Togoder security

npm package security report

@coinbase/wallet-sdk@4.3.6 security report

Risky patterns found that deserve a look.

Needs review Version 4.3.6 Files reviewed 98 Size 511.2 KB Scanned

Summary

Togoder Security scanned the npm package @coinbase/wallet-sdk@4.3.6 on Oct 4, 2026. An AI review of 98 source files produced 1 high, 19 medium, 39 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
1
high
19
medium
39
low

Findings 59

high

Sensitive Data Persistence in localStorage

NPS-BA436252BB0E

The store persists sensitive cryptographic material including keys, account, and spendPermissions to localStorage via createJSONStorage(() => localStorage). Any XSS vulnerability in the host application would allow an attacker to exfiltrate these credentials/wallet keys, leading to account compromise or fund theft. The partialize function explicitly includes the keys slice in persistence, meaning private keys or seed material may be stored in clear text in browser storage.

dist/store/store.js:60
medium

Telemetry / External Script Loading

NPS-B97756C20F59

The constructor and makeWeb3Provider method call loadTelemetryScript() which dynamically loads an external telemetry script from a Coinbase-controlled endpoint by default (when preference.telemetry is not false). This constitutes code that runs at import/instantiation time and performs network requests to an external server, potentially transmitting usage data without explicit user consent or transparency. While this is a known, documented feature of Coinbase Wallet SDK for analytics, it represents a data exfiltration vector that should be disclosed and can be disabled.

dist/CoinbaseWalletSDK.js:34
medium

Dynamic Module Loading

NPS-09E7F6A6D555

Telemetry script is loaded dynamically via loadTelemetryScript(), which likely injects a <script> tag or uses import() with a hardcoded but external URL. Dynamic loading of external code can be abused if the endpoint is compromised or if the URL is manipulated, leading to arbitrary code execution in the dapp context.

dist/CoinbaseWalletSDK.js:34
medium

Dynamic code execution

NPS-12B642B2394F

The code injects a script element with content from TELEMETRY_SCRIPT_CONTENT and appends it to the document head, causing immediate execution. While not using eval directly, this is a form of dynamic code execution that can be exploited if the content is attacker-controlled.

dist/core/telemetry/initCCA.js:11
medium

Data exfiltration

NPS-9DA09B474449

The code initializes a telemetry client that sends analytics data to an external endpoint 'https://cca-lite.coinbase.com' with a hardcoded Amplitude API key. It also collects and transmits a device identifier. This constitutes data exfiltration to a third-party server, which may be legitimate telemetry but is a privacy and security concern.

dist/core/telemetry/initCCA.js:37
medium

Telemetry data exfiltration risk

NPS-8EDBE3D74D5D

The logEvent function forwards SDK usage data to window.ClientAnalytics.logEvent, including appName, appOrigin (window.location.origin), sdkVersion, and arbitrary event payloads. While window.ClientAnalytics is an externally defined object (not directly imported), this represents a telemetry channel that could transmit sensitive application metadata and user interaction events to an external analytics service. The actual destination depends on how ClientAnalytics is initialized elsewhere, which is outside this file's scope.

dist/core/telemetry/logEvent.js:39
medium

Environment/context harvesting via global object

NPS-7EB593E338DB

The identify(event) function passes an arbitrary event object to window.ClientAnalytics.identify(), which in analytics SDKs commonly sends user identification data (user IDs, wallet addresses, preference options) to external servers. Combined with store.config.get().preference?.options being included in logEvent, sensitive configuration or preference data may be transmitted externally.

dist/core/telemetry/logEvent.js:44
medium

Data exfiltration / telemetry collection

NPS-5DE839AA56DD

The bundled script (Coinbase ClientAnalytics SDK) collects extensive user/device telemetry—device memory, hardware concurrency, network information (effectiveType, RTT, downlink, saveData), user agent/OS/browser fingerprint, storage estimates, session data, referrer/UTM parameters, and user IDs—and transmits it to Coinbase-controlled analytics endpoints (e.g., analytics-service-dev.cbhq.net, as.coinbase.com). This is intentional analytics behavior but represents a privacy-sensitive data collection pattern that should be scrutinized in a third-party dependency.

dist/core/telemetry/telemetry-content.js
medium

Environment / user data harvesting via IndexedDB and cookies

NPS-1FB2EC6EE1A8

The code reads/sets persistent data in IndexedDB ('keyval-store'), reads referrer and UTM/campaign params from the URL, and references an auth cookie ('logged_in') plus a JWT ('authorization' header). This is a broad harvesting of user-identifying and session data, though it targets the SDK's own storage rather than credential files like ~/.npmrc or ~/.ssh.

dist/core/telemetry/telemetry-content.js
medium

Suspicious network requests (sendBeacon / XHR / fetch to external endpoints)

