Togoder security

npm package security report

@coinbase/cdp-sdk@1.39.0 security report

Risky patterns found that deserve a look.

Needs review Version 1.39.0 Files reviewed 317 Size 1.4 MB Scanned

Summary

Togoder Security scanned the npm package @coinbase/cdp-sdk@1.39.0 on Oct 4, 2026. An AI review of 317 source files produced 2 high, 43 medium, 53 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
2
high
43
medium
53
low

Findings 98

high

Unsafe ERC20 approval pattern

NPS-3477351717A2

The function calls 'approve' with the full transfer amount before executing 'transfer'. This is functionally redundant (a direct ERC20 transfer does not require prior approval) and creates an unnecessary allowance. If the 'to' address is an externally controlled contract, the approved amount could be spent via transferFrom, potentially draining the approved tokens. Although not overtly malicious, this pattern is suspicious and could be part of a wallet drainer or allow unintended token spending.

_cjs/actions/evm/transfer/transferWithViem.js:38
high

Private key / account material exposure risk

NPS-6E24E053E7F1

toAccount(options.account) converts an EvmAccount (likely containing a private key or signer) into a viem Account and binds it to a user-supplied RPC URL via walletClient. If the URL is attacker-controlled, the wallet client could be used to sign/send transactions to a malicious RPC endpoint, enabling asset loss.

accounts/evm/resolveViemClients.ts:178
medium

Dynamic URL construction from configuration

NPS-1D48599B60FB

The request host/path and final RPC URL are built dynamically from cdpApiClient.config.basePath and the network parameter without validation. A tampered basePath could redirect authenticated requests (including the JWT bearer token) to an attacker-controlled endpoint, leaking API credentials.

_cjs/accounts/evm/getBaseNodeRpcUrl.js:18
medium

Credential usage in network request

NPS-C2ADE3175736

The function reads API key ID and secret from a global config object, generates a JWT, and sends it in an Authorization header to a remote URL derived from config.basePath. While this appears to be legitimate authentication against a known CDP (Coinbase Developer Platform) API, it demonstrates handling of secrets and outbound authenticated requests. If config.basePath is attacker-controlled (e.g., via environment or misconfiguration), credentials could be exfiltrated to an arbitrary server.

_cjs/accounts/evm/getBaseNodeRpcUrl.js:21
medium

Telemetry/Analytics data collection

NPS-1B5F94B80ACD

The code integrates an Analytics.trackAction(...) call in every single one of the account's methods (transfer, listTokenBalances, sendUserOperation, waitForUserOperation, getUserOperation, requestFaucet, quoteSwap, swap, signTypedData, useSpendPermission, useNetwork). Each call collects behavioral/usage metadata including action names, account type, and network details. While this appears to be first-party telemetry from the SDK itself (not an obvious exfiltration to an attacker-controlled endpoint in this file), it silently profiles user actions on EVM smart accounts and may be phoned home to a remote server. Users should verify the implementation of the referenced Analytics module (../../analytics.js) to confirm whether it sends data externally and if it is appropriately disclosed/opt-out. This is a privacy/tracking concern rather than a clear malicious payload.

_cjs/accounts/evm/toEvmSmartAccount.js:44
medium

Potential lack of input validation

NPS-2E6637FCA637

The 'to' address and 'value' are used directly without validation or sanitization. If called with attacker-controlled input, it could result in transfers to malicious addresses. However, no direct exfiltration or backdoor is present.

_cjs/actions/evm/transfer/transferWithViem.js:20
medium

Data exfiltration / Analytics telemetry

NPS-744506BB9962

The module sends potentially sensitive data to an external analytics endpoint at https://cca-lite.coinbase.com/amp. This includes error messages, stack traces, method names, user identifiers (Analytics.identifier), and arbitrary 'action' properties that may contain RPC URLs (trackAction extracts hostname from network URLs). This telemetry is enabled by default and can only be disabled via environment variables (DISABLE_CDP_ERROR_REPORTING, DISABLE_CDP_USAGE_TRACKING). Sending stack traces and application identifiers to a third-party server represents a privacy/security concern, though it appears to be legitimate SDK telemetry for Coinbase.

_cjs/analytics.js:57
medium

Sensitive data logging

NPS-5FBBFD23C51B

When the debug option is enabled, the interceptor logs the complete request configuration including headers (which will contain the JWT Authorization header) and request/response bodies. This can leak API key secrets, wallet secrets, and JWT tokens to logs or console output.

_cjs/auth/hooks/axios/withAuth.js:55
medium

Telemetry/Analytics data collection

NPS-B7695AD71DA0

The client configures analytics with the API key ID and wraps core classes with error tracking, sending usage and error data to external servers (Coinbase CDP analytics). This is opt-out via environment variables but enabled by default.

_cjs/client/cdp.js:88
medium

Cryptographic/key handling

NPS-6AAA89C74ABC

exportAccount retrieves a private key from the remote Coinbase CDP API and decrypts it locally using an RSA private key generated in-process. The private key is returned to the caller. Legitimate for this SDK, but any exposure path for the decrypted private key is sensitive.

_cjs/client/solana/solana.js:62
medium

Cryptographic/key handling

NPS-041B6BC7FF1A

importAccount accepts a user-supplied private key (base58 or raw bytes), encrypts it with a public encryption key (either user-provided or a hardcoded ImportAccountPublicRSAKey constant), and ships the encrypted private key to the remote API. Legitimate for the SDK's purpose but represents private-key material explicitly routed off-device.

_cjs/client/solana/solana.js:128
medium

Sensitive private key material handling

NPS-7BCFA1011AC7

The module includes API functions for exporting EVM account private keys (exportEvmAccount, exportEvmAccountByName) and importing existing private keys (importEvmAccount), as well as transaction signing and sending endpoints. While these are legitimate documented Coinbase CDP SDK operations, the presence of private key export/import functionality represents inherently sensitive operations that could be abused if this package were trojanized or if credentials were exfiltrated. No actual exfiltration occurs within this file.

_cjs/openapi-client/generated/evm-accounts/evm-accounts.js:128
medium

Sensitive key material handling

NPS-88345C419481

The module decrypts and formats Solana private keys. While standard cryptographic operations, handling plaintext private keys increases risk if the module or its consumers are compromised, and misuse can enable wallet key extraction.

_cjs/utils/export.js:51
medium

User-controlled RPC endpoint executed as network request

NPS-DF42BE8BEDBB

resolveViemClients accepts an arbitrary networkOrNodeUrl string and, when it is not a known network identifier, passes it directly into http(nodeUrl) and immediately calls tempPublicClient.getChainId(). Any caller who controls that input can force outbound HTTP requests to an attacker-chosen host, enabling SSRF-style probing and leaking of the node's IP/User-Agent to arbitrary endpoints. Expected for a wallet library but worth noting given the arbitrary host.

_esm/accounts/evm/resolveViemClients.js:47
medium

Dynamic chain resolution from remote response

NPS-4C72849AE811

The chain used to build the wallet/public clients is derived from the remote RPC's chainId response (resolveNodeUrlToChain). If the attacker controls the RPC URL, they can return a chainId mapping to a legitimate viem chain but serve malicious chain metadata (e.g., altered contract addresses used by the wallet client).

_esm/accounts/evm/resolveViemClients.js:52
medium

Unvalidated External Input Passed to Signing

NPS-16D08A8ACF32

signTypedData spreads untrusted parameters.types into the EIP712 types object and forwards arbitrary domain/message to the apiClient without validation. A malicious caller could supply crafted typed-data payloads (e.g., Permit signatures) that, if confirmed by the user, could authorize token approvals. This is an API design concern rather than an installed backdoor.

_esm/accounts/evm/toEvmServerAccount.js
medium

Arbitrary user operation execution

NPS-614D5AC84792

useSpendPermission constructs and sends a user operation (sendUserOperation) using caller-supplied spendPermission and value. If spendPermission is not validated, an attacker controlling options could craft calldata that leads to unauthorized spending or interaction with the spend permission manager. This is a standard DeFi transaction path but lacks visible validation in this file.

_esm/actions/evm/spend-permissions/smartAccount.use.js:16
medium

Hardcoded contract address

NPS-046EE9387CF6

SPEND_PERMISSION_MANAGER_ADDRESS is imported from constants rather than being provided by the caller. The function sends a user operation to this hardcoded address with calldata that includes a caller-supplied spendPermission and value. If this address were malicious or compromised, funds/permissions could be redirected. While the address is not shown in this file, hardcoded target addresses in transaction-sending utilities warrant review.

_esm/actions/evm/spend-permissions/smartAccount.use.js:20
medium

approve-then-transfer pattern

NPS-98E5F0B85138

For ERC20 tokens, the code first sends an approve transaction allowing the recipient (to) to spend the sender's tokens, then immediately performs a transfer. This is unnecessary for a simple transfer and creates a temporary allowance for the recipient. If the recipient is malicious or the approval is not revoked, they could later drain the approved amount. This is a potentially dangerous anti-pattern, though common in some libraries.

_esm/actions/evm/transfer/transferWithViem.js:41
medium

Data exfiltration / analytics tracking

NPS-182000D40D6D

The module automatically sends analytics events (including error messages, stack traces, user_id, and arbitrary event properties) to an external server at https://cca-lite.coinbase.com/amp. While this appears to be an intentional SDK telemetry feature with an opt-out via DISABLE_CDP_ERROR_REPORTING / DISABLE_CDP_USAGE_TRACKING environment variables, it silently collects and transmits potentially sensitive error details and user identifiers to a third-party endpoint.

_esm/analytics.js:64
medium

Error stack trace exfiltration

NPS-02723BC90368

handleMethodError destructures message and stack from caught errors and forwards them to the external analytics endpoint, potentially leaking file paths, internal code structure, and sensitive runtime information.

_esm/analytics.js:265
medium

Credential/Secret Logging

NPS-41CA0BDFC0D4

When options.debug is enabled, the interceptor logs request and response details including all headers (which include Authorization/JWT and API key headers), request bodies, and response data to the console. This can leak credentials and sensitive data into logs, CI output, or shared terminals.

_esm/auth/hooks/axios/withAuth.js:62
medium

Sensitive Data Exposure in Error Logging

NPS-498A2A47B526

The response error interceptor logs response headers and data on errors when debug is enabled, which may expose authentication tokens, API keys, or sensitive payload/response content.

