Togoder security

npm package security report

@metamask/onboarding@1.0.1 security report

Risky patterns found that deserve a look.

Needs review Version 1.0.1 Files reviewed 4 Size 97.6 KB Scanned

Summary

Togoder Security scanned the npm package @metamask/onboarding@1.0.1 on Oct 4, 2026. An AI review of 4 source files produced 4 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
4
medium
6
low

Findings 10

medium

PostMessage listener without origin validation

NPS-25C40CCA7910

The message event listener checks event.origin against this.forwarderOrigin, but the forwarderOrigin is configurable and defaults to an external domain. If an attacker can influence the forwarderOrigin or if the forwarder domain is compromised, they could send messages to trigger actions like location.reload() or wallet_registerOnboarding.

dist/metamask-onboarding.bundle.js:1830
medium

Dynamic iframe injection

NPS-69A89F358892

The code injects a hidden iframe pointing to a configurable external origin ('https://fwd.metamask.io' by default) into the page. While this is intended for MetaMask onboarding, the origin is configurable and could be set to an attacker-controlled domain, enabling cross-origin communication and potential data leakage.

dist/metamask-onboarding.bundle.js:1900
medium

Wallet interaction

NPS-69622B76BD45

The code calls window.ethereum.request({ method: 'wallet_registerOnboarding' }) which interacts with the user's MetaMask wallet. While this specific method is for onboarding registration, any compromise of the forwarder origin could potentially trigger other wallet methods if the code were modified.

dist/metamask-onboarding.bundle.js:1920
medium

Iframe injection / external content embedding

NPS-91B9AA8CF57D

The Onboarding class injects a hidden iframe pointing to an external origin (default 'https://fwd.metamask.io') into the host page's DOM. While this is a documented MetaMask onboarding mechanism, it establishes an embedded third-party context and a cross-origin postMessage channel that could be abused if the forwarder origin is overridden or compromised.

dist/metamask-onboarding.cjs.js:252
low

Session storage flags

NPS-47A1A9846C82

Uses sessionStorage to track REGISTRATION_IN_PROGRESS and conditionally injects the forwarder on construction. This is benign but runs top-level constructor logic when the class is instantiated.

dist/metamask-onboarding.cjs.js:47
low

Cross-origin message handling

NPS-E85E343E5487

The window 'message' event listener processes messages based on origin and handles 'metamask:reload' commands. It triggers a full page reload and calls wallet_registerOnboarding on the injected provider. If forwarderOrigin is user-supplied and untrusted, this could allow unintended page reloads or calls to wallet APIs.

dist/metamask-onboarding.cjs.js:65
low

External navigation / window.open

NPS-AD62600BFABD

startOnboarding opens the MetaMask download page and forwarder via window.open, and _openForwarder can open the forwarderOrigin in a new tab. These are expected UI behaviors but do redirect/add tabs when invoked.

dist/metamask-onboarding.cjs.js:219
low

Cross-Origin Message Handling

NPS-AB427BB34554

Listens for postMessage events and validates event.origin against forwarderOrigin to prevent accepting messages from unauthorized origins. Follows safe messaging practices.

src/index.ts:70
low

External Navigation

NPS-6BB01E6CCD30

Uses window.open to open a browser-specific extension download URL (MetaMask) in a new tab. This is a legitimate onboarding flow and not data exfiltration.

src/index.ts:150
low

Iframe Injection

NPS-254C074199B1

Injects a hidden iframe pointing to the MetaMask forwarder origin (https://fwd.metamask.io) for onboarding communication. This is part of the intended MetaMask onboarding mechanism.

src/index.ts:164

Files reviewed

FileVerdictWhat the reviewer saw
dist/metamask-onboarding.bundle.js medium The code is a legitimate MetaMask onboarding library with no obvious malicious patterns, but it uses a configurable external iframe and postMessage communication that could pose security risks if the forwarder origin is compromised or misconfigured.
dist/metamask-onboarding.cjs.js medium This appears to be a legitimate MetaMask onboarding module; no exfiltration, credential harvesting, obfuscation, shell execution, or malicious install-time behavior was found, though it does inject a hidden cross-origin iframe and process postMessage events.
dist/metamask-onboarding.es.js safe No malicious patterns detected; the code is a legitimate MetaMask onboarding library with standard browser feature detection and no exfiltration, code execution, or filesystem access.
src/index.ts safe The code is a legitimate MetaMask onboarding utility that follows secure postMessage patterns and contains no malicious behavior, credential harvesting, or code execution.

Frequently asked questions

Is @metamask/onboarding safe to use?

No confirmed malware was found in @metamask/onboarding@1.0.1, but the review flagged 4 medium, 6 low severity findings for risky patterns worth checking before you rely on it.

Does @metamask/onboarding contain malware?

No malware was identified in @metamask/onboarding@1.0.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @metamask/onboarding checked?

Togoder Security downloaded the published npm package and had an AI model read its 4 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @metamask/onboarding together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @metamask/onboarding@1.0.1, cost nothing.

Related security reports