NPS-5E3FF8843065

Telemetry is exfiltrated via navigator.sendBeacon, XMLHttpRequest, and fetch() to configurable API endpoints, with checksum of the payload signed using the amplitude API key. Endpoint is hardcoded to Coinbase domains but configurable via setConfig, meaning any consumer of this package could redirect telemetry.

dist/core/telemetry/telemetry-content.js
medium

Minified/obfuscated content in embedded string

NPS-BB5A62A103EB

The exported TELEMETRY_SCRIPT_CONTENT is a large minified JavaScript blob auto-generated by compile-assets.cjs. While this is a legitimate build artifact, embedding minified third-party code as a string reduces auditability and is a common vector for supply-chain attacks if the generator is compromised.

dist/core/telemetry/telemetry-content.js:4
medium

Cryptographic key management in third-party code

NPS-0691615C1E03

This module generates and stores P-256 keypairs using WebCryptoP256 (non-extractable) and WebAuthn-style signing bound to the origin 'https://keys.coinbase.com'. While it does not exfiltrate keys or send them over the network, it manages cryptographic material used for signing WebAuthn payloads. Any compromise of the storage layer (createStorage) or modification to this module could allow unauthorized signing on behalf of the user. The keys are stored via a storage abstraction whose security properties are not verifiable from this file alone, and keys are marked non-extractable which limits but does not eliminate risk.

dist/kms/crypto-key/index.js:21
medium

Local persistence of sensitive data

NPS-EF2351C4FFED

The createStorage function stores arbitrary key-value pairs in IndexedDB without encryption. If callers use it to persist cryptographic keys or other secrets, they will be stored in plaintext and remain accessible to any script running on the same origin (including third-party scripts and XSS).

dist/kms/crypto-key/storage.js:3
medium

Hardcoded chain ID

NPS-F8FE6C6D7EE0

The function uses a hardcoded chainId (84532) instead of the account's actual chain ID (account.chain.id). This could cause operations to be sent to the wrong network, potentially leading to asset loss or failed transactions if the wallet is connected to a different chain. While not inherently malicious, it is a dangerous practice.

dist/sign/scw/utils/handleAddSubAccountOwner.js:51
medium

Open redirect / deeplink manipulation

NPS-341277005B5D

The code constructs a URL to CBW_MOBILE_DEEPLINK_URL and appends the current page URL (redirect_url) and an optional walletLinkUrl (wl_url) as query parameters, then immediately navigates the user via a synthetic anchor click. If CBW_MOBILE_DEEPLINK_URL is attacker-controlled or the appended parameters are not validated, this could be used for redirect abuse or parameter injection into the Coinbase Wallet deeplink scheme.

dist/sign/walletlink/relay/ui/WLMobileRelayUI.js:16
medium

Wallet Key Management

NPS-7D699F2B2FCE

The code manages a keys slice and a spendPermissions slice, indicating it handles cryptocurrency wallet keys and spending permissions. While not inherently malicious, storing wallet keys in localStorage without encryption is a dangerous practice that could enable key theft if any script injection occurs.

dist/store/store.js:16
medium

Access to injected browser providers / global window state

NPS-E0869ED4D69D

Functions access globalThis.coinbaseWalletExtension, window.ethereum, and window.top.ethereum, and call setAppInfo on them. This reads and mutates host-page wallet provider state, which is sensitive and can be abused to manipulate wallet interactions if the module is compromised.

dist/util/provider.js:20
medium

Popup/Window Opener

NPS-838F2FCE39E3

The openPopup function uses window.open with a generated popup ID and appends SDK info (name, version, origin, COOP) as query parameters to the URL. While this is a legitimate wallet SDK pattern for authentication flows, opening external popups with dynamic parameters could potentially be abused if the URL is not validated to be same-origin or a trusted domain. However, no explicit URL validation is present in this file, meaning the caller must ensure the URL is trusted.

dist/util/web.js:24
medium

Data collection and exfiltration to external analytics endpoints

NPS-7DB31F3F5A8B

The package @cbhq/client-analytics (Coinbase Client Analytics SDK) collects extensive data including user IDs, device IDs, browser fingerprint data (user agent, screen dimensions, device memory, hardware concurrency), session information, page paths, referrer data, UTM parameters, and performance metrics. This data is transmitted to external endpoints such as https://as.coinbase.com/amp and https://analytics-service-dev.cbhq.net/amp via XHR, fetch, and navigator.sendBeacon. While this appears to be an intentional analytics SDK for Coinbase, the broad data collection and transmission to remote servers is a privacy concern and could be considered data exfiltration if used outside its intended context.

dist/vendor-js/CCA/ca.js
medium

Additional fingerprinting via UAParser

NPS-637EE91C914F

The bundle includes a UAParser library (module 353) that parses user agent strings to extract browser, engine, OS, device, and CPU architecture details. This is used for fingerprinting and analytics, which is a privacy concern but not malicious per se.

