Summary
Togoder Security scanned the npm package @gemini-wallet/core@0.3.2 on Oct 4, 2026. An AI review of 21 source files produced 1 medium, 9 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 10
Hardcoded contract addresses and creation bytecode
NPS-69C730E40655
predictProxyAddress embeds raw EVM creation bytecode (nexusProxyCreationCode). Hardcoded contract bytecode and addresses in a wallet SDK are typical for deterministic address prediction but increase risk if the package were tampered with to compute attacker-controlled addresses.
External network requests to third-party backend
NPS-4610414F426F
The SDK communicates with a Gemini-operated backend at https://keys.gemini.com and https://horizon-api.gemini.com/api/ens. Popup-based message posting uses window.postMessage with origin checks against the SDK backend origin. While typical for a wallet SDK, all user actions (connect, sign, send transaction, typed data) are routed to this external backend, meaning dApp data and user intents are sent off-device.
RPC URL auto-population from chain defaults
NPS-8BEF9D666680
getDefaultRpcUrl falls back to public RPC endpoints for supported chains. If a custom chain's rpcUrl is missing, requests (including personal_sign output and transaction params) may be sent to third-party RPCs. Not inherently malicious but expands trust surface to external RPC providers.
PostMessage origin validation
NPS-54C087EF0C3A
Communicator.onMessage validates event.origin against the SDK backend URL origin before trusting message data. This is a positive security control, but any compromise of keys.gemini.com would allow injection of malicious popup messages to the dApp.
LocalStorage credential/account persistence
NPS-A2D8F0CA1FE2
GeminiStorage persists account addresses, chain configuration, passkey credential keys, and call batch metadata in localStorage under a scoped namespace. Storage of passkey-related keys (STORAGE_PASSKEY_CREDENTIAL_KEY, STORAGE_PRESERVED_PASSKEY_CREDENTIALS_KEY) in localStorage may be sensitive, though these are credential IDs rather than private keys in this file.
Header-injected JSON-RPC fetch
NPS-4AA0B08C655E
fetchRpcRequest posts arbitrary JSON-RPC requests to a configured RPC URL. Method routing falls through to this for unknown methods, meaning any method not explicitly handled is forwarded to the RPC endpoint. This could leak wallet-related state to external RPC if misused by a dApp.
No install-time execution
NPS-516E1D7B8BCD
No top-level side effects observed other than module export construction. No npm lifecycle scripts with malicious commands (build uses tsup, dev uses tsup --watch).
Insecure postMessage targetOrigin
NPS-FCFC8806B6E4
The postMessage call uses this.url.origin, which is derived from SDK_BACKEND_URL (imported from ./utils). If SDK_BACKEND_URL can be influenced by environment variables or build-time configuration, this could potentially send sensitive SDK messages to an unintended origin. However, the origin is validated on incoming messages (event.origin !== this.url.origin), which mitigates most risk. The actual value of SDK_BACKEND_URL is not visible in this file and would need to be verified.
Sensitive window messaging without full validation
NPS-80242650550C
The onMessage handler only validates event.origin but does not validate event.source against the expected popup window reference. This could theoretically allow a same-origin or origin-spoofing scenario, though origin checking provides reasonable protection in practice.
Data transmission to external server
NPS-C835AB83D109
The communicator sends app metadata (appMetadata, window.location.origin, sdkVersion) to the popup backend on load. This is expected behavior for an SDK but involves transmitting application context data to an external origin. The data appears limited to non-sensitive metadata (app name, origin, version) and is part of the documented SDK functionality.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/index.cjs | medium | The package appears to be a legitimate Gemini Wallet SDK with expected external backend communication, localStorage persistence, and hardcoded contract bytecode; no data exfiltration, credential harvesting, obfuscation, or install-time execution was detected. |
| src/communicator.ts | medium | The code is a legitimate-looking SDK communicator that exchanges messages with a configured backend popup; no malicious patterns such as exfiltration, credential harvesting, shell execution, or obfuscation were found, though standard postMessage origin practices could be tightened. |
| dist/index.js | safe | This is a legitimate Gemini Wallet SDK that communicates with the official keys.gemini.com backend via popups and RPC; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or backdoor installation are present. |
| src/constants.ts | safe | No malicious patterns detected; the file only defines constants, chain IDs, and RPC URL helpers without any suspicious behavior. |
| src/index.ts | safe | This is a standard entry point file that only re-exports modules and symbols; it contains no executable code, network calls, dynamic execution, or other malicious patterns. |
| src/provider/index.ts | safe | No malicious patterns detected; the file only contains standard ES module re-exports with no runtime logic or side effects. |
| src/provider/provider.ts | safe | No malicious patterns detected; the code is a legitimate Ethereum wallet provider implementation handling standard RPC methods. |
| src/provider/provider.utils.ts | safe | No malicious patterns detected; the code performs standard RPC request handling and validation without exfiltration, credential harvesting, or dynamic code execution. |
| src/storage/index.ts | safe | This is a simple barrel export file re-exporting storage classes, types, and constants with no executable code or malicious patterns. |
| src/storage/storage.ts | safe | The code implements a standard localStorage wrapper with memory fallback and contains no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or unauthorized network/file operations. |
| src/storage/storageInterface.ts | safe | No malicious patterns detected |
| src/types.ts | safe | No malicious patterns detected |
| src/utils/base64.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/utils/calculateWalletAddress.ts | safe | No malicious patterns detected; the code is a pure off-chain wallet address derivation utility with no network, filesystem, process, or dynamic execution activity. |
| src/utils/constants.ts | safe | No malicious patterns detected |
| src/utils/ens.ts | safe | No malicious patterns detected; the code performs a standard, non-sensitive ENS reverse resolution HTTP request with proper error handling. |
| src/utils/index.ts | safe | No malicious patterns detected |
| src/utils/popup.ts | safe | The code opens and closes a browser popup window for wallet interactions with no malicious patterns detected. |
| src/utils/strings.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/wallets/index.ts | safe | No malicious patterns detected |
| src/wallets/wallet.ts | safe | This appears to be a legitimate Gemini wallet SDK for interacting with Ethereum chains; no malicious patterns such as credential harvesting, exfiltration, obfuscation, or process spawning were detected. |
Frequently asked questions
Is @gemini-wallet/core safe to use?
No confirmed malware was found in @gemini-wallet/core@0.3.2, but the review flagged 1 medium, 9 low severity findings for risky patterns worth checking before you rely on it.
Does @gemini-wallet/core contain malware?
No malware was identified in @gemini-wallet/core@0.3.2 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @gemini-wallet/core checked?
Togoder Security downloaded the published npm package and had an AI model read its 21 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @gemini-wallet/core together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @gemini-wallet/core@0.3.2, cost nothing.