757F9
The exportAccount method generates an encryption key pair, sends the public key to the API, receives an encrypted private key, and decrypts it locally. This pattern is standard for secure key export, but it involves handling sensitive private key material in memory. No direct exfiltration is present, but the risk of improper memory handling or accidental logging exists.
Import-time side effects / dynamic module namespace
NPS-1A0014858AD0
This file re-exports symbols from a 'spend-permissions' module and includes Ethereum-related utilities (viem parseEther/parseUnits, spend permission manager ABI/address). While no direct exfiltration, process spawning, or obfuscation is present in this index file, imported modules may execute top-level code on import. The presence of blockchain/wallet-related exports (SpendPermission, spendPermissionManagerAddress/Abi, parseEther) in a package warrants review of the underlying modules for wallet-draining or address-rewriting behavior, as these are common targets for supply-chain attacks. No malicious pattern is present in the shown code itself.
Unvalidated URL path interpolation
NPS-885248D05FB6
User-supplied address/name values are interpolated directly into request URLs (e.g. /v2/evm/accounts/${address}, /v2/evm/accounts/by-name/${name}, /v2/evm/accounts/export/by-name/${name}) without visible encoding or validation in this module. If cdpApiClient does not URL-encode these segments, an attacker-controlled address/name could alter the request path, potentially causing requests to unintended endpoints on the API host (path traversal / SSRF-style issues within the API surface).
Signature oracle exposure
NPS-0CAF49105396
Functions signEvmHash, signEvmMessage, signEvmTypedData, and signEvmTransaction allow arbitrary 32-byte hashes, EIP-191 messages, EIP-712 typed data, and RLP-serialized transactions to be signed. The docs note the API does not validate unsigned transactions. This is expected for a signing SDK, but callers with access to this module can obtain valid signatures over attacker-chosen payloads, which is a significant capability worth surfacing explicitly.
Cryptographic parameter choice
NPS-0854122E8A46
The RSA private key is generated in PKCS1 DER format with 4096-bit modulus, which is acceptable. However, RSA-OAEP-SHA256 decryption is used on a PKCS1-formatted key, which is valid. No cryptographic weakness is directly introduced by this code, but storing/exporting unencrypted private keys in base64 is a sensitive operation that should be handled carefully by callers.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| _cjs/accounts/evm/getBaseNodeRpcUrl.js | medium | The code is a legitimate-looking RPC URL resolver that authenticates with stored API credentials, but builds request URLs dynamically from configuration without validation, creating a potential credential-exfiltration vector if config.basePath is attacker-controlled. |
| _cjs/accounts/evm/toEvmSmartAccount.js | medium | The file is a benign-looking EVM smart account wrapper, but it silently instruments every user action with analytics telemetry and relies on owners[0] as an implicit signer—worth verifying the referenced Analytics and network-scoped modules before trusting it in production. |
| _cjs/actions/evm/transfer/transferWithViem.js | medium | The code contains a suspicious redundant ERC20 approve pattern that could lead to token drain, but no direct malicious patterns like exfiltration or backdoors were found. |
| _cjs/analytics.js | medium | This appears to be a legitimate Coinbase CDP SDK analytics module, but it performs default-on telemetry that transmits error stacks, identifiers, and action properties (potentially including RPC hostnames) to an external endpoint via no-cors fetch, raising privacy and data-exfiltration concerns. |
| _cjs/auth/hooks/axios/withAuth.js | medium | The code is a legitimate axios auth interceptor, but debug logging may expose JWT tokens and secrets in headers and bodies. |
| _cjs/client/cdp.js | medium | The code is a legitimate Coinbase CDP SDK client that handles API credentials and includes opt-out analytics/error tracking, posing moderate privacy concerns but no clear malicious patterns. |
| _cjs/client/solana/solana.js | medium | No malicious behavior detected: this is a legitimate Coinbase CDP Solana client that handles private keys as part of its documented functionality, though it performs external API calls and analytics telemetry that merit awareness. |
| _cjs/openapi-client/generated/evm-accounts/evm-accounts.js | medium | This is a generated Coinbase CDP API client for EVM account management; no malicious exfiltration, obfuscation, process spawning, or install-time execution was found, though it exposes legitimate but inherently sensitive private-key export/import operations. |
| _cjs/utils/export.js | medium | The code performs legitimate RSA key operations and Solana private key formatting but handles sensitive cryptographic key material, which presents a moderate security concern if misused or if the package is compromised. |
| _esm/accounts/evm/resolveViemClients.js | medium | No backdoors, exfiltration, or obfuscation found; the main concerns are SSRF-style arbitrary outbound requests and trust of remote RPC responses when a user-supplied node URL is used, both of which are expected behavior for an EVM client resolver but warrant review. |
| _esm/accounts/evm/toEvmServerAccount.js | medium | No malicious backdoor, exfiltration, or crypto-drainer patterns detected; the file contains legitimate SDK signing/transfer wrappers with extensive analytics tracking and remote signing delegation that warrant low-to-medium caution. |
| _esm/accounts/solana/toSolanaAccount.js | medium | The code wraps Solana account actions with analytics tracking, which is a minor privacy concern but no malicious patterns like data exfiltration, credential harvesting, or wallet draining were detected. |
| _esm/actions/evm/spend-permissions/smartAccount.use.js | medium | No clear malicious patterns (no exfiltration, credential harvesting, obfuscation, or process execution), but the function sends arbitrary user operations to a hardcoded contract address with caller-supplied permission data, which warrants trust verification of constants and input validation. |
| _esm/actions/evm/transfer/transferWithViem.js | medium | The code performs a standard EVM token transfer but uses an unnecessary approve-then-transfer pattern for ERC20 tokens, which could grant an unintended allowance to the recipient. |
| _esm/analytics.js | medium | The code contains intentional but potentially privacy-invasive telemetry that transmits error details, stack traces, and identifiers to an external Coinbase analytics endpoint; it is not overtly malicious but warrants scrutiny for data-leakage concerns. |