_esm/auth/hooks/axios/withAuth.js:78
medium

Credential / Environment Variable Access

NPS-63302A120C8C

Reads CDP_API_KEY_ID, CDP_API_KEY_SECRET, CDP_API_KEY_NAME, and CDP_WALLET_SECRET from process.env and passes them to CdpOpenApiClient.configure(). This is expected for an SDK that needs to authenticate against the CDP API, but it does mean the package has direct access to sensitive credential environment variables.

_esm/client/cdp.js:54
medium

Usage / Error Telemetry

NPS-AF2FF8677570

When DISABLE_CDP_ERROR_REPORTING and DISABLE_CDP_USAGE_TRACKING are not explicitly set to 'true', the code assigns the API key ID to Analytics.identifier and wraps CdpClient, EvmClient, SolanaClient, and PoliciesClient with error tracking. This enables telemetry that attaches the API key ID to analytics events and reports runtime errors to Coinbase. While this appears to be vendor-official coinbase/cdp-sdk behavior, it is data collection that occurs by default without explicit opt-in and should be reviewed for privacy/compliance implications.

_esm/client/cdp.js:94
medium

Signing/transaction endpoints exposed

NPS-4F6E6AC5B343

Functions such as sendEvmTransaction, signEvmTransaction, signEvmHash, and signEvmTypedData allow arbitrary transaction signing and broadcasting via the remote API. While expected for a wallet SDK, compromise of the API client or credentials could enable unauthorized signing of value-bearing transactions.

_esm/openapi-client/generated/evm-accounts/evm-accounts.js:78
medium

Sensitive private key export functions

NPS-EE3907FB669D

The module exposes exportEvmAccount and exportEvmAccountByName functions that retrieve an EVM account's private key from a remote API. If misused, these endpoints could facilitate private key exfiltration, though the functions themselves are legitimate CDP SDK API wrappers.

_esm/openapi-client/generated/evm-accounts/evm-accounts.js:123
medium

Cryptographic key handling with Solana wallet

NPS-E1D98AAF05BE

The code imports @solana/web3.js and manipulates Solana keypairs. The formatSolanaPrivateKey function takes a hex private key, derives a Solana Keypair, and encodes the full keypair (seed + public key) in base58 for import into wallet apps. While this may be legitimate for wallet export functionality, handling private keys in this manner is inherently sensitive and could be used to facilitate key theft or wallet draining if the private key source is attacker-controlled or exfiltrated.

_esm/utils/export.js:67
medium

Potential SSRF via config.basePath

NPS-9631D3AB8C35

The basePath is taken from a shared config object and directly interpolated into fetch URL without validation of scheme, host, or trust boundary. If an attacker can influence config.basePath, sensitive JWT (derived from apiKeySecret) could be sent to an attacker-controlled endpoint. The subsequent response (json.id) is also interpolated into a returned URL without validation.

accounts/evm/getBaseNodeRpcUrl.ts:21
medium

SSRF / outbound request to user-supplied URL

NPS-F84491FA7D15

resolveNodeUrlToChain creates a public client with http(nodeUrl) and immediately calls getChainId(), causing a server-side request to any user-supplied URL that passes isValidUrl. This can be abused for SSRF to internal services if input originates from untrusted sources.

accounts/evm/resolveViemClients.ts:56
medium

Dynamic chain resolution from remote data

NPS-454A2E2995DD

The chain is derived from getChainId() returned by a user-supplied RPC endpoint. A malicious RPC can return any chain ID, causing the wallet client to operate on an unintended chain, potentially leading to cross-chain replay or sending funds to the wrong network.

accounts/evm/resolveViemClients.ts:62
medium

Arbitrary RPC URL usage

NPS-0E67F47BAE4C

The function accepts arbitrary Node URLs via networkOrNodeUrl and constructs viem HTTP transports to those URLs. This allows the caller to direct RPC traffic and, more importantly, wallet-client signing/transaction submission to an attacker-controlled endpoint. While this is a legitimate feature for an EVM client resolver, it can enable phishing/traffic interception if the input is not strictly validated elsewhere.

accounts/evm/resolveViemClients.ts:174
medium

Unlimited token approval

NPS-F857BAB9A186

The code calls the ERC20 'approve' function with the user-supplied 'value' as the allowance before executing a 'transfer'. This grants the recipient (or spender) the approved amount directly on the token contract, creating an unnecessary and potentially dangerous approval window. In a standard transfer flow, 'approve' is not required and allowing an arbitrary spender to pull tokens is a common attack vector if the address or amount is not strictly controlled. This could be exploited to drain tokens if the transfer target is manipulated.

actions/evm/transfer/transferWithViem.ts:48
medium

data_exfiltration

NPS-13845B388620

The module sends telemetry data to an external endpoint 'https://cca-lite.coinbase.com/amp' via fetch POST. It transmits error messages, stack traces, method names, action names, account types, arbitrary 'properties' objects, project name, SDK version, and a user/identifier value. While this appears to be legitimate analytics, it is hidden/automatic in nature and captures potentially sensitive runtime data (including full stack traces and arbitrary user-provided properties).

analytics.ts
medium

automatic_monkey_patching / method wrapping

NPS-7FDA1C4001E8

wrapClassWithErrorTracking and wrapObjectMethodsWithErrorTracking mutate prototypes and object methods at runtime, replacing user-supplied methods with wrappers that automatically report errors (including stack traces and arguments context) to an external service without explicit user consent per-call. This is a form of automatic surveillance hooking.

analytics.ts
medium

sensitive_data_collection

NPS-8AA41983A9CD

Tracked error events include stack traces ('stack') which may contain file paths, function names, and other sensitive context. Action tracking passes through arbitrary properties (minus customRpcHost normalization), potentially leaking user-controlled data (e.g., amounts, addresses, tokens) to the external analytics service.

analytics.ts
medium

env_variable_opt_out_only

NPS-CE74C5211007

Telemetry is enabled by default and only disabled via environment variables (DISABLE_CDP_ERROR_REPORTING, DISABLE_CDP_USAGE_TRACKING). This means the package phone-homes silently unless the user takes explicit action.

analytics.ts
medium

URL Construction

NPS-52BE035A93AB

The fully qualified URL is built by string concatenation (axiosClient.getUri() + axiosConfig.url) before parsing with URL. If axiosConfig.url is an absolute URL, this could produce an unexpected host, potentially causing the Authorization header to be sent to an unintended destination (auth header leakage via SSRF-like behavior).

auth/hooks/axios/withAuth.ts:62
medium

Sensitive Data Logging

NPS-43B8E4C9122F

When debug mode is enabled, the request interceptor logs the full request config including Authorization headers (which contain JWT signed with the apiKeySecret) and the request body. Response interceptor likewise logs response headers and body. This can leak API keys, wallet secrets, and sensitive payloads to console/logs in production if debug is mistakenly enabled.

auth/hooks/axios/withAuth.ts:79
medium

Re-export of unknown modules

NPS-2340D8A15E6B

The file re-exports all members from ./utils/http.js, ./utils/jwt.js, and ./utils/ws.js, as well as importing ./hooks/axios/index.js. The actual content of these modules is not provided, so their behavior cannot be verified. If any of these modules contain malicious code (e.g., data exfiltration, credential harvesting, backdoors), it would be exposed via this barrel file. This pattern is common in supply chain attacks where a benign-looking index re-exports malicious submodules.

auth/index.ts
medium

Telemetry / analytics data reporting

NPS-9F54D3A71ECB

The code uses Analytics.identifier, setting it to the apiKeyId (a sensitive credential) and wraps multiple classes with error tracking. It sends usage/error data to external analytics servers unless explicitly disabled via DISABLE_CDP_ERROR_REPORTING or DISABLE_CDP_USAGE_TRACKING environment variables. Using the API key ID as an analytics identifier could leak credential-adjacent data to external endpoints. This is the official Coinbase SDK's known telemetry mechanism, so it is documented but still worth noting.

client/cdp.ts:116
medium

Error tracking wrappers on client classes

NPS-11C52BF6E9D8

Analytics.wrapClassWithErrorTracking is applied to CdpClient, EvmClient, SolanaClient, and PoliciesClient. This likely intercepts method calls and reports errors (and possibly arguments) to external analytics endpoints. Detailed error context could inadvertently include sensitive data such as API keys or wallet operation details.

client/cdp.ts:121
medium

Cryptographic operation with external/public key

NPS-82FAC6121776

The importAccount method encrypts a user-supplied private key using an RSA public key that can be overridden via the options parameter (options.encryptionPublicKey). An attacker who can control this parameter could specify their own public key and capture the user's private key. While the default key is a package constant, this override capability introduces a risk of key exfiltration if the caller is tricked or if the API is misused.

client/solana/solana.ts:237
medium

Private key export functionality

NPS-75010190D795

The file exposes functions exportEvmAccount and exportEvmAccountByName that export EVM account private keys. While this is expected CDP API functionality, it represents a high-value attack surface and should be documented with a clear security warning. The generated comments do mention storing the private key securely, but any code path able to call these functions could exfiltrate private keys if the surrounding client is compromised.

openapi-client/generated/evm-accounts/evm-accounts.ts:187
medium

Sensitive key material handling

NPS-64358F0A78EF

The formatSolanaPrivateKey function accepts a hex private key and constructs a full Solana secret key (seed + public key) for wallet import. While this is a legitimate utility, it processes raw private key material in memory and outputs it as base58. If this function is invoked with untrusted input or the resulting string is logged/transmitted, it could facilitate private key exposure. No exfiltration is present, but the function is a high-value target for misuse.

utils/export.ts:88
low

Silent error swallowing

NPS-CB7274523D4C

All exceptions in the try/catch are silently ignored with a bare catch returning undefined. This can hide network or authentication failures and complicate security monitoring, though it is not itself malicious.

_cjs/accounts/evm/getBaseNodeRpcUrl.js:36
low

analytics telemetry

NPS-DBC29B9BF3C6

The code sends analytics events (action names and account type) to an internal analytics module. This is expected telemetry for a wallet SDK, not data exfiltration to an external attacker-controlled server.

_cjs/accounts/evm/toEvmServerAccount.js
low

No install/import-time execution or dynamic code execution

NPS-1EE50DF5649D

No top-level side effects, eval/new Function, child_process/exec, filesystem manipulation, environment/credential harvesting, network calls outside the SDK's stated purpose, or dynamic require with computed input were found. Requires are static and refer to internal modules (.js relative paths).

_cjs/accounts/evm/toEvmSmartAccount.js
low

Implicit default-owner signing authority

NPS-DD3517E4D290

Several methods (quoteSwap, swap) hardcode signerAddress: this.owners[0].address and taker: this.address. If an attacker can influence options.owner at account creation time (e.g., via a supply-chain or config injection), the first owner becomes the implicit signing authority for all future swap/sign operations. This is a design risk worth scrutinizing in the surrounding toNetworkScopedEvmSmartAccount / sendSwapOperation modules.