dist/vendor-js/CCA/ca.js
low

Environment / Browser Data Access

NPS-45528FC04D7B

The code uses getFavicon() to retrieve the current site's favicon and collects app metadata (appName, appLogoUrl, appChainIds) by default. This data is sent to the telemetry system and potentially to the wallet provider. While not credential harvesting, it does access browser/environment data automatically upon instantiation.

dist/CoinbaseWalletSDK.js:20
low

JSON parsing with unsanitized input

NPS-57248AC8908E

viemHttpErrorToProviderError parses JSON from error.details. While JSON.parse is generally safe against code execution, the resulting object fields (message, data) may be attacker-controlled and could lead to unexpected behavior if consumed unsafely downstream. This is a minor input validation concern, not a malicious pattern.

dist/core/error/errors.js:135
low

Telemetry Event Logging

NPS-C81986ABE7C4

The file defines functions that log analytics events for SCW signer handshake and request lifecycle (started, error, completed). It imports a store and logEvent utility, gathering context like method, correlationId, errorMessage, and enableAutoSubAccounts. No sensitive data exfiltration, credential harvesting, obfuscation, dynamic execution, or suspicious network/file/process operations are present. The logging appears to be standard product telemetry.

dist/core/telemetry/events/scw-signer.js
low

Code runs at import time

NPS-CE7A578302C7

The loadTelemetryScript function is exported and may be called during module import or initialization, leading to automatic telemetry setup and data transmission without explicit user consent.

dist/core/telemetry/initCCA.js:4
low

Global object dependency without validation

NPS-AF24A76F62E8

Both exported functions rely on window.ClientAnalytics without verifying its origin, integrity, or that it is a trusted, expected SDK instance. A malicious or compromised page script could override window.ClientAnalytics to intercept telemetry payloads, and this code would faithfully forward potentially sensitive data to it.

dist/core/telemetry/logEvent.js:38
low

Dynamic module loading with computed input

NPS-F50634E3633A

The bundle uses a custom webpack-style module loader with runtime-computed requires (n(2), n(353), n(762), etc.) and dynamic export assignment, plus UMD-style fallback attaching ClientAnalytics to the global object. This is normal bundler output but makes auditing harder and could mask malicious payloads in minified form.

dist/core/telemetry/telemetry-content.js
low

Telemetry/network exfiltration

NPS-8A1B5A85F396

The SDK conditionally loads a telemetry script via loadTelemetryScript() when options.preference.telemetry is not set to false. Telemetry can send usage data to external Coinbase servers, which is a potential privacy/data-exfiltration concern, though it is opt-out and part of the official Coinbase Wallet SDK design.

dist/createCoinbaseWalletSDK.js:42
low

Dynamic external resource loading

NPS-838AD6FC88AB

loadTelemetryScript dynamically loads an external script (telemetry init). If fetched from a remote origin without integrity verification, this could be an avenue for supply-chain injection, though here it is a first-party core module.

dist/createCoinbaseWalletSDK.js:42
low

Cryptowallet-related functionality

NPS-C82C224DBD4D

The module implements subaccount creation and owner-adding via EIP-1193 requests (wallet_addSubAccount, wallet_connect, wallet_sendCalls) and encodes ABI calls for on-chain owner management. This is expected wallet SDK behavior, not a drainer pattern, but warrants review to ensure no address rewriting or unauthorized signing occurs.

dist/createCoinbaseWalletSDK.js:60
low

Import-time side effect (storage initialization)

NPS-CC32F5F5904E

A storage instance is created at module top-level (export const storage = createStorage(...)), which executes on import. This is a common pattern but constitutes import-time side effect in third-party packages. It does not perform network or filesystem operations outside the storage scope visible here, but the actual behavior depends on createStorage which is not shown.

dist/kms/crypto-key/index.js:12
low

Hardcoded external origin / domain binding

NPS-5E1E945791FB

WebAuthn signing payloads are hardcoded to origin 'https://keys.coinbase.com'. This is expected for Coinbase SDK functionality but ties the cryptographic operations to a specific external domain; if this package were used outside that context or if the domain were spoofed, signatures could be produced for unintended relying parties.

dist/kms/crypto-key/index.js:52
low

Missing error handling / silent failure

NPS-AD518A21F810

getItem, setItem, and removeItem do not handle errors from idb-keyval. In a key-management context, a failed write or delete could leave stale or inconsistent key material, but no error is surfaced to the caller.

dist/kms/crypto-key/storage.js
low

Unvalidated storage scope and name

NPS-B3588054BBEE

The scope and name arguments are passed directly to createStore without validation, allowing callers to choose arbitrary IndexedDB database/object store names. This could be abused to interfere with other components or to persist data in unexpected locations.