| _esm/auth/hooks/axios/withAuth.js | medium | No overtly malicious code (no exfiltration, shells, install-time hooks, or obfuscation), but debug logging can leak auth headers and response data, and URL construction lacks host validation. |
| _esm/client/cdp.js | medium | This appears to be the legitimate Coinbase CDP SDK client entrypoint; it reads standard CDP credential env vars and enables opt-out telemetry that includes the API key ID, which is a privacy concern but not evidence of malicious exfiltration. |
| _esm/client/end-user/endUser.js | medium | No clear malicious patterns were found; the file is a straightforward SDK client wrapper that forwards calls to a backend API client, though it does include built-in analytics tracking that warrants review of what is collected and transmitted. |
| _esm/openapi-client/generated/evm-accounts/evm-accounts.js | medium | No obfuscation, exfiltration, credential harvesting, or dynamic execution was found; the file is a straightforward OpenAPI client wrapper, but it exposes sensitive private-key export and signing endpoints that warrant caution. |
| _esm/utils/export.js | medium | The code handles cryptographic keys, including Solana wallet private keys, which is sensitive but not inherently malicious; no clear exfiltration or backdoor patterns were found. |
| accounts/evm/getBaseNodeRpcUrl.ts | medium | Code appears to be a legitimate API helper that authenticates with a JWT derived from API keys and calls a configured basePath, but lacks validation of config.basePath and silently swallows errors, presenting low-to-medium credential/SSRF exposure if config is attacker-influenced. |
| accounts/evm/resolveViemClients.ts | medium | No install-time or exfiltration code was found, but the module allows arbitrary user-supplied RPC URLs to be wired into a wallet client holding account credentials, creating SSRF and transaction-redirection risks if inputs are untrusted. |
| actions/evm/transfer/transferWithViem.ts | medium | The code performs ERC20 approvals and transfers as designed, but the redundant unlimited approval and lack of validation introduce medium-risk patterns that could be exploited in a malicious context; no direct exfiltration, obfuscation, or process execution was found. |
| analytics.ts | medium | Legitimate-looking analytics/telemetry code that automatically exfiltrates error details, stack traces, method names, and user-supplied properties to an external Coinbase endpoint by default, with only opt-out (not opt-in) controls. |
| auth/hooks/axios/withAuth.ts | medium | The interceptor performs expected auth header injection but has potential sensitive-data logging via debug flag and URL concatenation that could leak credentials to unintended hosts; no malicious exfiltration, backdoors, or install-time code found. |
Show 292 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| auth/index.ts | medium | The file appears to be a simple barrel export, but the security of the re-exported modules cannot be confirmed without reviewing their source code. |
| client/cdp.ts | medium | This appears to be the official Coinbase CDP SDK client; it reads credentials from environment variables and transmits telemetry/error analytics to external services (disableable via env vars), which are potential data-leak surfaces but are documented, legitimate SDK behaviors rather than overt malicious code. |
| client/end-user/endUser.ts | medium | No overt malicious patterns detected; the only concern is undocumented analytics tracking performed on every operation and reliance on an unshown Analytics module. |
| client/solana/solana.ts | medium | The code performs cryptographic operations and handles private keys with standard encryption, but the ability to override the RSA public key in importAccount introduces a medium-risk exfiltration vector; overall risk is warning due to potential misuse and telemetry. |
| index.ts | medium | The index file is a benign re-export surface but includes cryptocurrency-related modules whose underlying implementations should be audited for wallet-draining or import-time side effects. |
| openapi-client/generated/evm-accounts/evm-accounts.ts | medium | This is a standard orval-generated OpenAPI client for Coinbase's EVM account API; no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or install-time hooks were found, though the private-key export endpoints and unencoded path interpolation warrant a warning. |
| utils/export.ts | medium | The module provides legitimate RSA key generation/decryption and Solana key formatting utilities; no exfiltration, obfuscation, or backdoor patterns are present, but it handles raw private key material that requires careful downstream use. |
| _cjs/accounts/evm/chainToNetworkMapper.js | safe | Cleared by Jev triage; no further analysis needed |
| _cjs/accounts/evm/networkCapabilities.js | safe | No malicious patterns detected |
| _cjs/accounts/evm/networkToChainResolver.js | safe | No malicious patterns detected; the code is a standard CommonJS module that maps network identifiers to viem chain objects. |
| _cjs/accounts/evm/resolveViemClients.js | safe | No malicious patterns detected; the code is a legitimate utility for resolving viem clients from network identifiers or node URLs. |
| _cjs/accounts/evm/toEvmServerAccount.js | safe | The file defines a legitimate EVM server account wrapper with signing, transfer, and swap helpers; no malicious patterns such as exfiltration, credential harvesting, obfuscation, process spawning, or install-time execution were detected. |
| _cjs/accounts/evm/toNetworkScopedEvmServerAccount.js | safe | No malicious patterns detected; only standard telemetry analytics calls are present. |
| _cjs/accounts/evm/toNetworkScopedEvmSmartAccount.js | safe | No malicious patterns detected; the code is a standard EVM smart account wrapper that delegates to internal action modules and only sends analytics events for its own operations. |
| _cjs/accounts/evm/types.js | safe | No malicious patterns detected |
| _cjs/accounts/solana/toSolanaAccount.js | safe | The code is a standard Solana account wrapper that delegates to internal action modules and includes analytics tracking, with no malicious patterns detected. |
| _cjs/accounts/solana/types.js | safe | No malicious patterns detected |
| _cjs/actions/evm/getUserOperation.js | safe | The code only retrieves a user operation via the provided client and contains no malicious patterns, obfuscation, or suspicious activity. |
| _cjs/actions/evm/listSpendPermissions.js | safe | No malicious patterns detected |
| _cjs/actions/evm/listTokenBalances.js | safe | No malicious patterns detected |
| _cjs/actions/evm/requestFaucet.js | safe | No malicious patterns detected; the code is a straightforward wrapper for an EVM faucet API request with no suspicious behavior. |
| _cjs/actions/evm/sendTransaction.js | safe | No malicious patterns detected |