_cjs/accounts/evm/toEvmSmartAccount.js:96
low

Telemetry/Analytics

NPS-2E8277C27A5E

The code calls Analytics.trackAction at various points (send_transaction, transfer, wait_for_transaction_receipt, list_token_balances, request_faucet, quote_swap, swap, use_spend_permission). This is telemetry that sends usage data to an external analytics service. While not inherently malicious, it is data exfiltration of operational metadata and may be a privacy concern depending on the package's policies.

_cjs/accounts/evm/toNetworkScopedEvmServerAccount.js
low

External network/API call to a third party

NPS-92926FC5908D

The function calls client.prepareUserOperation and client.sendUserOperation, which may ultimately route to Coinbase CDP API endpoints. The default paymasterUrl for 'base' network is resolved via getBaseNodeRpcUrl. This is expected SDK behavior for a blockchain user operation sender, but the paymasterUrl is supplied by the caller and could point to an attacker-controlled endpoint, though it is not exfiltration by itself.

_cjs/actions/evm/sendUserOperation.js:78
low

Cryptographic signing operation

NPS-39E3396678C7

Owner private key material (owner.sign) is used to sign a userOpHash. This is normal for a wallet SDK but implies access to signing keys. No key exfiltration is observed; only a hash signature is produced.

_cjs/actions/evm/sendUserOperation.js:82
low

Network request with mode: no-cors

NPS-2912F172DCCF

The fetch call uses mode: 'no-cors', which prevents the caller from reading responses and can be used to bypass CORS restrictions. While commonly used for fire-and-forget analytics, it can also be used for covert data transmission without visibility into the response. Combined with the external endpoint, this is a notable pattern.

_cjs/analytics.js:78
low

Monkey-patching / method interception at import/usage time

NPS-FF256D7E0DDD

wrapClassWithErrorTracking and wrapObjectMethodsWithErrorTracking dynamically replace all prototype/object methods with wrapped functions via Object.getOwnPropertyNames. This is executed when consumers call these functions, and the wrapped functions automatically capture errors (including stack traces and messages) and forward them to the external analytics service. This interception behavior could be abused to exfiltrate error context, though here it appears to be for legitimate error reporting.

_cjs/analytics.js:197
low

Sensitive data logging on errors

NPS-FAD1C9FDF5B9

Debug mode also logs response error details including headers and data, which may contain authentication tokens or sensitive response payloads in error scenarios.

_cjs/auth/hooks/axios/withAuth.js:79
low

Environment variable harvesting

NPS-5D2B1B6A9108

The constructor reads sensitive credentials from environment variables (CDP_API_KEY_ID, CDP_API_KEY_SECRET, CDP_WALLET_SECRET, CDP_API_KEY_NAME) and passes them to the API client configuration. While this is expected for an SDK, it involves handling sensitive keys.

_cjs/client/cdp.js:62
low

Analytics/telemetry

NPS-442D2EA98C30

Every public client method calls Analytics.trackAction(...) before performing the operation, and accounts returned are wrapped with Analytics.wrapObjectMethodsWithErrorTracking(account). This transmits usage telemetry to remote analytics infrastructure, which may include method names, account types, and network identifiers.

_cjs/client/solana/solana.js:47
low

External network dependency

NPS-268A78E86223

All key operations (createAccount, exportAccount, importAccount, signMessage, signTransaction, sendTransaction) delegate to CdpOpenApiClient, which communicates with an external Coinbase endpoint. Since this file handles private keys, users should be aware that key material and/or signing requests flow to a remote service.

_cjs/client/solana/solana.js:72
low

User-controlled URL path segments without encoding

NPS-B19D1EE29456

Address and name parameters are interpolated directly into URL paths (e.g., /v2/evm/accounts/${address}) without encodeURIComponent. While this is a common pattern in generated API clients, it could allow path traversal or request forgery against unintended endpoints if untrusted input is passed. This is a minor input-handling concern, not malicious.

_cjs/openapi-client/generated/evm-accounts/evm-accounts.js:47
low

Potential insecure RSA key generation

NPS-24D6277AC9B3

Generates 4096-bit RSA keys and returns base64-encoded PKCS1 DER private keys. Although not inherently malicious, exporting private keys as strings from a utility module can facilitate credential leakage if logs, telemetry, or error paths capture them.

_cjs/utils/export.js:17
low

Private key / account material passed into wallet client

NPS-AECFABFC4585

options.account is converted via toAccount() and embedded into createWalletClient. This is standard for signing flows, but if the account object contains a raw private key, this module would be a convenient sink for credential theft in a compromised dependency. No local exfiltration is present, but the acceptance surface is broad.

_esm/accounts/evm/resolveViemClients.js:113
low

Analytics/Telemetry

NPS-4C9523CF2DC2

Every signing and transaction method calls Analytics.trackAction, sending operational metadata (action type, account type, network, and account address implicitly via the account object) to an analytics endpoint. While not inherently malicious and consistent with legitimate SDK telemetry, it constitutes data collection that may be undesirable depending on the threat model.

_esm/accounts/evm/toEvmServerAccount.js
low

Credential/Key Handling via Remote API

NPS-C728DCC83627

All cryptographic signing operations (signMessage, sign, signTransaction, signTypedData) delegate to a remote apiClient rather than local key storage. This is a server-managed account design, not a drainer, but it means sensitive operations depend on a trusted external service and the code does not itself expose private keys.

_esm/accounts/evm/toEvmServerAccount.js
low

Telemetry / analytics tracking

NPS-EC3D962DE305

The module calls Analytics.trackAction() on every account method invocation, reporting action names and network properties. This appears to be first-party product telemetry (Coinbase CDP SDK), not exfiltration of secrets; no credentials, keys, or user data beyond account type and network are collected.

_esm/accounts/evm/toEvmSmartAccount.js
low

Network scoping logic

NPS-D80FFE40AC3C

The function resolves viem clients from a user-supplied network or RPC URL and delegates signing/sending to the underlying account. This is expected behavior for a network-scoped account wrapper and does not itself exfiltrate data or execute untrusted code.

_esm/accounts/evm/toNetworkScopedEvmServerAccount.js:20
low

Analytics tracking

NPS-4C65BB676548

The code calls Analytics.trackAction with action names, account type, and network properties before performing operations. This is telemetry, not credential/secret exfiltration, and does not transmit private keys, seed phrases, or sensitive file contents.

_esm/accounts/evm/toNetworkScopedEvmServerAccount.js:44
low

Analytics data collection

NPS-3C71D8013FDB

The code calls Analytics.trackAction for each operation, sending action names and account type properties to an analytics endpoint. This is a common, non-malicious pattern for usage telemetry but does constitute data exfiltration if the endpoint is external and not disclosed. However, no sensitive data like credentials or keys is included.

_esm/accounts/evm/toNetworkScopedEvmSmartAccount.js
low

User behavior tracking

NPS-3D2C2AB56350

The code uses an Analytics.trackAction function to track user actions (request_faucet, sign_message, sign_transaction, send_transaction, transfer) along with account type and network information. While this may be a legitimate analytics feature, it constitutes telemetry data collection that could be considered a privacy concern depending on how the collected data is used.

_esm/accounts/solana/toSolanaAccount.js
low

Import-time side effects / method wrapping

NPS-0E6696CC56F1

The module export objects (Analytics, AnalyticsDeprecated) and the wrapping functions modify prototypes and object methods at call sites. No top-level execution occurs beyond symbol/constant definitions, but the wrapping utilities intercept and redirect every class/object method through error-reporting wrappers that call sendEvent, effectively instrumenting arbitrary user classes for telemetry.

_esm/analytics.js
low

Potential SSRF / Unvalidated Request Targeting

NPS-9DC602A56799

The interceptor builds a fully qualified URL from axiosClient.getUri() concatenated with axiosConfig.url and sends authentication headers to the resulting host/path. If the axios client base URL or request URL is attacker-influenced, credentials could be sent to an unintended host. No allow-listing or host validation is present.

_esm/auth/hooks/axios/withAuth.js:22
low

Import-time Side Effects

NPS-5E25666B19B2

The module imports Analytics and openapi-client modules which may perform network/telemetry side effects. The constructor also performs environment and version checks and modifies shared static configuration (CdpOpenApiClient.configure) as a side effect of instantiation.

_esm/client/cdp.js
low

Telemetry/Analytics tracking

NPS-27EA7DA97AAF

The code imports and calls an internal Analytics.trackAction() function on every public method invocation (createEndUser, listEndUsers, validateAccessToken). While the analytics module is part of the same package and no data exfiltration to an external server is directly visible here, sending usage telemetry from a client-side SDK is a privacy concern that should be scrutinized (what data is collected and where it is sent).

_esm/client/end-user/endUser.js:24
low

Random identifier generation

NPS-9C88ABCB94C8

randomUUID() from Node's crypto module is used to generate user IDs. This is cryptographically appropriate and not a security concern.

_esm/client/end-user/endUser.js:24
low

Credential handling

NPS-DD49F5FBD361

validateAccessToken forwards the provided accessToken directly to the backend API client. The token is not logged or persisted in this file, which is good practice, but it does get passed through to CdpOpenApiClient without any local redaction or validation, so any weakness in that layer could expose credentials.

_esm/client/end-user/endUser.js:84
low

Data collection for analytics

NPS-073EC9D08939

The code sends action names and limited context (e.g., scope) to an internal Analytics module. This appears to be first-party telemetry for the CDP SDK, not exfiltration to an attacker-controlled server. No credentials, environment variables, or sensitive user data are collected.

_esm/client/policies/policies.js:56
low

Input validation using Zod

NPS-2BA574910557

CreatePolicyBodySchema.parse and UpdatePolicyBodySchema.parse are called to validate input; this is legitimate input validation and not dynamic code execution.

_esm/client/policies/policies.js:191
low

Path parameter interpolation without encoding

NPS-7BE0F23C14CA

Address and name values are interpolated directly into URL paths (e.g. /v2/evm/accounts/${address}) without URL encoding. A malicious or malformed address/name containing path traversal or special characters could alter the request target, potentially leading to unexpected API endpoints being hit.