dist/kms/crypto-key/storage.js:3
low

Encrypted remote communication

NPS-3281BE89FE32

The code sends encrypted requests to a popup communicator and fetches chain/RPC metadata, but uses standard cryptographic helpers and known SDK URLs rather than obvious exfiltration endpoints.

dist/sign/scw/SCWSigner.js
low

External RPC/network request

NPS-EDEC86F3F592

Unrecognized JSON-RPC requests are forwarded to a chain RPC URL, and coinbase_fetchPermissions calls the hardcoded CB_WALLET_RPC_URL; these are expected provider behaviors, not malicious exfiltration.

dist/sign/scw/SCWSigner.js
low

Wallet-related signer functionality

NPS-99DC01FAAEAA

This module implements a signer type selection and wallet link session handshake mechanism for a cryptocurrency wallet SDK (likely Coinbase Wallet SDK, given 'CBWSDK' namespace). It handles wallet connection types (SCW and WalletLink) but does not contain obvious exfiltration, credential harvesting, or key theft patterns. However, it is security-sensitive code managing wallet sessions and signer selection, which warrants scrutiny in a supply chain context.

dist/sign/util.js
low

Top-level storage initialization

NPS-94A57638AB87

Module-level instantiation of ScopedLocalStorage runs at import time. While not inherently malicious in this context, top-level side effects on import can be a concern if the storage scope is manipulated or if this is used to persist sensitive state unexpectedly.

dist/sign/util.js:5
low

Data exfiltration risk

NPS-3C42C9BCAB59

The code sends data to a Coinbase Wallet link server URL (linkAPIUrl). While this is expected for a wallet SDK, it includes broadcasting origin and location (location.origin, location.href) along with encrypted event data, which could be used for tracking or analytics. This is a privacy concern but not necessarily malicious.

dist/sign/walletlink/relay/connection/WalletLinkConnection.js
low

Environment and credential access

NPS-1BF8AA38EE83

The code uses session secrets and keys (session.secret, session.key) for encryption and authentication. While this is necessary for the SDK's functionality, it handles sensitive cryptographic material. However, no harvesting of external credentials (e.g., .npmrc, ~/.ssh) is observed.

dist/sign/walletlink/relay/connection/WalletLinkConnection.js
low

Dynamic code execution

NPS-F853C02A7661

No use of eval, Function constructor, or other dynamic code execution mechanisms was found.

dist/sign/walletlink/relay/connection/WalletLinkConnection.js
low

Suspicious network requests

NPS-4A2D553D271D

The code makes WebSocket connections and HTTP requests to a configurable linkAPIUrl. This is expected for a wallet connection SDK, but it could be a vector for data exfiltration if the URL is controlled by an attacker. No hardcoded suspicious external URLs were found.

dist/sign/walletlink/relay/connection/WalletLinkConnection.js
low

File system manipulation

NPS-5B59E753FD48

No file system operations (reading, writing, deleting files) were observed.

dist/sign/walletlink/relay/connection/WalletLinkConnection.js
low

Process spawning

NPS-209D33FC88C1

No spawning of child processes or shell commands was detected.

dist/sign/walletlink/relay/connection/WalletLinkConnection.js
low

Install-time execution

NPS-55624DBDB1DA

This is a library file, not a script that runs at install time. It is part of a larger package (likely @coinbase/wallet-sdk), and its import-time behavior is limited to class definition and constant initialization.

dist/sign/walletlink/relay/connection/WalletLinkConnection.js
low

Credential handling via Basic Auth

NPS-990AF2AFC057

The constructor encodes the session key into a Basic Authorization header. While not inherently malicious, this pattern could expose sensitive session material in network logs or if the endpoint is intercepted. It is a standard practice for some wallet relay protocols but warrants review.

dist/sign/walletlink/relay/connection/WalletLinkHTTP.js:6
low

Network requests to configurable endpoint

NPS-C934CC692084

The code sends authenticated POST and GET requests to a user‑provided linkAPIUrl. If an attacker can control this URL (e.g., via a compromised configuration), session data could be exfiltrated. However, this is expected functionality for a wallet relay client.

dist/sign/walletlink/relay/connection/WalletLinkHTTP.js:12
low

Credential storage in browser storage

NPS-3A05E0ADAD66

Session secret is stored in browser storage (localStorage/sessionStorage) via STORAGE_KEY_SESSION_SECRET. While this is a common pattern for session management, secrets stored in browser storage are accessible to any JavaScript running on the same origin, which could be a concern if there is an XSS vulnerability. However, this is not a malicious pattern and is standard for such SDKs.

dist/sign/walletlink/relay/type/WalletLinkSession.js:45
low

Synthetic user interaction / popup bypass

NPS-5139B989FDA9

A synthetic anchor element is created and clicked programmatically to navigate to an external deeplink, and a setTimeout is used to trigger a second redirect dialog. This pattern bypasses expected user interaction and could be abused to force navigation without explicit consent.