| _cjs/actions/evm/sendUserOperation.js | safe | The file is a standard Coinbase CDP SDK helper for sending EVM user operations; no obfuscation, credential harvesting, dynamic execution, or malicious patterns were found. |
| _cjs/actions/evm/signAndWrapTypedDataForSmartAccount.js | safe | No malicious patterns detected; the code implements documented EIP-712 signing and signature wrapping for Coinbase Smart Wallets using the viem library without any exfiltration, obfuscation, or dangerous operations. |
| _cjs/actions/evm/spend-permissions/account.use.js | safe | No malicious patterns detected |
| _cjs/actions/evm/spend-permissions/resolveSpendPermission.js | safe | No malicious patterns detected; the code performs standard input validation and spend permission resolution without exfiltration, credential harvesting, dynamic execution, or other suspicious behavior. |
| _cjs/actions/evm/spend-permissions/smartAccount.use.js | safe | No malicious patterns detected; the code performs standard EVM spend permission encoding and user operation sending without exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| _cjs/actions/evm/spend-permissions/types.js | safe | No malicious patterns detected |
| _cjs/actions/evm/swap/createSwapQuote.js | safe | No malicious patterns detected in the swap quote creation module; it performs expected validation, API calls, and transaction assembly without suspicious behavior. |
| _cjs/actions/evm/swap/getSwapPrice.js | safe | No malicious patterns detected; the file only performs a straightforward API call to fetch a swap price and maps the response without exfiltration, dynamic execution, or suspicious behavior. |
| _cjs/actions/evm/swap/sendSwapOperation.js | safe | No malicious patterns detected |
| _cjs/actions/evm/swap/sendSwapTransaction.js | safe | No malicious patterns detected; the code implements a legitimate swap transaction helper with standard blockchain interaction and no data exfiltration, credential harvesting, or dynamic code execution. |
| _cjs/actions/evm/swap/types.js | safe | No malicious patterns detected |
| _cjs/actions/evm/transfer/accountTransferStrategy.js | safe | No malicious patterns detected |
| _cjs/actions/evm/transfer/smartAccountTransferStrategy.js | safe | No malicious patterns detected; the code performs standard ERC20 and native token transfers via user operations without any exfiltration, obfuscation, or suspicious behavior. |
| _cjs/actions/evm/transfer/transfer.js | safe | No malicious patterns detected; the file contains only a straightforward transfer function with validation and delegation to a strategy, with no exfiltration, credential harvesting, obfuscation, or other red flags. |
| _cjs/actions/evm/transfer/types.js | safe | No malicious patterns detected; the code contains only simple validation and type-guard logic with a static import. |
| _cjs/actions/evm/transfer/utils.js | safe | Cleared by Jev triage; no further analysis needed |
| _cjs/actions/evm/types.js | safe | No malicious patterns detected |
| _cjs/actions/evm/waitForUserOperation.js | safe | No malicious patterns detected; the code implements a legitimate polling function for user operations in the Coinbase CDP SDK. |
| _cjs/actions/solana/constants.js | safe | The file contains only static string constants for Solana genesis hashes and USDC mint addresses, with no executable, network, filesystem, or obfuscated code. |
| _cjs/actions/solana/requestFaucet.js | safe | No malicious patterns detected; the code is a straightforward API wrapper for requesting Solana faucet funds with no exfiltration, credential harvesting, obfuscation, or process spawning. |
| _cjs/actions/solana/rpc.js | safe | No malicious patterns detected |
| _cjs/actions/solana/sendTransaction.js | safe | No malicious patterns detected |
| _cjs/actions/solana/signMessage.js | safe | No malicious patterns detected |
| _cjs/actions/solana/signTransaction.js | safe | The file is a straightforward API wrapper for signing Solana transactions with no malicious patterns, obfuscation, credential harvesting, or dynamic code execution. |
| _cjs/actions/solana/transfer.js | safe | No malicious patterns detected; the code implements standard Solana SOL and SPL token transfer logic using official Solana libraries and does not exhibit any of the specified red flags. |
| _cjs/actions/solana/types.js | safe | No malicious patterns detected |
| _cjs/actions/solana/utils.js | safe | No malicious patterns detected |
| _cjs/auth/errors.js | safe | No malicious patterns detected |
| _cjs/auth/hooks/axios/index.js | safe | No malicious patterns detected; the file only re-exports a module using standard TypeScript/CommonJS helper functions. |
| _cjs/auth/index.js | safe | No malicious patterns detected; the file contains only standard TypeScript CommonJS module re-export boilerplate. |
| _cjs/auth/utils/hash.js | safe | No malicious patterns detected |
| _cjs/auth/utils/http.js | safe | No malicious patterns detected; code appears to be legitimate HTTP authentication header generation logic. |
| _cjs/auth/utils/index.js | safe | No malicious patterns detected; this is a standard TypeScript re-export barrel file with no runtime logic beyond module re-exports. |
| _cjs/auth/utils/jwt.js | safe | No malicious patterns detected; the file implements standard JWT generation for Coinbase API authentication using the jose library without any data exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
| _cjs/auth/utils/ws.js | safe | No malicious patterns detected; the code simply generates JWT-based authentication headers for WebSocket connections using internal modules. |
| _cjs/client/end-user/endUser.js | safe | No malicious patterns detected; the code is a legitimate CDP end-user client using standard API calls with no exfiltration, obfuscation, or dangerous behaviors. |
| _cjs/client/end-user/endUser.types.js | safe | No malicious patterns detected |
| _cjs/client/evm/evm.js | safe | No malicious patterns detected; the code is a legitimate EVM client for interacting with Coinbase's CDP API, using standard cryptography and network calls. |
| _cjs/client/evm/evm.types.js | safe | No malicious patterns detected |
| _cjs/client/policies/index.js | safe | No malicious patterns detected |
| _cjs/client/policies/policies.js | safe | No malicious patterns detected |
| _cjs/client/policies/policies.types.js | safe | No malicious patterns detected |
| _cjs/client/solana/index.js | safe | No malicious patterns detected |
| _cjs/client/solana/solana.types.js | safe | No malicious patterns detected |
| _cjs/constants.js | safe | No malicious patterns detected; the file contains only a documentation URL constant and a public RSA key used for account import encryption. |
| _cjs/errors.js | safe | Cleared by Jev triage; no further analysis needed |