_esm/openapi-client/generated/evm-accounts/evm-accounts.js:30
low

No obvious malicious patterns

NPS-D487270A8802

The code performs standard RSA key generation and decryption, and Solana key formatting. There is no evidence of data exfiltration, environment variable harvesting, obfuscation, dynamic code execution, mining, backdoors, suspicious network requests, file system manipulation, or process spawning. The cryptographic operations appear to be for legitimate export/decryption purposes.

_esm/utils/export.js
low

Credential-Based Network Request

NPS-7DA45DBE8D38

The function constructs an API key-based JWT (using apiKeyId and apiKeySecret from the config) and sends it via an Authorization header to a dynamically-derived URL from config.basePath. While this appears to be legitimate authentication to the CDP API, it represents credential usage in outbound network requests that could become exfiltration if config is attacker-controlled or basePath is tampered with.

accounts/evm/getBaseNodeRpcUrl.ts:31
low

Silent Error Swallowing

NPS-17D0DA53DF69

The catch block silently returns undefined, hiding failures including network errors or auth errors. This is not malicious per se but can mask misbehavior and complicate security auditing of the credential flow.

accounts/evm/getBaseNodeRpcUrl.ts:45
low

Analytics/Telemetry

NPS-608ACB1D9865

The code tracks user actions (send_transaction, transfer, wait_for_transaction_receipt, etc.) via an Analytics module. This is common in SDKs but could be a privacy concern if it sends data externally without consent. However, it only tracks action names and network/account type, not sensitive data.

accounts/evm/toNetworkScopedEvmServerAccount.ts:86
low

Analytics tracking

NPS-1564DBAA83AA

The code includes Analytics.trackAction calls that report action types and some account metadata (e.g., accountType, network) to an internal analytics system. This is not classic exfiltration of credentials or secrets but is telemetry that could be a privacy concern depending on policy. No external endpoints are hardcoded in this file.

accounts/solana/toSolanaAccount.ts
low

No malicious patterns

NPS-294EA9E95977

No obfuscation, eval/exec, environment variable harvesting, filesystem manipulation outside package scope, process spawning, dynamic imports, or wallet draining logic is present. The code simply constructs an account object with wrapper methods that delegate to imported actions.

accounts/solana/toSolanaAccount.ts
low

Missing validation / user confirmation

NPS-9D36C6CAFAD0

The function takes transfer arguments (recipient address, amount, token) from the caller and immediately submits transactions without any validation or confirmation. While this may be intentional for a library, it enables misuse where an attacker-controlled caller can initiate token approvals and transfers. The code does not verify that the token address is legitimate, that the recipient matches the intended one, or that the amount is within safe limits.

actions/evm/transfer/transferWithViem.ts:38
low

hardcoded_public_client_id

NPS-090F88D1C602

A hardcoded 'publicClientId' (54f2ee2fb3d2b901a829940d70fbfc13) is embedded and used to authenticate to the external analytics endpoint. This is expected for analytics but represents a fixed, non-user-configurable reporting channel.

analytics.ts
low

md5_usage

NPS-A7F29EE36B10

MD5 is used to generate an integrity 'checksum' for telemetry payloads. MD5 is cryptographically broken, though here it is not used for security purposes (just payload integrity), so risk is low.

analytics.ts
low

Credential Handling

NPS-6C0BABD8C9FC

API key secrets and optional wallet secrets are accepted as plain strings and passed through to getAuthHeaders. No validation or zeroization of secrets in memory. This is typical for auth libraries but warrants attention given the wallet secret handling.

auth/hooks/axios/withAuth.ts:36
low

Credential harvesting via environment variables

NPS-14401589F979

The constructor reads sensitive credentials (CDP_API_KEY_ID, CDP_API_KEY_NAME, CDP_API_KEY_SECRET, CDP_WALLET_SECRET) from environment variables. While this is a documented design pattern and expected behavior for SDK configuration, it involves accessing sensitive secrets from the process environment, which could be exploited if the package were compromised. This is standard behavior for the official Coinbase CDP SDK, not inherently malicious.

client/cdp.ts:76
low

Data exfiltration via analytics

NPS-7C7AE1750532

The client imports an Analytics module and calls Analytics.trackAction for each public method (createEndUser, listEndUsers, validateAccessToken). This collects telemetry about user operations. While this appears to be intentional SDK analytics rather than covert exfiltration, it does transmit usage data alongside operations without an explicit opt-out, and the Analytics implementation is not shown and could contain unexpected behavior.

client/end-user/endUser.ts:3
low

Cryptographic identifier generation

NPS-A723DCE04196

Uses crypto.randomUUID() to generate user IDs when not supplied. This is standard and safe, but worth noting as it involves identity material generated client-side.

client/end-user/endUser.ts:44
low

Sensitive data handling (cryptography)

NPS-7006BEB928B7

The module uses Node's crypto primitives (publicEncrypt with RSA-OAEP/SHA-256 and a decryptWithPrivateKey helper) to protect private keys during import/export. This is a legitimate cryptographic design, not a backdoor; no key material is exfiltrated to unintended destinations.

client/evm/evm.ts
low

Network communication to external API

NPS-4A51FE9006A8

All network calls go through the CDP OpenApiClient (Coinbase Developer Platform SDK). Endpoints are hardcoded/derived from the SDK configuration; no user-controllable URLs, eval, or dynamic imports are used to redirect traffic.

client/evm/evm.ts
low

Analytics tracking

NPS-BFD1BD8CCD56

Multiple methods call Analytics.trackAction, which may transmit usage data to external servers. While not inherently malicious, this constitutes data collection that could include sensitive metadata (e.g., action types, account types, network names). Users should be aware of this telemetry.

client/solana/solana.ts
low

Private key handling

NPS-18C65DA757F9

The exportAccount method generates an encryption key pair, sends the public key to the API, receives an encrypted private key, and decrypts it locally. This pattern is standard for secure key export, but it involves handling sensitive private key material in memory. No direct exfiltration is present, but the risk of improper memory handling or accidental logging exists.

client/solana/solana.ts:141
low

Import-time side effects / dynamic module namespace

NPS-1A0014858AD0

This file re-exports symbols from a 'spend-permissions' module and includes Ethereum-related utilities (viem parseEther/parseUnits, spend permission manager ABI/address). While no direct exfiltration, process spawning, or obfuscation is present in this index file, imported modules may execute top-level code on import. The presence of blockchain/wallet-related exports (SpendPermission, spendPermissionManagerAddress/Abi, parseEther) in a package warrants review of the underlying modules for wallet-draining or address-rewriting behavior, as these are common targets for supply-chain attacks. No malicious pattern is present in the shown code itself.

index.ts
low

Unvalidated URL path interpolation

NPS-885248D05FB6

User-supplied address/name values are interpolated directly into request URLs (e.g. /v2/evm/accounts/${address}, /v2/evm/accounts/by-name/${name}, /v2/evm/accounts/export/by-name/${name}) without visible encoding or validation in this module. If cdpApiClient does not URL-encode these segments, an attacker-controlled address/name could alter the request path, potentially causing requests to unintended endpoints on the API host (path traversal / SSRF-style issues within the API surface).

openapi-client/generated/evm-accounts/evm-accounts.ts:62
low

Signature oracle exposure

NPS-0CAF49105396

Functions signEvmHash, signEvmMessage, signEvmTypedData, and signEvmTransaction allow arbitrary 32-byte hashes, EIP-191 messages, EIP-712 typed data, and RLP-serialized transactions to be signed. The docs note the API does not validate unsigned transactions. This is expected for a signing SDK, but callers with access to this module can obtain valid signatures over attacker-chosen payloads, which is a significant capability worth surfacing explicitly.

openapi-client/generated/evm-accounts/evm-accounts.ts:133
low

Cryptographic parameter choice

NPS-0854122E8A46

The RSA private key is generated in PKCS1 DER format with 4096-bit modulus, which is acceptable. However, RSA-OAEP-SHA256 decryption is used on a PKCS1-formatted key, which is valid. No cryptographic weakness is directly introduced by this code, but storing/exporting unencrypted private keys in base64 is a sensitive operation that should be handled carefully by callers.