dist/sign/walletlink/relay/ui/WLMobileRelayUI.js:24
low

Inline SVG data URIs

NPS-32F2C9364C9F

The code embeds two base64-encoded SVG images as data URIs (Coinbase logo and gear icon). These are decoded and rendered as images, not evaluated as code. The decoded SVGs appear to be legitimate UI icons with no script content.

dist/sign/walletlink/relay/ui/components/Snackbar/Snackbar.js:7
low

Sensitive data in URL query parameters

NPS-C6B88A7E4B84

createQrUrl embeds sessionSecret (a shared secret) into a URL query string, which may be exposed via browser history, referrer headers, server logs, or QR code scanning.

dist/sign/walletlink/relay/ui/components/util.js:3
low

Cross-origin iframe location access

NPS-BCE47FD410CF

getLocation attempts to read window.top.location when in an iframe. While guarded by try/catch, accessing parent/top location is blocked by same-origin policy and this pattern is sometimes used to probe embedding context.

dist/sign/walletlink/relay/ui/components/util.js:17
low

Weak cryptographic parameter / potential security risk

NPS-138902AE04D8

The encrypt function uses a 12-byte (96-bit) IV for AES-GCM, which is standard. However, the IV is randomly generated with crypto.getRandomValues, which is cryptographically secure. No immediate issue. But note: deriveSharedSecret uses ECDH with P-256 and derives an AES-GCM key, which is secure. No direct malicious pattern.

dist/util/cipher.js
low

Key export/import with extractable flag

NPS-E5FF96D880B6

exportKeyToHexString exports private keys as pkcs8 and public keys as spki, and importKeyFromHexString imports them with extractable=true for both public and private keys. This allows private key extraction, which could be a security concern if keys are mishandled, but it is not inherently malicious. It is a design choice for key serialization.

dist/util/cipher.js
low

Potential information leakage via error serialization

NPS-CC8298CC3FB9

encryptContent serializes Error objects by including error.code and error.message. This could inadvertently expose sensitive information in error messages when encrypted content is later decrypted. However, this is a functional behavior, not a malicious pattern.

dist/util/cipher.js
low

Suspicious network request

NPS-DE56C720184D

The fetchRPCRequest function uses window.fetch to send arbitrary JSON-RPC requests to a caller-provided rpcUrl. While expected for a wallet SDK, this constitutes a network egress primitive that could be abused to exfiltrate wallet-related data if rpcUrl is attacker-controlled.

dist/util/provider.js:3
low

Cross-origin request with identifying headers

NPS-5753EC407615

Requests include X-Cbw-Sdk-Version and X-Cbw-Sdk-Platform headers, fingerprinting the SDK/version/platform to the remote RPC endpoint. Combined with arbitrary rpcUrl this could leak client environment details to third parties.

dist/util/provider.js:8
low

Telemetry and Logging

NPS-A2C143898B17

The code imports and calls telemetry functions (logSnackbarActionClicked, logSnackbarShown) which may send user interaction data to external servers. While common for analytics, this could be a privacy concern if data is exfiltrated without user consent. The telemetry destination is not visible in this file, so it cannot be fully assessed.

dist/util/web.js:2
low

Dynamic code execution via eval-like patterns

NPS-09B51B18B878

The code contains a Webpack module loader that evaluates modules dynamically using e[r].call(a.exports, a, a.exports, n). While this is standard Webpack bundling behavior, it constitutes dynamic code execution and could be abused if module IDs or content are attacker-controlled. The presence of Function constructor or eval is not directly observed, but the module system allows runtime execution of bundled code.

dist/vendor-js/CCA/ca.js
low

Use of IndexedDB for persistent storage

NPS-A24443454C44

The code uses IndexedDB (keyval-store) to persist analytics data such as event IDs, session IDs, and user IDs across sessions. This is standard for analytics but enables long-term tracking.