| _cjs/index.js | safe | No malicious patterns detected; the file is a standard CommonJS re-export barrel file with no executable logic or suspicious behavior. |
| _cjs/openapi-client/cdpApiClient.js | safe | No malicious patterns detected; this is a legitimate Coinbase CDP OpenAPI client setup file. |
| _cjs/openapi-client/errors.js | safe | Cleared by Jev triage; no further analysis needed |
| _cjs/openapi-client/generated/coinbaseDeveloperPlatformAPIs.schemas.js | safe | No malicious patterns detected; the file only exports static enum-like constants for API schemas. |
| _cjs/openapi-client/generated/end-user-accounts/end-user-accounts.js | safe | No malicious patterns detected |
| _cjs/openapi-client/generated/evm-smart-accounts/evm-smart-accounts.js | safe | This is a standard auto-generated OpenAPI client module containing only thin wrapper functions that delegate HTTP requests to the shared cdpApiClient, with no obfuscation, credential harvesting, code execution, or other malicious patterns detected. |
| _cjs/openapi-client/generated/evm-swaps/evm-swaps.js | safe | The code is a straightforward API client for EVM swap operations and contains no malicious patterns. |
| _cjs/openapi-client/generated/evm-token-balances/evm-token-balances.js | safe | No malicious patterns detected; the code is a simple API client function that makes a parameterized GET request to a Coinbase CDP endpoint. |
| _cjs/openapi-client/generated/faucets/faucets.js | safe | The file contains standard generated OpenAPI client functions for requesting testnet faucet funds, with no malicious patterns detected. |
| _cjs/openapi-client/generated/onchain-data/onchain-data.js | safe | No malicious patterns detected; the file only defines two API client wrapper functions for fetching onchain token data. |
| _cjs/openapi-client/generated/onramp/onramp.js | safe | This is a standard auto-generated OpenAPI client for Coinbase's Onramp API that delegates all network calls to a shared cdpApiClient helper with no malicious patterns detected. |
| _cjs/openapi-client/generated/policy-engine/policy-engine.js | safe | No malicious patterns detected |
| _cjs/openapi-client/generated/solana-accounts/solana-accounts.js | safe | This is a legitimate auto-generated OpenAPI client for Coinbase's CDP Solana accounts API; it contains only standard HTTP request wrappers delegating to a cdpApiClient and exhibits no malicious patterns. |
| _cjs/openapi-client/generated/solana-token-balances/solana-token-balances.js | safe | No malicious patterns detected |
| _cjs/openapi-client/generated/sql-api-alpha/sql-api-alpha.js | safe | No malicious patterns detected; the code is a straightforward API client wrapper for SQL query endpoints with no exfiltration, obfuscation, or suspicious behavior. |
| _cjs/openapi-client/generated/webhooks/webhooks.js | safe | No malicious patterns detected; the code is a straightforward OpenAPI-generated client for managing webhook subscriptions. |
| _cjs/openapi-client/generated/x402-facilitator/x402-facilitator.js | safe | No malicious patterns detected; the file contains straightforward API client wrapper functions for x402 payment operations. |
| _cjs/openapi-client/index.js | safe | No malicious patterns detected; the code is standard TypeScript-compiled CommonJS module re-exporting generated OpenAPI client modules. |
| _cjs/policies/evmSchema.js | safe | No malicious patterns detected; the file only defines Zod validation schemas for EVM policy rules without any network, filesystem, process, or dynamic code execution behavior. |
| _cjs/policies/solanaSchema.js | safe | No malicious patterns detected |
| _cjs/policies/types.js | safe | No malicious patterns detected; the file only defines Zod validation schemas for policy rules and bodies. |
| _cjs/spend-permissions/constants.js | safe | This file only exports a hardcoded Ethereum contract address and its ABI definition as static constants; no executable code, network calls, file access, environment harvesting, obfuscation, or other malicious patterns are present. |
| _cjs/spend-permissions/types.js | safe | No malicious patterns detected |
| _cjs/spend-permissions/utils.js | safe | The code is a simple utility function that resolves token addresses for a given network, with no malicious patterns detected. |
| _cjs/types/calls.js | safe | This file contains only a standard CommonJS module export marker and a source map URL comment, with no executable code or malicious patterns. |
| _cjs/types/contract.js | safe | No malicious patterns detected |
| _cjs/types/misc.js | safe | No malicious patterns detected in the provided JavaScript file. |
| _cjs/types/multicall.js | safe | No malicious patterns detected |
| _cjs/types/utils.js | safe | No malicious patterns detected |
| _cjs/utils/bigint.js | safe | Cleared by Jev triage; no further analysis needed |
| _cjs/utils/hash.js | safe | No malicious patterns detected |
| _cjs/utils/serializeTransaction.js | safe | The file is a simple wrapper around viem's serializeTransaction with no malicious patterns detected. |
| _cjs/utils/sortKeys.js | safe | Cleared by Jev triage; no further analysis needed |
| _cjs/utils/uuidV4.js | safe | Cleared by Jev triage; no further analysis needed |
| _cjs/utils/wait.js | safe | Cleared by Jev triage; no further analysis needed |
| _cjs/version.js | safe | No malicious patterns detected; the file only exports a static version string. |
| _esm/accounts/evm/chainToNetworkMapper.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/accounts/evm/getBaseNodeRpcUrl.js | safe | No malicious patterns detected; the code performs legitimate authenticated API requests using configured credentials to retrieve an RPC URL. |
| _esm/accounts/evm/networkCapabilities.js | safe | No malicious patterns detected; the file only defines static network capability flags and helper functions with no side effects, network calls, or dynamic code execution. |
| _esm/accounts/evm/networkToChainResolver.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/accounts/evm/toEvmSmartAccount.js | safe | The file defines a standard EVM smart account wrapper with built-in analytics tracking; no malicious exfiltration, credential harvesting, obfuscation, or process spawning was detected. |
| _esm/accounts/evm/toNetworkScopedEvmServerAccount.js | safe | The file implements a network-scoped EVM account wrapper with expected signing, transfer, and telemetry behavior; no malicious patterns such as exfiltration, credential harvesting, obfuscation, shell execution, or install-time payloads were detected. |
| _esm/accounts/evm/toNetworkScopedEvmSmartAccount.js | safe | The code is a legitimate wrapper for EVM smart account operations with standard analytics tracking and no malicious patterns. |
| _esm/accounts/evm/types.js | safe | No malicious patterns detected |
| _esm/accounts/solana/types.js | safe | No malicious patterns detected |