utils/export.ts:12

Files reviewed

FileVerdictWhat the reviewer saw
_cjs/accounts/evm/getBaseNodeRpcUrl.js medium The code is a legitimate-looking RPC URL resolver that authenticates with stored API credentials, but builds request URLs dynamically from configuration without validation, creating a potential credential-exfiltration vector if config.basePath is attacker-controlled.
_cjs/accounts/evm/toEvmSmartAccount.js medium The file is a benign-looking EVM smart account wrapper, but it silently instruments every user action with analytics telemetry and relies on owners[0] as an implicit signer—worth verifying the referenced Analytics and network-scoped modules before trusting it in production.
_cjs/actions/evm/transfer/transferWithViem.js medium The code contains a suspicious redundant ERC20 approve pattern that could lead to token drain, but no direct malicious patterns like exfiltration or backdoors were found.
_cjs/analytics.js medium This appears to be a legitimate Coinbase CDP SDK analytics module, but it performs default-on telemetry that transmits error stacks, identifiers, and action properties (potentially including RPC hostnames) to an external endpoint via no-cors fetch, raising privacy and data-exfiltration concerns.
_cjs/auth/hooks/axios/withAuth.js medium The code is a legitimate axios auth interceptor, but debug logging may expose JWT tokens and secrets in headers and bodies.
_cjs/client/cdp.js medium The code is a legitimate Coinbase CDP SDK client that handles API credentials and includes opt-out analytics/error tracking, posing moderate privacy concerns but no clear malicious patterns.
_cjs/client/solana/solana.js medium No malicious behavior detected: this is a legitimate Coinbase CDP Solana client that handles private keys as part of its documented functionality, though it performs external API calls and analytics telemetry that merit awareness.
_cjs/openapi-client/generated/evm-accounts/evm-accounts.js medium This is a generated Coinbase CDP API client for EVM account management; no malicious exfiltration, obfuscation, process spawning, or install-time execution was found, though it exposes legitimate but inherently sensitive private-key export/import operations.
_cjs/utils/export.js medium The code performs legitimate RSA key operations and Solana private key formatting but handles sensitive cryptographic key material, which presents a moderate security concern if misused or if the package is compromised.
_esm/accounts/evm/resolveViemClients.js medium No backdoors, exfiltration, or obfuscation found; the main concerns are SSRF-style arbitrary outbound requests and trust of remote RPC responses when a user-supplied node URL is used, both of which are expected behavior for an EVM client resolver but warrant review.
_esm/accounts/evm/toEvmServerAccount.js medium No malicious backdoor, exfiltration, or crypto-drainer patterns detected; the file contains legitimate SDK signing/transfer wrappers with extensive analytics tracking and remote signing delegation that warrant low-to-medium caution.
_esm/accounts/solana/toSolanaAccount.js medium The code wraps Solana account actions with analytics tracking, which is a minor privacy concern but no malicious patterns like data exfiltration, credential harvesting, or wallet draining were detected.
_esm/actions/evm/spend-permissions/smartAccount.use.js medium No clear malicious patterns (no exfiltration, credential harvesting, obfuscation, or process execution), but the function sends arbitrary user operations to a hardcoded contract address with caller-supplied permission data, which warrants trust verification of constants and input validation.
_esm/actions/evm/transfer/transferWithViem.js medium The code performs a standard EVM token transfer but uses an unnecessary approve-then-transfer pattern for ERC20 tokens, which could grant an unintended allowance to the recipient.
_esm/analytics.js medium The code contains intentional but potentially privacy-invasive telemetry that transmits error details, stack traces, and identifiers to an external Coinbase analytics endpoint; it is not overtly malicious but warrants scrutiny for data-leakage concerns.
_esm/auth/hooks/axios/withAuth.js medium No overtly malicious code (no exfiltration, shells, install-time hooks, or obfuscation), but debug logging can leak auth headers and response data, and URL construction lacks host validation.
_esm/client/cdp.js medium This appears to be the legitimate Coinbase CDP SDK client entrypoint; it reads standard CDP credential env vars and enables opt-out telemetry that includes the API key ID, which is a privacy concern but not evidence of malicious exfiltration.
_esm/client/end-user/endUser.js medium No clear malicious patterns were found; the file is a straightforward SDK client wrapper that forwards calls to a backend API client, though it does include built-in analytics tracking that warrants review of what is collected and transmitted.
_esm/openapi-client/generated/evm-accounts/evm-accounts.js medium No obfuscation, exfiltration, credential harvesting, or dynamic execution was found; the file is a straightforward OpenAPI client wrapper, but it exposes sensitive private-key export and signing endpoints that warrant caution.
_esm/utils/export.js medium The code handles cryptographic keys, including Solana wallet private keys, which is sensitive but not inherently malicious; no clear exfiltration or backdoor patterns were found.
accounts/evm/getBaseNodeRpcUrl.ts medium Code appears to be a legitimate API helper that authenticates with a JWT derived from API keys and calls a configured basePath, but lacks validation of config.basePath and silently swallows errors, presenting low-to-medium credential/SSRF exposure if config is attacker-influenced.
accounts/evm/resolveViemClients.ts medium No install-time or exfiltration code was found, but the module allows arbitrary user-supplied RPC URLs to be wired into a wallet client holding account credentials, creating SSRF and transaction-redirection risks if inputs are untrusted.
actions/evm/transfer/transferWithViem.ts medium The code performs ERC20 approvals and transfers as designed, but the redundant unlimited approval and lack of validation introduce medium-risk patterns that could be exploited in a malicious context; no direct exfiltration, obfuscation, or process execution was found.
analytics.ts medium Legitimate-looking analytics/telemetry code that automatically exfiltrates error details, stack traces, method names, and user-supplied properties to an external Coinbase endpoint by default, with only opt-out (not opt-in) controls.
auth/hooks/axios/withAuth.ts medium The interceptor performs expected auth header injection but has potential sensitive-data logging via debug flag and URL concatenation that could leak credentials to unintended hosts; no malicious exfiltration, backdoors, or install-time code found.
Show 292 more files
FileVerdictWhat the reviewer saw
auth/index.ts medium The file appears to be a simple barrel export, but the security of the re-exported modules cannot be confirmed without reviewing their source code.
client/cdp.ts medium This appears to be the official Coinbase CDP SDK client; it reads credentials from environment variables and transmits telemetry/error analytics to external services (disableable via env vars), which are potential data-leak surfaces but are documented, legitimate SDK behaviors rather than overt malicious code.
client/end-user/endUser.ts medium No overt malicious patterns detected; the only concern is undocumented analytics tracking performed on every operation and reliance on an unshown Analytics module.
client/solana/solana.ts medium The code performs cryptographic operations and handles private keys with standard encryption, but the ability to override the RSA public key in importAccount introduces a medium-risk exfiltration vector; overall risk is warning due to potential misuse and telemetry.
index.ts medium The index file is a benign re-export surface but includes cryptocurrency-related modules whose underlying implementations should be audited for wallet-draining or import-time side effects.
openapi-client/generated/evm-accounts/evm-accounts.ts medium This is a standard orval-generated OpenAPI client for Coinbase's EVM account API; no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or install-time hooks were found, though the private-key export endpoints and unencoded path interpolation warrant a warning.
utils/export.ts medium The module provides legitimate RSA key generation/decryption and Solana key formatting utilities; no exfiltration, obfuscation, or backdoor patterns are present, but it handles raw private key material that requires careful downstream use.
_cjs/accounts/evm/chainToNetworkMapper.js safe Cleared by Jev triage; no further analysis needed
_cjs/accounts/evm/networkCapabilities.js safe No malicious patterns detected
_cjs/accounts/evm/networkToChainResolver.js safe No malicious patterns detected; the code is a standard CommonJS module that maps network identifiers to viem chain objects.
_cjs/accounts/evm/resolveViemClients.js safe No malicious patterns detected; the code is a legitimate utility for resolving viem clients from network identifiers or node URLs.
_cjs/accounts/evm/toEvmServerAccount.js safe The file defines a legitimate EVM server account wrapper with signing, transfer, and swap helpers; no malicious patterns such as exfiltration, credential harvesting, obfuscation, process spawning, or install-time execution were detected.
_cjs/accounts/evm/toNetworkScopedEvmServerAccount.js safe No malicious patterns detected; only standard telemetry analytics calls are present.
_cjs/accounts/evm/toNetworkScopedEvmSmartAccount.js safe No malicious patterns detected; the code is a standard EVM smart account wrapper that delegates to internal action modules and only sends analytics events for its own operations.
_cjs/accounts/evm/types.js safe No malicious patterns detected
_cjs/accounts/solana/toSolanaAccount.js safe The code is a standard Solana account wrapper that delegates to internal action modules and includes analytics tracking, with no malicious patterns detected.
_cjs/accounts/solana/types.js safe No malicious patterns detected
_cjs/actions/evm/getUserOperation.js safe The code only retrieves a user operation via the provided client and contains no malicious patterns, obfuscation, or suspicious activity.
_cjs/actions/evm/listSpendPermissions.js safe No malicious patterns detected
_cjs/actions/evm/listTokenBalances.js safe No malicious patterns detected
_cjs/actions/evm/requestFaucet.js safe No malicious patterns detected; the code is a straightforward wrapper for an EVM faucet API request with no suspicious behavior.
_cjs/actions/evm/sendTransaction.js safe No malicious patterns detected
_cjs/actions/evm/sendUserOperation.js safe The file is a standard Coinbase CDP SDK helper for sending EVM user operations; no obfuscation, credential harvesting, dynamic execution, or malicious patterns were found.
_cjs/actions/evm/signAndWrapTypedDataForSmartAccount.js safe No malicious patterns detected; the code implements documented EIP-712 signing and signature wrapping for Coinbase Smart Wallets using the viem library without any exfiltration, obfuscation, or dangerous operations.
_cjs/actions/evm/spend-permissions/account.use.js safe No malicious patterns detected
_cjs/actions/evm/spend-permissions/resolveSpendPermission.js safe No malicious patterns detected; the code performs standard input validation and spend permission resolution without exfiltration, credential harvesting, dynamic execution, or other suspicious behavior.
_cjs/actions/evm/spend-permissions/smartAccount.use.js safe No malicious patterns detected; the code performs standard EVM spend permission encoding and user operation sending without exfiltration, credential harvesting, obfuscation, or suspicious behavior.
_cjs/actions/evm/spend-permissions/types.js safe No malicious patterns detected
_cjs/actions/evm/swap/createSwapQuote.js safe No malicious patterns detected in the swap quote creation module; it performs expected validation, API calls, and transaction assembly without suspicious behavior.
_cjs/actions/evm/swap/getSwapPrice.js safe No malicious patterns detected; the file only performs a straightforward API call to fetch a swap price and maps the response without exfiltration, dynamic execution, or suspicious behavior.
_cjs/actions/evm/swap/sendSwapOperation.js safe No malicious patterns detected
