# @metamask/onboarding@1.0.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:07:44.000Z
- Files reviewed: 4
- Findings: 4 medium, 6 low severity findings
- Report: https://security.togoder.click/npm/@metamask/onboarding
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @metamask/onboarding@1.0.1 on Oct 4, 2026. An AI review of 4 source files produced 4 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] PostMessage listener without origin validation

Finding ID: `NPS-25C40CCA7910`

File: `dist/metamask-onboarding.bundle.js:1830`

The message event listener checks event.origin against this.forwarderOrigin, but the forwarderOrigin is configurable and defaults to an external domain. If an attacker can influence the forwarderOrigin or if the forwarder domain is compromised, they could send messages to trigger actions like location.reload() or wallet_registerOnboarding.

### [medium] Dynamic iframe injection

Finding ID: `NPS-69A89F358892`

File: `dist/metamask-onboarding.bundle.js:1900`

The code injects a hidden iframe pointing to a configurable external origin ('https://fwd.metamask.io' by default) into the page. While this is intended for MetaMask onboarding, the origin is configurable and could be set to an attacker-controlled domain, enabling cross-origin communication and potential data leakage.

### [medium] Wallet interaction

Finding ID: `NPS-69622B76BD45`

File: `dist/metamask-onboarding.bundle.js:1920`

The code calls window.ethereum.request({ method: 'wallet_registerOnboarding' }) which interacts with the user's MetaMask wallet. While this specific method is for onboarding registration, any compromise of the forwarder origin could potentially trigger other wallet methods if the code were modified.

### [medium] Iframe injection / external content embedding

Finding ID: `NPS-91B9AA8CF57D`

File: `dist/metamask-onboarding.cjs.js:252`

The Onboarding class injects a hidden iframe pointing to an external origin (default 'https://fwd.metamask.io') into the host page's DOM. While this is a documented MetaMask onboarding mechanism, it establishes an embedded third-party context and a cross-origin postMessage channel that could be abused if the forwarder origin is overridden or compromised.

### [low] Session storage flags

Finding ID: `NPS-47A1A9846C82`

File: `dist/metamask-onboarding.cjs.js:47`

Uses sessionStorage to track REGISTRATION_IN_PROGRESS and conditionally injects the forwarder on construction. This is benign but runs top-level constructor logic when the class is instantiated.

### [low] Cross-origin message handling

Finding ID: `NPS-E85E343E5487`

File: `dist/metamask-onboarding.cjs.js:65`

The window 'message' event listener processes messages based on origin and handles 'metamask:reload' commands. It triggers a full page reload and calls wallet_registerOnboarding on the injected provider. If forwarderOrigin is user-supplied and untrusted, this could allow unintended page reloads or calls to wallet APIs.

### [low] External navigation / window.open

Finding ID: `NPS-AD62600BFABD`

File: `dist/metamask-onboarding.cjs.js:219`

startOnboarding opens the MetaMask download page and forwarder via window.open, and _openForwarder can open the forwarderOrigin in a new tab. These are expected UI behaviors but do redirect/add tabs when invoked.

### [low] Cross-Origin Message Handling

Finding ID: `NPS-AB427BB34554`

File: `src/index.ts:70`

Listens for postMessage events and validates event.origin against forwarderOrigin to prevent accepting messages from unauthorized origins. Follows safe messaging practices.

### [low] External Navigation

Finding ID: `NPS-6BB01E6CCD30`

File: `src/index.ts:150`

Uses window.open to open a browser-specific extension download URL (MetaMask) in a new tab. This is a legitimate onboarding flow and not data exfiltration.

### [low] Iframe Injection

Finding ID: `NPS-254C074199B1`

File: `src/index.ts:164`

Injects a hidden iframe pointing to the MetaMask forwarder origin (https://fwd.metamask.io) for onboarding communication. This is part of the intended MetaMask onboarding mechanism.

## Files reviewed

- `dist/metamask-onboarding.bundle.js` (medium): The code is a legitimate MetaMask onboarding library with no obvious malicious patterns, but it uses a configurable external iframe and postMessage communication that could pose security risks if the forwarder origin is compromised or misconfigured.
- `dist/metamask-onboarding.cjs.js` (medium): This appears to be a legitimate MetaMask onboarding module; no exfiltration, credential harvesting, obfuscation, shell execution, or malicious install-time behavior was found, though it does inject a hidden cross-origin iframe and process postMessage events.
- `dist/metamask-onboarding.es.js` (safe): No malicious patterns detected; the code is a legitimate MetaMask onboarding library with standard browser feature detection and no exfiltration, code execution, or filesystem access.
- `src/index.ts` (safe): The code is a legitimate MetaMask onboarding utility that follows secure postMessage patterns and contains no malicious behavior, credential harvesting, or code execution.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