| _esm/actions/evm/getUserOperation.js | safe | No malicious patterns detected; the code is a straightforward async function retrieving a user operation via an injected client without exfiltration, credential access, dynamic execution, or other suspicious behavior. |
| _esm/actions/evm/listSpendPermissions.js | safe | No malicious patterns detected |
| _esm/actions/evm/listTokenBalances.js | safe | No malicious patterns detected; the code is a straightforward token balance listing function with no data exfiltration, credential harvesting, obfuscation, or other security concerns. |
| _esm/actions/evm/requestFaucet.js | safe | No malicious patterns detected |
| _esm/actions/evm/sendTransaction.js | safe | No malicious patterns detected |
| _esm/actions/evm/sendUserOperation.js | safe | No malicious patterns detected; the code is a legitimate SDK function for sending EVM user operations via the Coinbase CDP SDK. |
| _esm/actions/evm/signAndWrapTypedDataForSmartAccount.js | safe | No malicious patterns detected; the code only performs EIP-712 typed data hashing, signature wrapping for Coinbase Smart Wallets, and cryptographic signature formatting without any network, filesystem, process, or credential-harvesting activity. |
| _esm/actions/evm/spend-permissions/account.use.js | safe | No malicious patterns detected; the code performs a legitimate EVM transaction for spend permissions using viem and an API client without obfuscation, exfiltration, or dangerous operations. |
| _esm/actions/evm/spend-permissions/resolveSpendPermission.js | safe | No malicious patterns detected; the code only resolves spend permission parameters and generates a random salt using the Web Crypto API. |
| _esm/actions/evm/spend-permissions/types.js | safe | No malicious patterns detected |
| _esm/actions/evm/swap/createSwapQuote.js | safe | The file is a straightforward swap quote implementation for an EVM network that delegates API calls and transaction execution to internal modules without any malicious patterns such as data exfiltration, credential harvesting, obfuscation, or shell execution. |
| _esm/actions/evm/swap/getSwapPrice.js | safe | No malicious patterns detected in the swap price retrieval logic; it appears to be a standard API wrapper with no exfiltration, obfuscation, or dangerous operations. |
| _esm/actions/evm/swap/sendSwapOperation.js | safe | No malicious patterns detected; the code is a legitimate swap operation helper using viem and Coinbase SDK utilities. |
| _esm/actions/evm/swap/sendSwapTransaction.js | safe | No malicious patterns detected; the code is a legitimate swap transaction handler using viem and internal CDP client APIs without exfiltration, dynamic code execution, or filesystem/process manipulation. |
| _esm/actions/evm/swap/types.js | safe | No malicious patterns detected |
| _esm/actions/evm/transfer/accountTransferStrategy.js | safe | No malicious patterns detected; the code performs standard EVM token transfer transaction serialization and submission using viem. |
| _esm/actions/evm/transfer/smartAccountTransferStrategy.js | safe | No malicious patterns detected |
| _esm/actions/evm/transfer/transfer.js | safe | No malicious patterns detected |
| _esm/actions/evm/transfer/types.js | safe | No malicious patterns detected; the code only contains pure validation and type-guard functions with no I/O, network, shell, or dynamic execution behavior. |
| _esm/actions/evm/transfer/utils.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/actions/evm/types.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/actions/evm/waitForUserOperation.js | safe | No malicious patterns detected; the code only implements polling for user operation status via the provided CDP client. |
| _esm/actions/solana/constants.js | safe | No malicious patterns detected |
| _esm/actions/solana/requestFaucet.js | safe | No malicious patterns detected |
| _esm/actions/solana/rpc.js | safe | No malicious patterns detected; the code simply creates a Solana RPC client for mainnet or devnet using the official @solana/kit library. |
| _esm/actions/solana/sendTransaction.js | safe | This is a straightforward Solana transaction wrapper that delegates to a Coinbase API client with no malicious patterns detected. |
| _esm/actions/solana/signMessage.js | safe | No malicious patterns detected |
| _esm/actions/solana/signTransaction.js | safe | The code is a straightforward, non-obfuscated utility that delegates Solana transaction signing to the provided API client without any exfiltration, credential harvesting, dynamic execution, or other malicious patterns. |
| _esm/actions/solana/transfer.js | safe | No malicious patterns detected; the code performs standard Solana SOL and SPL token transfers using well-known libraries. |
| _esm/actions/solana/types.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/actions/solana/utils.js | safe | No malicious patterns detected; the code performs standard Solana network connection and USDC mint address lookup operations using only hardcoded constants and public RPC endpoints. |
| _esm/auth/errors.js | safe | No malicious patterns detected |
| _esm/auth/hooks/axios/index.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/auth/index.js | safe | This barrel file only re-exports local modules and contains no malicious patterns, dynamic code execution, or external data transfers. |
| _esm/auth/utils/hash.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/auth/utils/http.js | safe | No malicious patterns detected; the code generates authentication headers using local JWT utilities and does not perform any exfiltration or dangerous operations. |
| _esm/auth/utils/index.js | safe | No malicious patterns detected in this barrel file; it only re-exports from sibling modules without any executable logic. |
| _esm/auth/utils/jwt.js | safe | This is a legitimate Coinbase CDP SDK JWT generation module that uses standard cryptographic libraries (jose) for signing tokens with EC or Ed25519 keys, with no malicious patterns detected. |
| _esm/auth/utils/ws.js | safe | No malicious patterns detected; the module only generates authentication headers for WebSocket connections using standard JWT signing and correlation data. |
| _esm/client/end-user/endUser.types.js | safe | No malicious patterns detected |
| _esm/client/evm/evm.js | safe | No malicious patterns detected |
| _esm/client/evm/evm.types.js | safe | No malicious patterns detected |
| _esm/client/policies/index.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/client/policies/policies.js | safe | The file contains standard SDK client methods for policy management with first-party analytics tracking and input validation, and no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or backdoors were detected. |
| _esm/client/policies/policies.types.js | safe | No malicious patterns detected |
| _esm/client/solana/index.js | safe | No malicious patterns detected |