_cjs/actions/evm/swap/sendSwapTransaction.js safe No malicious patterns detected; the code implements a legitimate swap transaction helper with standard blockchain interaction and no data exfiltration, credential harvesting, or dynamic code execution.
_cjs/actions/evm/swap/types.js safe No malicious patterns detected
_cjs/actions/evm/transfer/accountTransferStrategy.js safe No malicious patterns detected
_cjs/actions/evm/transfer/smartAccountTransferStrategy.js safe No malicious patterns detected; the code performs standard ERC20 and native token transfers via user operations without any exfiltration, obfuscation, or suspicious behavior.
_cjs/actions/evm/transfer/transfer.js safe No malicious patterns detected; the file contains only a straightforward transfer function with validation and delegation to a strategy, with no exfiltration, credential harvesting, obfuscation, or other red flags.
_cjs/actions/evm/transfer/types.js safe No malicious patterns detected; the code contains only simple validation and type-guard logic with a static import.
_cjs/actions/evm/transfer/utils.js safe Cleared by Jev triage; no further analysis needed
_cjs/actions/evm/types.js safe No malicious patterns detected
_cjs/actions/evm/waitForUserOperation.js safe No malicious patterns detected; the code implements a legitimate polling function for user operations in the Coinbase CDP SDK.
_cjs/actions/solana/constants.js safe The file contains only static string constants for Solana genesis hashes and USDC mint addresses, with no executable, network, filesystem, or obfuscated code.
_cjs/actions/solana/requestFaucet.js safe No malicious patterns detected; the code is a straightforward API wrapper for requesting Solana faucet funds with no exfiltration, credential harvesting, obfuscation, or process spawning.
_cjs/actions/solana/rpc.js safe No malicious patterns detected
_cjs/actions/solana/sendTransaction.js safe No malicious patterns detected
_cjs/actions/solana/signMessage.js safe No malicious patterns detected
_cjs/actions/solana/signTransaction.js safe The file is a straightforward API wrapper for signing Solana transactions with no malicious patterns, obfuscation, credential harvesting, or dynamic code execution.
_cjs/actions/solana/transfer.js safe No malicious patterns detected; the code implements standard Solana SOL and SPL token transfer logic using official Solana libraries and does not exhibit any of the specified red flags.
_cjs/actions/solana/types.js safe No malicious patterns detected
_cjs/actions/solana/utils.js safe No malicious patterns detected
_cjs/auth/errors.js safe No malicious patterns detected
_cjs/auth/hooks/axios/index.js safe No malicious patterns detected; the file only re-exports a module using standard TypeScript/CommonJS helper functions.
_cjs/auth/index.js safe No malicious patterns detected; the file contains only standard TypeScript CommonJS module re-export boilerplate.
_cjs/auth/utils/hash.js safe No malicious patterns detected
_cjs/auth/utils/http.js safe No malicious patterns detected; code appears to be legitimate HTTP authentication header generation logic.
_cjs/auth/utils/index.js safe No malicious patterns detected; this is a standard TypeScript re-export barrel file with no runtime logic beyond module re-exports.
_cjs/auth/utils/jwt.js safe No malicious patterns detected; the file implements standard JWT generation for Coinbase API authentication using the jose library without any data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
_cjs/auth/utils/ws.js safe No malicious patterns detected; the code simply generates JWT-based authentication headers for WebSocket connections using internal modules.
_cjs/client/end-user/endUser.js safe No malicious patterns detected; the code is a legitimate CDP end-user client using standard API calls with no exfiltration, obfuscation, or dangerous behaviors.
_cjs/client/end-user/endUser.types.js safe No malicious patterns detected
_cjs/client/evm/evm.js safe No malicious patterns detected; the code is a legitimate EVM client for interacting with Coinbase's CDP API, using standard cryptography and network calls.
_cjs/client/evm/evm.types.js safe No malicious patterns detected
_cjs/client/policies/index.js safe No malicious patterns detected
_cjs/client/policies/policies.js safe No malicious patterns detected
_cjs/client/policies/policies.types.js safe No malicious patterns detected
_cjs/client/solana/index.js safe No malicious patterns detected
_cjs/client/solana/solana.types.js safe No malicious patterns detected
_cjs/constants.js safe No malicious patterns detected; the file contains only a documentation URL constant and a public RSA key used for account import encryption.
_cjs/errors.js safe Cleared by Jev triage; no further analysis needed
_cjs/index.js safe No malicious patterns detected; the file is a standard CommonJS re-export barrel file with no executable logic or suspicious behavior.
_cjs/openapi-client/cdpApiClient.js safe No malicious patterns detected; this is a legitimate Coinbase CDP OpenAPI client setup file.
_cjs/openapi-client/errors.js safe Cleared by Jev triage; no further analysis needed
_cjs/openapi-client/generated/coinbaseDeveloperPlatformAPIs.schemas.js safe No malicious patterns detected; the file only exports static enum-like constants for API schemas.
_cjs/openapi-client/generated/end-user-accounts/end-user-accounts.js safe No malicious patterns detected
_cjs/openapi-client/generated/evm-smart-accounts/evm-smart-accounts.js safe This is a standard auto-generated OpenAPI client module containing only thin wrapper functions that delegate HTTP requests to the shared cdpApiClient, with no obfuscation, credential harvesting, code execution, or other malicious patterns detected.
_cjs/openapi-client/generated/evm-swaps/evm-swaps.js safe The code is a straightforward API client for EVM swap operations and contains no malicious patterns.
_cjs/openapi-client/generated/evm-token-balances/evm-token-balances.js safe No malicious patterns detected; the code is a simple API client function that makes a parameterized GET request to a Coinbase CDP endpoint.
_cjs/openapi-client/generated/faucets/faucets.js safe The file contains standard generated OpenAPI client functions for requesting testnet faucet funds, with no malicious patterns detected.
_cjs/openapi-client/generated/onchain-data/onchain-data.js safe No malicious patterns detected; the file only defines two API client wrapper functions for fetching onchain token data.
_cjs/openapi-client/generated/onramp/onramp.js safe This is a standard auto-generated OpenAPI client for Coinbase's Onramp API that delegates all network calls to a shared cdpApiClient helper with no malicious patterns detected.
_cjs/openapi-client/generated/policy-engine/policy-engine.js safe No malicious patterns detected
_cjs/openapi-client/generated/solana-accounts/solana-accounts.js safe This is a legitimate auto-generated OpenAPI client for Coinbase's CDP Solana accounts API; it contains only standard HTTP request wrappers delegating to a cdpApiClient and exhibits no malicious patterns.
_cjs/openapi-client/generated/solana-token-balances/solana-token-balances.js safe No malicious patterns detected
_cjs/openapi-client/generated/sql-api-alpha/sql-api-alpha.js safe No malicious patterns detected; the code is a straightforward API client wrapper for SQL query endpoints with no exfiltration, obfuscation, or suspicious behavior.
_cjs/openapi-client/generated/webhooks/webhooks.js safe No malicious patterns detected; the code is a straightforward OpenAPI-generated client for managing webhook subscriptions.
_cjs/openapi-client/generated/x402-facilitator/x402-facilitator.js safe No malicious patterns detected; the file contains straightforward API client wrapper functions for x402 payment operations.
_cjs/openapi-client/index.js safe No malicious patterns detected; the code is standard TypeScript-compiled CommonJS module re-exporting generated OpenAPI client modules.
_cjs/policies/evmSchema.js safe No malicious patterns detected; the file only defines Zod validation schemas for EVM policy rules without any network, filesystem, process, or dynamic code execution behavior.
_cjs/policies/solanaSchema.js safe No malicious patterns detected
_cjs/policies/types.js safe No malicious patterns detected; the file only defines Zod validation schemas for policy rules and bodies.
_cjs/spend-permissions/constants.js safe This file only exports a hardcoded Ethereum contract address and its ABI definition as static constants; no executable code, network calls, file access, environment harvesting, obfuscation, or other malicious patterns are present.
_cjs/spend-permissions/types.js safe No malicious patterns detected
_cjs/spend-permissions/utils.js safe The code is a simple utility function that resolves token addresses for a given network, with no malicious patterns detected.
_cjs/types/calls.js safe This file contains only a standard CommonJS module export marker and a source map URL comment, with no executable code or malicious patterns.
_cjs/types/contract.js safe No malicious patterns detected
_cjs/types/misc.js safe No malicious patterns detected in the provided JavaScript file.
_cjs/types/multicall.js safe No malicious patterns detected
_cjs/types/utils.js safe No malicious patterns detected
_cjs/utils/bigint.js safe Cleared by Jev triage; no further analysis needed
_cjs/utils/hash.js safe No malicious patterns detected
_cjs/utils/serializeTransaction.js safe The file is a simple wrapper around viem's serializeTransaction with no malicious patterns detected.
_cjs/utils/sortKeys.js safe Cleared by Jev triage; no further analysis needed
_cjs/utils/uuidV4.js safe Cleared by Jev triage; no further analysis needed
_cjs/utils/wait.js safe Cleared by Jev triage; no further analysis needed
_cjs/version.js safe No malicious patterns detected; the file only exports a static version string.
_esm/accounts/evm/chainToNetworkMapper.js safe Cleared by Jev triage; no further analysis needed
_esm/accounts/evm/getBaseNodeRpcUrl.js safe No malicious patterns detected; the code performs legitimate authenticated API requests using configured credentials to retrieve an RPC URL.
_esm/accounts/evm/networkCapabilities.js safe No malicious patterns detected; the file only defines static network capability flags and helper functions with no side effects, network calls, or dynamic code execution.
_esm/accounts/evm/networkToChainResolver.js safe Cleared by Jev triage; no further analysis needed
_esm/accounts/evm/toEvmSmartAccount.js safe The file defines a standard EVM smart account wrapper with built-in analytics tracking; no malicious exfiltration, credential harvesting, obfuscation, or process spawning was detected.
_esm/accounts/evm/toNetworkScopedEvmServerAccount.js safe The file implements a network-scoped EVM account wrapper with expected signing, transfer, and telemetry behavior; no malicious patterns such as exfiltration, credential harvesting, obfuscation, shell execution, or install-time payloads were detected.
_esm/accounts/evm/toNetworkScopedEvmSmartAccount.js safe The code is a legitimate wrapper for EVM smart account operations with standard analytics tracking and no malicious patterns.
_esm/accounts/evm/types.js safe No malicious patterns detected
_esm/accounts/solana/types.js safe No malicious patterns detected
_esm/actions/evm/getUserOperation.js safe No malicious patterns detected; the code is a straightforward async function retrieving a user operation via an injected client without exfiltration, credential access, dynamic execution, or other suspicious behavior.
_esm/actions/evm/listSpendPermissions.js safe No malicious patterns detected
_esm/actions/evm/listTokenBalances.js safe No malicious patterns detected; the code is a straightforward token balance listing function with no data exfiltration, credential harvesting, obfuscation, or other security concerns.
_esm/actions/evm/requestFaucet.js safe No malicious patterns detected
_esm/actions/evm/sendTransaction.js safe No malicious patterns detected
_esm/actions/evm/sendUserOperation.js safe No malicious patterns detected; the code is a legitimate SDK function for sending EVM user operations via the Coinbase CDP SDK.
_esm/actions/evm/signAndWrapTypedDataForSmartAccount.js safe No malicious patterns detected; the code only performs EIP-712 typed data hashing, signature wrapping for Coinbase Smart Wallets, and cryptographic signature formatting without any network, filesystem, process, or credential-harvesting activity.