dist/vendor-js/CCA/ca.js

Files reviewed

FileVerdictWhat the reviewer saw
dist/CoinbaseWalletSDK.js medium The code is a legitimate Coinbase Wallet SDK entry point, but it automatically loads external telemetry scripts and collects app metadata, which presents privacy and potential data exfiltration concerns that users should be aware of and can disable via preferences.
dist/core/telemetry/initCCA.js medium The code performs telemetry data collection and transmission to an external server with a hardcoded API key, raising privacy and security concerns, though no overtly malicious patterns like credential harvesting or backdoors were found.
dist/core/telemetry/logEvent.js medium Telemetry module forwards SDK metadata, preferences, and arbitrary events to a globally-defined ClientAnalytics object, presenting a medium-risk data exposure surface depending on where that object sends data.
dist/core/telemetry/telemetry-content.js medium This is a bundled Coinbase analytics/telemetry SDK that intentionally collects extensive user, device, session and network data and transmits it to Coinbase endpoints; it is not overtly malicious (no credential theft, shells, crypto miners, or eval), but its aggressive telemetry, persistent storage, and embedded minified payload warrant caution as a third-party dependency.
dist/createCoinbaseWalletSDK.js medium No malicious patterns detected; the code is a legitimate Coinbase Wallet SDK entry point with opt-out telemetry and standard wallet functions, though the telemetry/script-loading behavior is worth noting for privacy.
dist/kms/crypto-key/index.js medium The code implements Coinbase WebAuthn-style key management and signing without obvious data exfiltration, shell execution, or backdoor patterns, but handles sensitive cryptographic key material and uses an opaque storage abstraction whose security cannot be fully verified from this file alone.
dist/kms/crypto-key/storage.js medium The code is a simple IndexedDB wrapper with no exfiltration, code execution, or credential harvesting, but it stores key-value data in plaintext and lacks validation and error handling, which is a moderate concern for a crypto-key storage module.
dist/sign/scw/utils/handleAddSubAccountOwner.js medium The code appears to be a legitimate utility for adding sub-account owners in a wallet SDK, but contains a hardcoded chain ID that could result in transactions being sent to an unintended network.
dist/sign/util.js medium No malicious patterns detected; code appears to be legitimate wallet signer configuration for a Coinbase Wallet SDK, though the domain is inherently security-sensitive.
dist/sign/walletlink/relay/connection/WalletLinkConnection.js medium The code appears to be a legitimate Coinbase Wallet SDK component with expected network communication and cryptographic operations, but no clear malicious patterns were detected.
dist/sign/walletlink/relay/connection/WalletLinkHTTP.js medium No malicious patterns detected; code appears to be a legitimate wallet relay client, but it handles sensitive session data and makes configurable network requests.
dist/sign/walletlink/relay/ui/WLMobileRelayUI.js medium No clear malicious code, credential harvesting, or exfiltration was found, but the module performs programmatic external deeplink navigation with user-controlled parameters, which warrants a warning.
dist/sign/walletlink/relay/ui/components/util.js medium Utility module for WalletLink relay UI has no clear malicious code but exposes a session secret in a URL and accesses top-level window location; treat as low-risk warning.
dist/store/store.js medium No overtly malicious behavior (exfiltration, shell execution, obfuscation, or install-time backdoors) was detected, but the module persists sensitive wallet keys and account data in browser localStorage, posing a high risk of credential theft via XSS.
dist/util/cipher.js medium The code implements standard ECDH key exchange and AES-GCM encryption without malicious patterns, but uses extractable private keys and serializes error details, which are low-risk security considerations.
dist/util/provider.js medium Wallet SDK code that performs RPC fetch calls and accesses injected provider globals; no direct malicious patterns such as exfiltration, credential harvesting, or code execution were found, but it exposes network and wallet-state primitives that warrant review of how rpcUrl and providers are supplied.
dist/util/web.js medium The code is a legitimate wallet SDK UI utility for popup handling; no clear malicious patterns like data exfiltration, credential harvesting, or command execution were found, but it includes telemetry and external popup opening that warrant caution.
dist/vendor-js/CCA/ca.js medium The package is a legitimate analytics SDK (Coinbase Client Analytics) that collects and transmits user and device data to external servers; while not overtly malicious, it exhibits extensive data collection and tracking behavior that warrants caution.
dist/CoinbaseWalletProvider.js safe No malicious patterns detected; the code is a standard Coinbase Wallet provider implementation with telemetry, RPC calls, and signer management.
dist/assets/wallet-logo.js safe No malicious patterns detected
dist/core/communicator/Communicator.js safe No malicious patterns detected; the code implements a standard popup-based communication channel with origin validation and no data exfiltration, credential harvesting, or dynamic code execution.
dist/core/constants.js safe No malicious patterns detected
dist/core/error/constants.js safe No malicious patterns detected
dist/core/error/errors.js safe No malicious patterns detected; the code is a standard Ethereum JSON-RPC error handling utility with no exfiltration, credential harvesting, dynamic code execution, or network activity.