| _esm/client/solana/solana.js | safe | No malicious patterns detected; the code is a legitimate Solana client for Coinbase's CDP SDK performing expected account operations. |
| _esm/client/solana/solana.types.js | safe | No malicious patterns detected |
| _esm/constants.js | safe | No malicious patterns detected; the file only exports static constants including a public RSA encryption key and a documentation URL. |
| _esm/errors.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/index.js | safe | No malicious patterns detected; the file consists solely of static re-exports from internal modules and the viem library, with no executable top-level logic, network calls, credential access, or obfuscation. |
| _esm/openapi-client/cdpApiClient.js | safe | No malicious patterns detected; the code is a legitimate Coinbase CDP OpenAPI client with standard Axios request handling and error mapping. |
| _esm/openapi-client/errors.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/openapi-client/generated/coinbaseDeveloperPlatformAPIs.schemas.js | safe | No malicious patterns detected |
| _esm/openapi-client/generated/end-user-accounts/end-user-accounts.js | safe | This file only defines API client wrapper functions for Coinbase CDP end-user accounts, with no malicious patterns such as exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
| _esm/openapi-client/generated/evm-smart-accounts/evm-smart-accounts.js | safe | This is a standard auto-generated API client wrapper for EVM smart account operations; no malicious patterns, obfuscation, exfiltration, or process execution detected. |
| _esm/openapi-client/generated/evm-swaps/evm-swaps.js | safe | No malicious patterns detected; the file is a straightforward API client wrapper generating requests to a fixed CDP endpoint. |
| _esm/openapi-client/generated/evm-token-balances/evm-token-balances.js | safe | No malicious patterns detected |
| _esm/openapi-client/generated/faucets/faucets.js | safe | The file contains only benign API client wrapper functions for requesting testnet faucet funds, with no malicious patterns, credential harvesting, obfuscation, or unauthorized network/file/process activity. |
| _esm/openapi-client/generated/onchain-data/onchain-data.js | safe | No malicious patterns detected; the file only defines two API client wrapper functions making GET requests to a fixed internal CDP endpoint. |
| _esm/openapi-client/generated/onramp/onramp.js | safe | No malicious patterns detected |
| _esm/openapi-client/generated/policy-engine/policy-engine.js | safe | No malicious patterns detected; the file contains standard API client wrapper functions for a policy engine. |
| _esm/openapi-client/generated/solana-accounts/solana-accounts.js | safe | This file is a straightforward generated API client for Solana account operations that delegates all network calls to a shared cdpApiClient, with no malicious patterns, credential harvesting, obfuscation, or suspicious execution detected. |
| _esm/openapi-client/generated/solana-token-balances/solana-token-balances.js | safe | No malicious patterns detected |
| _esm/openapi-client/generated/sql-api-alpha/sql-api-alpha.js | safe | The file contains simple API client wrappers for SQL query endpoints with no malicious patterns, obfuscation, credential harvesting, or suspicious behavior. |
| _esm/openapi-client/generated/webhooks/webhooks.js | safe | This file contains standard OpenAPI client wrapper functions for Coinbase CDP webhook subscription management with no malicious patterns, obfuscation, or exfiltration behavior. |
| _esm/openapi-client/generated/x402-facilitator/x402-facilitator.js | safe | No malicious patterns detected; the file only defines straightforward API client wrappers for x402 payment verify/settle/supported endpoints without exfiltration, credential access, obfuscation, or lifecycle execution. |
| _esm/openapi-client/index.js | safe | No malicious patterns detected; the file only re-exports generated SDK modules and defines API client aggregations. |
| _esm/policies/evmSchema.js | safe | No malicious patterns detected |
| _esm/policies/solanaSchema.js | safe | The file contains only Zod schema definitions for Solana policy validation, with no malicious patterns, execution logic, network calls, or filesystem access detected. |
| _esm/policies/types.js | safe | No malicious patterns detected; the file contains only Zod schema definitions for policy validation. |
| _esm/spend-permissions/constants.js | safe | The file contains only a hardcoded Ethereum contract address and its ABI definitions; no malicious patterns, dynamic execution, network calls, or exfiltration behavior were detected. |
| _esm/spend-permissions/types.js | safe | No malicious patterns detected |
| _esm/spend-permissions/utils.js | safe | No malicious patterns detected |
| _esm/types/calls.js | safe | No malicious patterns detected |
| _esm/types/contract.js | safe | No malicious patterns detected |
| _esm/types/misc.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/types/multicall.js | safe | No malicious patterns detected |
| _esm/types/utils.js | safe | No malicious patterns detected |
| _esm/utils/bigint.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/utils/hash.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/utils/serializeTransaction.js | safe | No malicious patterns detected |
| _esm/utils/sortKeys.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/utils/uuidV4.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/utils/wait.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/version.js | safe | Cleared by Jev triage; no further analysis needed |
| accounts/evm/chainToNetworkMapper.ts | safe | Cleared by Jev triage; no further analysis needed |
| accounts/evm/networkCapabilities.ts | safe | No malicious patterns detected |
| accounts/evm/networkToChainResolver.ts | safe | Cleared by Jev triage; no further analysis needed |
| accounts/evm/toEvmServerAccount.ts | safe | No malicious patterns detected; the file is a legitimate CDP SDK account wrapper with no data exfiltration, credential harvesting, obfuscated code, or suspicious behavior. |
| accounts/evm/toEvmSmartAccount.ts | safe | The file is a straightforward TypeScript module that constructs an EvmSmartAccount abstraction with analytics tracking and calls to internal action modules; no malicious patterns such as exfiltration, credential harvesting, obfuscation, process spawning, or import-time execution were detected. |
| accounts/evm/toNetworkScopedEvmServerAccount.ts | safe | No malicious patterns detected; the code appears to be a legitimate SDK for managing EVM accounts with optional analytics tracking. |
| accounts/evm/toNetworkScopedEvmSmartAccount.ts | safe | No malicious patterns detected; the code is a legitimate factory function for network-scoped EVM smart accounts with standard analytics and API calls. |