_esm/actions/evm/spend-permissions/account.use.js safe No malicious patterns detected; the code performs a legitimate EVM transaction for spend permissions using viem and an API client without obfuscation, exfiltration, or dangerous operations.
_esm/actions/evm/spend-permissions/resolveSpendPermission.js safe No malicious patterns detected; the code only resolves spend permission parameters and generates a random salt using the Web Crypto API.
_esm/actions/evm/spend-permissions/types.js safe No malicious patterns detected
_esm/actions/evm/swap/createSwapQuote.js safe The file is a straightforward swap quote implementation for an EVM network that delegates API calls and transaction execution to internal modules without any malicious patterns such as data exfiltration, credential harvesting, obfuscation, or shell execution.
_esm/actions/evm/swap/getSwapPrice.js safe No malicious patterns detected in the swap price retrieval logic; it appears to be a standard API wrapper with no exfiltration, obfuscation, or dangerous operations.
_esm/actions/evm/swap/sendSwapOperation.js safe No malicious patterns detected; the code is a legitimate swap operation helper using viem and Coinbase SDK utilities.
_esm/actions/evm/swap/sendSwapTransaction.js safe No malicious patterns detected; the code is a legitimate swap transaction handler using viem and internal CDP client APIs without exfiltration, dynamic code execution, or filesystem/process manipulation.
_esm/actions/evm/swap/types.js safe No malicious patterns detected
_esm/actions/evm/transfer/accountTransferStrategy.js safe No malicious patterns detected; the code performs standard EVM token transfer transaction serialization and submission using viem.
_esm/actions/evm/transfer/smartAccountTransferStrategy.js safe No malicious patterns detected
_esm/actions/evm/transfer/transfer.js safe No malicious patterns detected
_esm/actions/evm/transfer/types.js safe No malicious patterns detected; the code only contains pure validation and type-guard functions with no I/O, network, shell, or dynamic execution behavior.
_esm/actions/evm/transfer/utils.js safe Cleared by Jev triage; no further analysis needed
_esm/actions/evm/types.js safe Cleared by Jev triage; no further analysis needed
_esm/actions/evm/waitForUserOperation.js safe No malicious patterns detected; the code only implements polling for user operation status via the provided CDP client.
_esm/actions/solana/constants.js safe No malicious patterns detected
_esm/actions/solana/requestFaucet.js safe No malicious patterns detected
_esm/actions/solana/rpc.js safe No malicious patterns detected; the code simply creates a Solana RPC client for mainnet or devnet using the official @solana/kit library.
_esm/actions/solana/sendTransaction.js safe This is a straightforward Solana transaction wrapper that delegates to a Coinbase API client with no malicious patterns detected.
_esm/actions/solana/signMessage.js safe No malicious patterns detected
_esm/actions/solana/signTransaction.js safe The code is a straightforward, non-obfuscated utility that delegates Solana transaction signing to the provided API client without any exfiltration, credential harvesting, dynamic execution, or other malicious patterns.
_esm/actions/solana/transfer.js safe No malicious patterns detected; the code performs standard Solana SOL and SPL token transfers using well-known libraries.
_esm/actions/solana/types.js safe Cleared by Jev triage; no further analysis needed
_esm/actions/solana/utils.js safe No malicious patterns detected; the code performs standard Solana network connection and USDC mint address lookup operations using only hardcoded constants and public RPC endpoints.
_esm/auth/errors.js safe No malicious patterns detected
_esm/auth/hooks/axios/index.js safe Cleared by Jev triage; no further analysis needed
_esm/auth/index.js safe This barrel file only re-exports local modules and contains no malicious patterns, dynamic code execution, or external data transfers.
_esm/auth/utils/hash.js safe Cleared by Jev triage; no further analysis needed
_esm/auth/utils/http.js safe No malicious patterns detected; the code generates authentication headers using local JWT utilities and does not perform any exfiltration or dangerous operations.
_esm/auth/utils/index.js safe No malicious patterns detected in this barrel file; it only re-exports from sibling modules without any executable logic.
_esm/auth/utils/jwt.js safe This is a legitimate Coinbase CDP SDK JWT generation module that uses standard cryptographic libraries (jose) for signing tokens with EC or Ed25519 keys, with no malicious patterns detected.
_esm/auth/utils/ws.js safe No malicious patterns detected; the module only generates authentication headers for WebSocket connections using standard JWT signing and correlation data.
_esm/client/end-user/endUser.types.js safe No malicious patterns detected
_esm/client/evm/evm.js safe No malicious patterns detected
_esm/client/evm/evm.types.js safe No malicious patterns detected
_esm/client/policies/index.js safe Cleared by Jev triage; no further analysis needed
_esm/client/policies/policies.js safe The file contains standard SDK client methods for policy management with first-party analytics tracking and input validation, and no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or backdoors were detected.
_esm/client/policies/policies.types.js safe No malicious patterns detected
_esm/client/solana/index.js safe No malicious patterns detected
_esm/client/solana/solana.js safe No malicious patterns detected; the code is a legitimate Solana client for Coinbase's CDP SDK performing expected account operations.
_esm/client/solana/solana.types.js safe No malicious patterns detected
_esm/constants.js safe No malicious patterns detected; the file only exports static constants including a public RSA encryption key and a documentation URL.
_esm/errors.js safe Cleared by Jev triage; no further analysis needed
_esm/index.js safe No malicious patterns detected; the file consists solely of static re-exports from internal modules and the viem library, with no executable top-level logic, network calls, credential access, or obfuscation.
_esm/openapi-client/cdpApiClient.js safe No malicious patterns detected; the code is a legitimate Coinbase CDP OpenAPI client with standard Axios request handling and error mapping.
_esm/openapi-client/errors.js safe Cleared by Jev triage; no further analysis needed
_esm/openapi-client/generated/coinbaseDeveloperPlatformAPIs.schemas.js safe No malicious patterns detected
_esm/openapi-client/generated/end-user-accounts/end-user-accounts.js safe This file only defines API client wrapper functions for Coinbase CDP end-user accounts, with no malicious patterns such as exfiltration, credential harvesting, obfuscation, or dynamic code execution.
_esm/openapi-client/generated/evm-smart-accounts/evm-smart-accounts.js safe This is a standard auto-generated API client wrapper for EVM smart account operations; no malicious patterns, obfuscation, exfiltration, or process execution detected.
_esm/openapi-client/generated/evm-swaps/evm-swaps.js safe No malicious patterns detected; the file is a straightforward API client wrapper generating requests to a fixed CDP endpoint.
_esm/openapi-client/generated/evm-token-balances/evm-token-balances.js safe No malicious patterns detected
_esm/openapi-client/generated/faucets/faucets.js safe The file contains only benign API client wrapper functions for requesting testnet faucet funds, with no malicious patterns, credential harvesting, obfuscation, or unauthorized network/file/process activity.
_esm/openapi-client/generated/onchain-data/onchain-data.js safe No malicious patterns detected; the file only defines two API client wrapper functions making GET requests to a fixed internal CDP endpoint.
_esm/openapi-client/generated/onramp/onramp.js safe No malicious patterns detected
_esm/openapi-client/generated/policy-engine/policy-engine.js safe No malicious patterns detected; the file contains standard API client wrapper functions for a policy engine.
_esm/openapi-client/generated/solana-accounts/solana-accounts.js safe This file is a straightforward generated API client for Solana account operations that delegates all network calls to a shared cdpApiClient, with no malicious patterns, credential harvesting, obfuscation, or suspicious execution detected.
_esm/openapi-client/generated/solana-token-balances/solana-token-balances.js safe No malicious patterns detected
_esm/openapi-client/generated/sql-api-alpha/sql-api-alpha.js safe The file contains simple API client wrappers for SQL query endpoints with no malicious patterns, obfuscation, credential harvesting, or suspicious behavior.
_esm/openapi-client/generated/webhooks/webhooks.js safe This file contains standard OpenAPI client wrapper functions for Coinbase CDP webhook subscription management with no malicious patterns, obfuscation, or exfiltration behavior.
_esm/openapi-client/generated/x402-facilitator/x402-facilitator.js safe No malicious patterns detected; the file only defines straightforward API client wrappers for x402 payment verify/settle/supported endpoints without exfiltration, credential access, obfuscation, or lifecycle execution.
_esm/openapi-client/index.js safe No malicious patterns detected; the file only re-exports generated SDK modules and defines API client aggregations.
_esm/policies/evmSchema.js safe No malicious patterns detected
_esm/policies/solanaSchema.js safe The file contains only Zod schema definitions for Solana policy validation, with no malicious patterns, execution logic, network calls, or filesystem access detected.
_esm/policies/types.js safe No malicious patterns detected; the file contains only Zod schema definitions for policy validation.
_esm/spend-permissions/constants.js safe The file contains only a hardcoded Ethereum contract address and its ABI definitions; no malicious patterns, dynamic execution, network calls, or exfiltration behavior were detected.
_esm/spend-permissions/types.js safe No malicious patterns detected
_esm/spend-permissions/utils.js safe No malicious patterns detected
_esm/types/calls.js safe No malicious patterns detected
_esm/types/contract.js safe No malicious patterns detected
_esm/types/misc.js safe Cleared by Jev triage; no further analysis needed
_esm/types/multicall.js safe No malicious patterns detected
_esm/types/utils.js safe No malicious patterns detected
_esm/utils/bigint.js safe Cleared by Jev triage; no further analysis needed
_esm/utils/hash.js safe Cleared by Jev triage; no further analysis needed
_esm/utils/serializeTransaction.js safe No malicious patterns detected
_esm/utils/sortKeys.js safe Cleared by Jev triage; no further analysis needed
_esm/utils/uuidV4.js safe Cleared by Jev triage; no further analysis needed
_esm/utils/wait.js safe Cleared by Jev triage; no further analysis needed
_esm/version.js safe Cleared by Jev triage; no further analysis needed
accounts/evm/chainToNetworkMapper.ts safe Cleared by Jev triage; no further analysis needed
accounts/evm/networkCapabilities.ts safe No malicious patterns detected
accounts/evm/networkToChainResolver.ts safe Cleared by Jev triage; no further analysis needed
accounts/evm/toEvmServerAccount.ts safe No malicious patterns detected; the file is a legitimate CDP SDK account wrapper with no data exfiltration, credential harvesting, obfuscated code, or suspicious behavior.
accounts/evm/toEvmSmartAccount.ts safe The file is a straightforward TypeScript module that constructs an EvmSmartAccount abstraction with analytics tracking and calls to internal action modules; no malicious patterns such as exfiltration, credential harvesting, obfuscation, process spawning, or import-time execution were detected.
accounts/evm/toNetworkScopedEvmServerAccount.ts safe No malicious patterns detected; the code appears to be a legitimate SDK for managing EVM accounts with optional analytics tracking.
accounts/evm/toNetworkScopedEvmSmartAccount.ts safe No malicious patterns detected; the code is a legitimate factory function for network-scoped EVM smart accounts with standard analytics and API calls.
accounts/evm/types.ts safe This TypeScript file contains only type definitions and imports for an EVM account SDK, with no executable code, I/O, network, or suspicious patterns.
accounts/solana/toSolanaAccount.ts safe The file is a straightforward account wrapper with analytics tracking and no evident malicious behavior, though the analytics telemetry is noted as a minor privacy consideration.