dist/core/error/serialize.js safe No malicious patterns detected; the code is a legitimate error serialization utility that does not exfiltrate data, run dynamic code, access credentials, or spawn processes.
Show 73 more files
FileVerdictWhat the reviewer saw
dist/core/error/utils.js safe No malicious patterns detected
dist/core/message/ConfigMessage.js safe No malicious patterns detected; the file is an empty module export with only a source map reference.
dist/core/message/Message.js safe The file contains only an empty export statement and a source map reference, with no executable or malicious code.
dist/core/message/RPCMessage.js safe No malicious patterns detected
dist/core/message/RPCRequest.js safe No malicious patterns detected
dist/core/message/RPCResponse.js safe No malicious patterns detected
dist/core/provider/interface.js safe Cleared by Jev triage; no further analysis needed
dist/core/rpc/coinbase_fetchSpendPermissions.js safe No malicious patterns detected
dist/core/rpc/wallet_addSubAccount.js safe No malicious patterns detected
dist/core/rpc/wallet_connect.js safe No malicious patterns detected
dist/core/rpc/wallet_getSubAccount.js safe The file contains only an empty export and a source map reference, with no executable code or malicious patterns.
dist/core/rpc/wallet_prepareCalls.js safe No malicious patterns detected
dist/core/rpc/wallet_sendPreparedCalls.js safe This file is an empty ES module re-export with only a source map comment, containing no executable or suspicious code.
dist/core/storage/ScopedLocalStorage.js safe No malicious patterns detected; the code is a straightforward localStorage wrapper with scoped keys.
dist/core/telemetry/events/communicator.js safe The file only logs telemetry events via an internal logEvent helper and contains no malicious patterns, external network calls, credential harvesting, or dynamic execution.
dist/core/telemetry/events/provider.js safe No malicious patterns detected
dist/core/telemetry/events/scw-signer.js safe The code only implements telemetry event logging for SCW signer operations and contains no malicious patterns.
dist/core/telemetry/events/scw-sub-account.js safe No malicious patterns detected; the file only contains telemetry event logging functions that use internal store and logEvent imports with no data exfiltration, credential harvesting, obfuscation, process spawning, or suspicious network activity.
dist/core/telemetry/events/signer-selection.js safe No malicious patterns detected
dist/core/telemetry/events/snackbar.js safe The file contains only straightforward telemetry logging functions with no malicious patterns, external network calls, credential access, or dynamic code execution.
dist/core/telemetry/events/walletlink-signer.js safe No malicious patterns detected
dist/core/telemetry/utils.js safe Cleared by Jev triage; no further analysis needed
dist/core/type/index.js safe No malicious patterns detected; the code only defines simple type/utility functions with no I/O, network, process, or dynamic execution behavior.
dist/core/type/util.js safe No malicious patterns detected; the code implements standard Ethereum/hex utility functions without data exfiltration, credential harvesting, obfuscation, or process execution.
dist/createCoinbaseWalletProvider.js safe No malicious patterns detected
dist/index.js safe No malicious patterns detected
dist/sdk-info.js safe No malicious patterns detected; the file only exports package name and version constants.
dist/sign/interface.js safe No malicious patterns detected
dist/sign/scw/SCWKeyManager.js safe No malicious patterns detected; the file implements a straightforward ECDH key manager using local storage without network, process, or filesystem abuse.
dist/sign/scw/SCWSigner.js safe This SCWSigner implementation appears to be a legitimate wallet signer with expected encrypted popup communication and RPC forwarding, and no clear malicious patterns were detected.
dist/sign/scw/utils.js safe No malicious patterns detected
dist/sign/scw/utils/constants.js safe The file contains only hardcoded Ethereum contract addresses and ABI definitions with no executable, network, filesystem, or obfuscated code.
dist/sign/scw/utils/createSmartAccount.js safe The code implements a Coinbase Smart Account SDK using viem and ox libraries with no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or network calls detected.
dist/sign/scw/utils/createSubAccountSigner.js safe No malicious patterns detected; the code implements a legitimate Ethereum sub-account signer RPC handler without any data exfiltration, credential harvesting, obfuscation, or backdoor behavior.
dist/sign/scw/utils/findOwnerIndex.js safe The code is a legitimate utility for finding an owner index in a smart contract and contains no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
dist/sign/scw/utils/handleInsufficientBalance.js safe No malicious patterns detected; the code handles insufficient balance errors in a cryptocurrency wallet context using expected libraries and APIs without exfiltration, obfuscation, or spawns.
dist/sign/scw/utils/presentAddOwnerDialog.js safe No malicious patterns detected; the file only presents a UI dialog and logs telemetry events.
dist/sign/walletlink/WalletLinkSigner.js safe No malicious patterns detected; the code is a legitimate Ethereum wallet signer with expected network and storage interactions.
dist/sign/walletlink/relay/RelayEventManager.js safe No malicious patterns detected; the file only implements a simple request ID manager for WalletLink relay events.
dist/sign/walletlink/relay/WalletLinkRelay.js safe No malicious patterns detected
dist/sign/walletlink/relay/connection/HeartbeatWorker.js safe Cleared by Jev triage; no further analysis needed