| accounts/evm/types.ts | safe | This TypeScript file contains only type definitions and imports for an EVM account SDK, with no executable code, I/O, network, or suspicious patterns. |
| accounts/solana/toSolanaAccount.ts | safe | The file is a straightforward account wrapper with analytics tracking and no evident malicious behavior, though the analytics telemetry is noted as a minor privacy consideration. |
| accounts/solana/types.ts | safe | No malicious patterns detected |
| actions/evm/getUserOperation.ts | safe | No malicious patterns detected |
| actions/evm/listSpendPermissions.ts | safe | No malicious patterns detected |
| actions/evm/listTokenBalances.ts | safe | The code is a straightforward API wrapper for listing EVM token balances with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
| actions/evm/requestFaucet.ts | safe | No malicious patterns detected; the code is a straightforward API wrapper for requesting testnet faucet funds. |
| actions/evm/sendTransaction.ts | safe | No malicious patterns detected; the code is a straightforward transaction-sending wrapper around the CDP OpenAPI client with no data exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
| actions/evm/sendUserOperation.ts | safe | No malicious patterns detected |
| actions/evm/signAndWrapTypedDataForSmartAccount.ts | safe | No malicious patterns detected |
| actions/evm/spend-permissions/account.use.ts | safe | The code is a straightforward wrapper for sending an EVM transaction via a CDP API client, with no obfuscation, data exfiltration, or other malicious patterns. |
| actions/evm/spend-permissions/resolveSpendPermission.ts | safe | No malicious patterns detected; the code is a straightforward input resolver for spend permissions using secure random salt generation and no network, filesystem, or dynamic execution behavior. |
| actions/evm/spend-permissions/smartAccount.use.ts | safe | No malicious patterns detected; the code is a straightforward spend permission transaction builder with no exfiltration, obfuscation, or suspicious behavior. |
| actions/evm/spend-permissions/types.ts | safe | No malicious patterns detected; the file contains only type definitions and imports with no executable code or suspicious behavior. |
| actions/evm/swap/createSwapQuote.ts | safe | No malicious patterns detected; the code is a straightforward swap quote implementation using a provided API client without exfiltration, credential harvesting, obfuscation, or system-level side effects. |
| actions/evm/swap/getSwapPrice.ts | safe | No malicious patterns detected; the code is a straightforward API wrapper that delegates to the client's getEvmSwapPrice method. |
| actions/evm/swap/sendSwapOperation.ts | safe | The code is a legitimate swap operation helper that creates quotes, signs Permit2 typed data, and sends user operations without any malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or unauthorized file/network access. |
| actions/evm/swap/sendSwapTransaction.ts | safe | No malicious patterns detected; the code performs expected swap transaction logic using viem and internal CDP client calls without any data exfiltration, credential harvesting, obfuscation, or suspicious process/network/file operations. |
| actions/evm/swap/types.ts | safe | This file contains only TypeScript type definitions and interfaces for EVM swap operations with no executable logic or malicious patterns. |
| actions/evm/transfer/accountTransferStrategy.ts | safe | The code implements a standard EVM transfer strategy using viem for encoding and serializing transactions, with no malicious patterns, data exfiltration, or suspicious behavior. |
| actions/evm/transfer/smartAccountTransferStrategy.ts | safe | No malicious patterns detected; the code performs expected EVM token transfers using standard viem utilities and SDK helpers. |
| actions/evm/transfer/transfer.ts | safe | No malicious patterns detected; the code implements a straightforward token transfer utility with network validation and strategy delegation. |
| actions/evm/transfer/types.ts | safe | No malicious patterns detected |
| actions/evm/transfer/utils.ts | safe | Cleared by Jev triage; no further analysis needed |
| actions/evm/types.ts | safe | TypeScript file contains only type declarations and JSDoc for EVM actions with no executable, network, filesystem, or dynamic code patterns. |
| actions/evm/waitForUserOperation.ts | safe | No malicious patterns detected; the file implements a straightforward polling utility for EVM user operations using an injected API client. |
| actions/solana/constants.ts | safe | No malicious patterns detected |
| actions/solana/requestFaucet.ts | safe | No malicious patterns detected |
| actions/solana/rpc.ts | safe | The file only creates a Solana RPC client pointing to official Solana public endpoints with no malicious patterns detected. |
| actions/solana/sendTransaction.ts | safe | The code is a straightforward wrapper that forwards Solana transaction options to an API client without any malicious patterns. |
| actions/solana/signMessage.ts | safe | The file is a straightforward thin wrapper that delegates message signing to an injected API client, with no network, filesystem, process, or obfuscation red flags. |
| actions/solana/signTransaction.ts | safe | The code is a straightforward wrapper that delegates transaction signing to an injected API client, with no malicious patterns such as credential harvesting, code execution, or data exfiltration. |
| actions/solana/transfer.ts | safe | No malicious patterns detected; the code performs standard Solana SOL/SPL token transfers without exfiltration, credential harvesting, obfuscation, or suspicious system access. |
| actions/solana/types.ts | safe | No malicious patterns detected; the file only contains TypeScript type definitions and documentation comments for Solana account actions. |
| actions/solana/utils.ts | safe | No malicious patterns detected; the code only establishes Solana network connections and returns standard mint addresses without exfiltration, obfuscation, or privileged operations. |
| auth/errors.ts | safe | No malicious patterns detected |
| auth/hooks/axios/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| auth/utils/hash.ts | safe | Cleared by Jev triage; no further analysis needed |
| auth/utils/http.ts | safe | No malicious patterns detected; the code is a legitimate authentication header generator for the Coinbase CDP SDK. |
| auth/utils/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| auth/utils/jwt.ts | safe | No malicious patterns detected; the code is a legitimate JWT utility for Coinbase API authentication with no data exfiltration, credential harvesting, obfuscation, or other security concerns. |
| auth/utils/ws.ts | safe | No malicious patterns detected; the code legitimately generates JWT auth headers for WebSocket connections using local imports only. |