accounts/solana/types.ts safe No malicious patterns detected
actions/evm/getUserOperation.ts safe No malicious patterns detected
actions/evm/listSpendPermissions.ts safe No malicious patterns detected
actions/evm/listTokenBalances.ts safe The code is a straightforward API wrapper for listing EVM token balances with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
actions/evm/requestFaucet.ts safe No malicious patterns detected; the code is a straightforward API wrapper for requesting testnet faucet funds.
actions/evm/sendTransaction.ts safe No malicious patterns detected; the code is a straightforward transaction-sending wrapper around the CDP OpenAPI client with no data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
actions/evm/sendUserOperation.ts safe No malicious patterns detected
actions/evm/signAndWrapTypedDataForSmartAccount.ts safe No malicious patterns detected
actions/evm/spend-permissions/account.use.ts safe The code is a straightforward wrapper for sending an EVM transaction via a CDP API client, with no obfuscation, data exfiltration, or other malicious patterns.
actions/evm/spend-permissions/resolveSpendPermission.ts safe No malicious patterns detected; the code is a straightforward input resolver for spend permissions using secure random salt generation and no network, filesystem, or dynamic execution behavior.
actions/evm/spend-permissions/smartAccount.use.ts safe No malicious patterns detected; the code is a straightforward spend permission transaction builder with no exfiltration, obfuscation, or suspicious behavior.
actions/evm/spend-permissions/types.ts safe No malicious patterns detected; the file contains only type definitions and imports with no executable code or suspicious behavior.
actions/evm/swap/createSwapQuote.ts safe No malicious patterns detected; the code is a straightforward swap quote implementation using a provided API client without exfiltration, credential harvesting, obfuscation, or system-level side effects.
actions/evm/swap/getSwapPrice.ts safe No malicious patterns detected; the code is a straightforward API wrapper that delegates to the client's getEvmSwapPrice method.
actions/evm/swap/sendSwapOperation.ts safe The code is a legitimate swap operation helper that creates quotes, signs Permit2 typed data, and sends user operations without any malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or unauthorized file/network access.
actions/evm/swap/sendSwapTransaction.ts safe No malicious patterns detected; the code performs expected swap transaction logic using viem and internal CDP client calls without any data exfiltration, credential harvesting, obfuscation, or suspicious process/network/file operations.
actions/evm/swap/types.ts safe This file contains only TypeScript type definitions and interfaces for EVM swap operations with no executable logic or malicious patterns.
actions/evm/transfer/accountTransferStrategy.ts safe The code implements a standard EVM transfer strategy using viem for encoding and serializing transactions, with no malicious patterns, data exfiltration, or suspicious behavior.
actions/evm/transfer/smartAccountTransferStrategy.ts safe No malicious patterns detected; the code performs expected EVM token transfers using standard viem utilities and SDK helpers.
actions/evm/transfer/transfer.ts safe No malicious patterns detected; the code implements a straightforward token transfer utility with network validation and strategy delegation.
actions/evm/transfer/types.ts safe No malicious patterns detected
actions/evm/transfer/utils.ts safe Cleared by Jev triage; no further analysis needed
actions/evm/types.ts safe TypeScript file contains only type declarations and JSDoc for EVM actions with no executable, network, filesystem, or dynamic code patterns.
actions/evm/waitForUserOperation.ts safe No malicious patterns detected; the file implements a straightforward polling utility for EVM user operations using an injected API client.
actions/solana/constants.ts safe No malicious patterns detected
actions/solana/requestFaucet.ts safe No malicious patterns detected
actions/solana/rpc.ts safe The file only creates a Solana RPC client pointing to official Solana public endpoints with no malicious patterns detected.
actions/solana/sendTransaction.ts safe The code is a straightforward wrapper that forwards Solana transaction options to an API client without any malicious patterns.
actions/solana/signMessage.ts safe The file is a straightforward thin wrapper that delegates message signing to an injected API client, with no network, filesystem, process, or obfuscation red flags.
actions/solana/signTransaction.ts safe The code is a straightforward wrapper that delegates transaction signing to an injected API client, with no malicious patterns such as credential harvesting, code execution, or data exfiltration.
actions/solana/transfer.ts safe No malicious patterns detected; the code performs standard Solana SOL/SPL token transfers without exfiltration, credential harvesting, obfuscation, or suspicious system access.
actions/solana/types.ts safe No malicious patterns detected; the file only contains TypeScript type definitions and documentation comments for Solana account actions.
actions/solana/utils.ts safe No malicious patterns detected; the code only establishes Solana network connections and returns standard mint addresses without exfiltration, obfuscation, or privileged operations.
auth/errors.ts safe No malicious patterns detected
auth/hooks/axios/index.ts safe Cleared by Jev triage; no further analysis needed
auth/utils/hash.ts safe Cleared by Jev triage; no further analysis needed
auth/utils/http.ts safe No malicious patterns detected; the code is a legitimate authentication header generator for the Coinbase CDP SDK.
auth/utils/index.ts safe Cleared by Jev triage; no further analysis needed
auth/utils/jwt.ts safe No malicious patterns detected; the code is a legitimate JWT utility for Coinbase API authentication with no data exfiltration, credential harvesting, obfuscation, or other security concerns.
auth/utils/ws.ts safe No malicious patterns detected; the code legitimately generates JWT auth headers for WebSocket connections using local imports only.
client/end-user/endUser.types.ts safe Cleared by Jev triage; no further analysis needed
client/evm/evm.ts safe No malicious patterns detected; the code is a legitimate CDP EVM client SDK using standard crypto and API calls.
client/evm/evm.types.ts safe This file contains only TypeScript type definitions, interfaces, and type aliases with no executable code, network calls, file system access, or other malicious patterns.
client/policies/index.ts safe Cleared by Jev triage; no further analysis needed
client/policies/policies.ts safe No malicious patterns detected; the code is a legitimate API client for managing CDP policies with only analytics tracking and schema validation.
client/policies/policies.types.ts safe Cleared by Jev triage; no further analysis needed
client/solana/index.ts safe No malicious patterns detected
client/solana/solana.types.ts safe No malicious patterns detected
constants.ts safe No malicious patterns detected
errors.ts safe Cleared by Jev triage; no further analysis needed
openapi-client/cdpApiClient.ts safe No malicious patterns detected
openapi-client/errors.ts safe Cleared by Jev triage; no further analysis needed
openapi-client/generated/end-user-accounts/end-user-accounts.ts safe No malicious patterns detected; the file contains standard generated API client functions for the Coinbase Developer Platform with no data exfiltration, credential harvesting, obfuscation, or process spawning.
openapi-client/generated/evm-smart-accounts/evm-smart-accounts.ts safe No malicious patterns detected; the code is a standard OpenAPI-generated TypeScript client for Coinbase's EVM smart accounts API with no dynamic execution, credential harvesting, or exfiltration.
openapi-client/generated/evm-swaps/evm-swaps.ts safe No malicious patterns detected; this is a standard OpenAPI-generated TypeScript client for Coinbase's EVM swap endpoints that delegates HTTP requests to the shared cdpApiClient.
openapi-client/generated/evm-token-balances/evm-token-balances.ts safe No malicious patterns detected
openapi-client/generated/faucets/faucets.ts safe No malicious patterns detected
openapi-client/generated/onchain-data/onchain-data.ts safe No malicious patterns detected; the file contains standard generated OpenAPI client code for Coinbase Developer Platform API endpoints.
openapi-client/generated/onramp/onramp.ts safe The file contains only auto-generated OpenAPI client functions that delegate requests to an internal cdpApiClient module, with no malicious patterns detected
openapi-client/generated/policy-engine/policy-engine.ts safe No malicious patterns detected in this auto-generated API client code that only makes standard HTTP requests to Coinbase Developer Platform endpoints.
openapi-client/generated/solana-accounts/solana-accounts.ts safe No malicious patterns detected; this is an auto-generated OpenAPI client for Coinbase's Solana account API that only makes parameterized HTTP requests to a fixed base URL via cdpApiClient.
openapi-client/generated/solana-token-balances/solana-token-balances.ts safe No malicious patterns detected
openapi-client/generated/sql-api-alpha/sql-api-alpha.ts safe This is a benign auto-generated OpenAPI client that defines two API wrapper functions (runSQLQuery and getSQLGrammar) delegating to an internal cdpApiClient, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
openapi-client/generated/webhooks/webhooks.ts safe This is a standard orval-generated OpenAPI client for Coinbase Developer Platform webhook subscriptions, with no malicious patterns or security concerns detected.
openapi-client/generated/x402-facilitator/x402-facilitator.ts safe No malicious patterns detected; the file contains standard OpenAPI-generated client wrappers for legitimate x402 payment endpoints and does not execute code at import time, harvest credentials, or perform suspicious network or filesystem operations.
openapi-client/index.ts safe No malicious patterns detected
policies/evmSchema.ts safe No malicious patterns detected; the file only defines Zod schemas and TypeScript types for EVM policy validation without any runtime side effects, network calls, or process execution.
policies/solanaSchema.ts safe No malicious patterns detected; the file contains only Zod schema definitions for validating Solana policy configuration data.
policies/types.ts safe No malicious patterns detected; the file contains only type definitions and Zod validation schemas with no executable, network, or filesystem side effects.
spend-permissions/constants.ts safe The file only contains a hardcoded contract address and its ABI definition; no executable logic, network calls, filesystem access, or malicious patterns are present.
spend-permissions/types.ts safe No malicious patterns detected in this TypeScript type definition file.
spend-permissions/utils.ts safe No malicious patterns detected
types/calls.ts safe No malicious patterns detected
types/contract.ts safe Cleared by Jev triage; no further analysis needed
types/misc.ts safe No malicious patterns detected
types/multicall.ts safe Cleared by Jev triage; no further analysis needed
types/utils.ts safe Cleared by Jev triage; no further analysis needed
utils/bigint.ts safe Cleared by Jev triage; no further analysis needed
utils/hash.ts safe Cleared by Jev triage; no further analysis needed
utils/serializeTransaction.ts safe No malicious patterns detected
utils/sortKeys.ts safe Cleared by Jev triage; no further analysis needed
utils/uuidV4.ts safe Cleared by Jev triage; no further analysis needed
utils/wait.ts safe Cleared by Jev triage; no further analysis needed
version.ts safe Cleared by Jev triage; no further analysis needed

Frequently asked questions

Is @coinbase/cdp-sdk safe to use?

No confirmed malware was found in @coinbase/cdp-sdk@1.39.0, but the review flagged 2 high, 43 medium, 53 low severity findings for risky patterns worth checking before you rely on it.

Does @coinbase/cdp-sdk contain malware?

No malware was identified in @coinbase/cdp-sdk@1.39.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @coinbase/cdp-sdk checked?

Togoder Security downloaded the published npm package and had an AI model read its 317 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @coinbase/cdp-sdk together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @coinbase/cdp-sdk@1.39.0, cost nothing.

Related security reports