dist/sign/walletlink/relay/connection/WalletLinkCipher.js safe No malicious patterns detected; the code implements standard AES-GCM encryption/decryption for WalletLink communication without exfiltration, credential harvesting, or execution of untrusted code.
dist/sign/walletlink/relay/connection/WalletLinkWebSocket.js safe No malicious patterns detected
dist/sign/walletlink/relay/constants.js safe No malicious patterns detected
dist/sign/walletlink/relay/mocks/fixtures.js safe No malicious patterns detected; the file contains only static mock test fixtures with no executable or exfiltration logic.
dist/sign/walletlink/relay/mocks/relay.js safe This is a benign mock relay module for testing WalletLink interactions, containing only hardcoded fake responses with no network, file system, process execution, or obfuscated code.
dist/sign/walletlink/relay/type/ClientMessage.js safe No malicious patterns detected
dist/sign/walletlink/relay/type/EthereumTransactionParams.js safe No malicious patterns detected
dist/sign/walletlink/relay/type/ServerMessage.js safe No malicious patterns detected
dist/sign/walletlink/relay/type/WalletLinkEventData.js safe No malicious patterns detected in the provided stub file; it only contains a copyright comment, an empty export, and a source map reference.
dist/sign/walletlink/relay/type/WalletLinkSession.js safe The code is a legitimate session management implementation for Coinbase WalletLink, with no malicious patterns detected; it uses standard cryptographic hashing and random generation for session IDs and secrets.
dist/sign/walletlink/relay/type/Web3Request.js safe No malicious patterns detected
dist/sign/walletlink/relay/type/Web3Response.js safe No malicious patterns detected in the provided file
dist/sign/walletlink/relay/ui/RelayUI.js safe No malicious patterns detected
dist/sign/walletlink/relay/ui/WalletLinkRelayUI.js safe No malicious patterns detected; the file contains legitimate UI code for the Coinbase Wallet SDK relay interface.
dist/sign/walletlink/relay/ui/components/RedirectDialog/RedirectDialog-css.js safe The file contains only static CSS styling for a dialog component and exhibits no malicious patterns, dynamic code execution, network activity, or filesystem access.
dist/sign/walletlink/relay/ui/components/RedirectDialog/RedirectDialog.js safe No malicious patterns detected; the code is a standard UI component for rendering a redirect dialog with no network, filesystem, or process manipulation.
dist/sign/walletlink/relay/ui/components/Snackbar/Snackbar-css.js safe This is a pure CSS-in-JS style string for a Coinbase Wallet SDK snackbar UI component with no executable code, network access, or malicious patterns.
dist/sign/walletlink/relay/ui/components/Snackbar/Snackbar.js safe No malicious patterns detected; the file contains only benign UI rendering logic for a Snackbar component with static SVG assets and no network, filesystem, or process manipulation.
dist/sign/walletlink/relay/ui/components/cssReset/cssReset-css.js safe This file contains only a static CSS reset string exported via an IIFE, with no network, filesystem, process execution, or other malicious patterns.
dist/sign/walletlink/relay/ui/components/cssReset/cssReset.js safe No malicious patterns detected
dist/store/chain-clients/store.js safe The file simply creates a Zustand vanilla store with an empty object and contains no malicious patterns.
dist/store/chain-clients/utils.js safe No malicious patterns detected
dist/store/correlation-ids/store.js safe No malicious patterns detected; the code is a simple Zustand store for managing correlation IDs with no external calls, dynamic execution, or file/process access.
dist/util/assertPresence.js safe No malicious patterns detected; the file contains only simple validation utility functions with no network, filesystem, or dynamic execution behavior.
dist/util/assertSubAccount.js safe No malicious patterns detected; the file only performs input validation for sub-account fields using trusted viem utilities.
dist/util/checkCrossOriginOpenerPolicy.js safe No malicious patterns detected; the code only performs a same-origin HEAD request to check the COOP header and logs an error if misconfigured.
dist/util/encoding.js safe No malicious patterns detected; the code is a benign WebAuthn encoding utility with standard cryptographic conversions.
dist/util/get.js safe The file contains a simple utility function for safe property access on objects with no malicious patterns, external calls, or dynamic code execution.
dist/util/validatePreferences.js safe No malicious patterns detected
dist/vendor-js/eth-eip712-util/abi.cjs safe No malicious patterns detected; the code is a legitimate Ethereum ABI encoding utility extracted from ethereumjs-abi with no data exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
dist/vendor-js/eth-eip712-util/index.cjs safe No malicious patterns detected; this is a standard EIP-712 typed data signing utility with no network, filesystem, process spawning, or obfuscated code.
dist/vendor-js/eth-eip712-util/util.cjs safe No malicious patterns detected

Frequently asked questions

Is @coinbase/wallet-sdk safe to use?

No confirmed malware was found in @coinbase/wallet-sdk@4.3.6, but the review flagged 1 high, 19 medium, 39 low severity findings for risky patterns worth checking before you rely on it.

Does @coinbase/wallet-sdk contain malware?

No malware was identified in @coinbase/wallet-sdk@4.3.6 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @coinbase/wallet-sdk checked?

Togoder Security downloaded the published npm package and had an AI model read its 98 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @coinbase/wallet-sdk together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @coinbase/wallet-sdk@4.3.6, cost nothing.

Related security reports