| client/end-user/endUser.types.ts | safe | Cleared by Jev triage; no further analysis needed |
| client/evm/evm.ts | safe | No malicious patterns detected; the code is a legitimate CDP EVM client SDK using standard crypto and API calls. |
| client/evm/evm.types.ts | safe | This file contains only TypeScript type definitions, interfaces, and type aliases with no executable code, network calls, file system access, or other malicious patterns. |
| client/policies/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| client/policies/policies.ts | safe | No malicious patterns detected; the code is a legitimate API client for managing CDP policies with only analytics tracking and schema validation. |
| client/policies/policies.types.ts | safe | Cleared by Jev triage; no further analysis needed |
| client/solana/index.ts | safe | No malicious patterns detected |
| client/solana/solana.types.ts | safe | No malicious patterns detected |
| constants.ts | safe | No malicious patterns detected |
| errors.ts | safe | Cleared by Jev triage; no further analysis needed |
| openapi-client/cdpApiClient.ts | safe | No malicious patterns detected |
| openapi-client/errors.ts | safe | Cleared by Jev triage; no further analysis needed |
| openapi-client/generated/end-user-accounts/end-user-accounts.ts | safe | No malicious patterns detected; the file contains standard generated API client functions for the Coinbase Developer Platform with no data exfiltration, credential harvesting, obfuscation, or process spawning. |
| openapi-client/generated/evm-smart-accounts/evm-smart-accounts.ts | safe | No malicious patterns detected; the code is a standard OpenAPI-generated TypeScript client for Coinbase's EVM smart accounts API with no dynamic execution, credential harvesting, or exfiltration. |
| openapi-client/generated/evm-swaps/evm-swaps.ts | safe | No malicious patterns detected; this is a standard OpenAPI-generated TypeScript client for Coinbase's EVM swap endpoints that delegates HTTP requests to the shared cdpApiClient. |
| openapi-client/generated/evm-token-balances/evm-token-balances.ts | safe | No malicious patterns detected |
| openapi-client/generated/faucets/faucets.ts | safe | No malicious patterns detected |
| openapi-client/generated/onchain-data/onchain-data.ts | safe | No malicious patterns detected; the file contains standard generated OpenAPI client code for Coinbase Developer Platform API endpoints. |
| openapi-client/generated/onramp/onramp.ts | safe | The file contains only auto-generated OpenAPI client functions that delegate requests to an internal cdpApiClient module, with no malicious patterns detected |
| openapi-client/generated/policy-engine/policy-engine.ts | safe | No malicious patterns detected in this auto-generated API client code that only makes standard HTTP requests to Coinbase Developer Platform endpoints. |
| openapi-client/generated/solana-accounts/solana-accounts.ts | safe | No malicious patterns detected; this is an auto-generated OpenAPI client for Coinbase's Solana account API that only makes parameterized HTTP requests to a fixed base URL via cdpApiClient. |
| openapi-client/generated/solana-token-balances/solana-token-balances.ts | safe | No malicious patterns detected |
| openapi-client/generated/sql-api-alpha/sql-api-alpha.ts | safe | This is a benign auto-generated OpenAPI client that defines two API wrapper functions (runSQLQuery and getSQLGrammar) delegating to an internal cdpApiClient, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
| openapi-client/generated/webhooks/webhooks.ts | safe | This is a standard orval-generated OpenAPI client for Coinbase Developer Platform webhook subscriptions, with no malicious patterns or security concerns detected. |
| openapi-client/generated/x402-facilitator/x402-facilitator.ts | safe | No malicious patterns detected; the file contains standard OpenAPI-generated client wrappers for legitimate x402 payment endpoints and does not execute code at import time, harvest credentials, or perform suspicious network or filesystem operations. |
| openapi-client/index.ts | safe | No malicious patterns detected |
| policies/evmSchema.ts | safe | No malicious patterns detected; the file only defines Zod schemas and TypeScript types for EVM policy validation without any runtime side effects, network calls, or process execution. |
| policies/solanaSchema.ts | safe | No malicious patterns detected; the file contains only Zod schema definitions for validating Solana policy configuration data. |
| policies/types.ts | safe | No malicious patterns detected; the file contains only type definitions and Zod validation schemas with no executable, network, or filesystem side effects. |
| spend-permissions/constants.ts | safe | The file only contains a hardcoded contract address and its ABI definition; no executable logic, network calls, filesystem access, or malicious patterns are present. |
| spend-permissions/types.ts | safe | No malicious patterns detected in this TypeScript type definition file. |
| spend-permissions/utils.ts | safe | No malicious patterns detected |
| types/calls.ts | safe | No malicious patterns detected |
| types/contract.ts | safe | Cleared by Jev triage; no further analysis needed |
| types/misc.ts | safe | No malicious patterns detected |
| types/multicall.ts | safe | Cleared by Jev triage; no further analysis needed |
| types/utils.ts | safe | Cleared by Jev triage; no further analysis needed |
| utils/bigint.ts | safe | Cleared by Jev triage; no further analysis needed |
| utils/hash.ts | safe | Cleared by Jev triage; no further analysis needed |
| utils/serializeTransaction.ts | safe | No malicious patterns detected |
| utils/sortKeys.ts | safe | Cleared by Jev triage; no further analysis needed |
| utils/uuidV4.ts | safe | Cleared by Jev triage; no further analysis needed |
| utils/wait.ts | safe | Cleared by Jev triage; no further analysis needed |
| version.ts | safe | Cleared by Jev triage; no further analysis needed |
Scanned versions of @coinbase/cdp-sdk
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 1.39.0 | Needs review | 317 | Oct 4, 2026 |
Frequently asked questions
Is @coinbase/cdp-sdk safe to use?
No confirmed malware was found in @coinbase/cdp-sdk@1.39.0, but the review flagged 2 high, 43 medium, 53 low severity findings for risky patterns worth checking before you rely on it.
Does @coinbase/cdp-sdk contain malware?
No malware was identified in @coinbase/cdp-sdk@1.39.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @coinbase/cdp-sdk checked?
Togoder Security downloaded the published npm package and had an AI model read its 317 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @coinbase/cdp-sdk together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @coinbase/cdp-sdk@1.39.0, cost nothing.