# @metamask/providers@16.1.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:07:54.000Z
- Files reviewed: 54
- Findings: 8 medium, 4 low severity findings
- Report: https://security.togoder.click/npm/@metamask/providers
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @metamask/providers@16.1.0 on Oct 4, 2026. An AI review of 54 source files produced 8 medium, 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Missing modules

Finding ID: `NPS-8EAEB8E4733C`

File: `dist/EIP6963.js:4`

The file requires './chunk-WBB62AKC.js' and './chunk-3W5G4CYI.js', which are not included in the analysis. The actual implementation of announceProvider and requestProvider, including any network operations, data handling, or dynamic code execution, resides in these chunks. Without reviewing them, malicious behavior cannot be ruled out.

### [medium] Suspicious import of local chunks

Finding ID: `NPS-EB0560912912`

File: `dist/MetaMaskInpageProvider.mjs:1`

The file imports multiple local chunk files (e.g., chunk-URMSZO7Z.mjs) that are not analyzed here. While this is common in bundled packages, the actual malicious code could reside in these chunks, and this file serves as an entry point. This is a potential risk if the package is not verified.

### [medium] Missing source files for review

Finding ID: `NPS-FA7C2FCBEA02`

File: `dist/StreamProvider.js`

The file is a thin re-export wrapper that requires seven separate chunk files (chunk-DWR5HIZK.js, chunk-A3W22U42.js, chunk-O5ECOCX2.js, chunk-6QNVTE4W.js, chunk-ZOFGBGOM.js, chunk-4EQNSGSR.js, chunk-3W5G4CYI.js). The actual implementation logic and any potential malicious behavior reside in those unprovided files, so they cannot be audited from this snippet alone.

### [medium] External chunk dependency at import time

Finding ID: `NPS-AC884B114DF8`

File: `dist/StreamProvider.js:3`

The module eagerly `require`s all chunk files at the top level. Any code executed at load time inside those chunks (e.g. environment harvesting, network calls, side effects) will run automatically when this module is imported. This is a common vector for obfuscated or delayed payload execution in bundled packages.

### [medium] unverifiable transitive imports

Finding ID: `NPS-AF51A43DC6E7`

File: `dist/StreamProvider.mjs:1`

The file is a barrel re-export that immediately imports several internal chunks (chunk-UTROHXPT.mjs, chunk-OGPA5Q76.mjs, etc.). The actual implementation and any top-level side effects live in these chunks and cannot be inspected from this file. Malicious behavior such as network exfiltration, environment harvesting, or dynamic code execution could be hidden there. This file itself is not obviously malicious, but it provides no security assurance about the package.

### [medium] data_exfiltration

Finding ID: `NPS-66CB50F343DB`

File: `dist/chunk-Q4DN6VYN.js:9`

The sendSiteMetadata function extracts site metadata (name and icon URL) from the current page and sends it via a JSON-RPC message with method 'metamask_sendDomainMetadata'. This is a form of data exfiltration, as it transmits domain metadata to an external engine (likely a browser extension or injected provider) without explicit user consent.

### [medium] Obfuscated/Uninspected Dependencies

Finding ID: `NPS-CFB690043780`

File: `dist/initializeInpageProvider.mjs:2`

The file imports numerous chunk files (chunk-*.mjs) with hashed names whose contents are not provided for inspection, making it impossible to verify whether any of them contain malicious logic such as data exfiltration, credential harvesting, or backdoor installation.

### [medium] Top-level Import Side Effects

Finding ID: `NPS-B329B8E466F6`

File: `dist/initializeInpageProvider.mjs:2`

The imports are executed at module load time, and since the imported chunks are unreviewed, any top-level side effects (network requests, file system access, process spawning) within them would run immediately upon importing this module.

### [low] Data Exfiltration

Finding ID: `NPS-5F62CD4FD831`

File: `dist/chunk-55ZQ55PO.mjs:15`

The code extracts site metadata (name, icon URL) from the current page and sends it via the 'metamask_sendDomainMetadata' JSON-RPC method to an 'engine' object. While this appears to be legitimate MetaMask functionality for phishing detection, the data (including the page title and favicon URL) is transmitted to an external entity (the MetaMask extension), which could be considered a privacy concern if used maliciously.

### [low] Suspicious Network Request

Finding ID: `NPS-793204B22236`

File: `dist/chunk-55ZQ55PO.mjs:63`

The function 'imgExists' creates an image element and sets its 'src' to a URL derived from the page's favicon link. This triggers an HTTP request to that URL, which could be used to leak information via the Referer header or to probe internal resources. However, this is standard behavior for checking image existence.

### [low] External extension connection

Finding ID: `NPS-C7D87D230542`

File: `dist/chunk-KUKZKOBU.js:1`

The code connects to a browser extension via chrome.runtime.connect using well-known MetaMask extension IDs. This is expected behavior for MetaMask's external extension provider and does not constitute exfiltration or unauthorized access.

### [low] suspicious_network_request

Finding ID: `NPS-B318111E22FC`

File: `dist/chunk-Q4DN6VYN.js:63`

The imgExists function dynamically creates an image element and sets its src to a URL found in the page's icon link tags. This triggers a network request to that URL, which could be used to track users or leak information (e.g., via referrer or timing).

## Files reviewed

- `dist/EIP6963.js` (medium): The entry point file is a thin re-export wrapper for EIP-6963 provider functions, but the referenced chunk files containing the actual logic are absent and could harbor malicious code.
- `dist/MetaMaskInpageProvider.mjs` (medium): The entry point file is benign but relies on unanalyzed local chunks, which could contain malicious code.
- `dist/StreamProvider.js` (medium): The provided file is a harmless re-export shim, but it depends on seven unaudited chunk files that execute at import time and could contain hidden malicious logic.
- `dist/StreamProvider.mjs` (medium): This is a simple re-export file with no direct malicious code, but it depends on uninspectable internal chunks that could hide unsafe behavior, so the package cannot be fully assessed from this file alone.
- `dist/chunk-55ZQ55PO.mjs` (medium): The code sends site metadata to a Metamask engine and checks favicon existence, which are typical for wallet extensions but could pose privacy risks.
- `dist/chunk-Q4DN6VYN.js` (medium): The code collects site metadata and icon URLs from the current page and sends them via a JSON-RPC message, which may constitute data exfiltration and tracking.
- `dist/initializeInpageProvider.mjs` (medium): This is a thin re-export module whose only visible logic is importing several obfuscated chunk files and re-exporting two functions; its security cannot be fully assessed without inspecting the imported chunks, which are a potential hiding place for malicious code.
- `dist/BaseProvider.js` (safe): No malicious patterns detected in the re-export shim; it simply loads internal chunks and exports BaseProvider.
- `dist/BaseProvider.mjs` (safe): No malicious patterns detected
- `dist/EIP6963.mjs` (safe): No malicious patterns detected; the file is a simple re-export module for EIP-6963 provider announcement and request utilities.
- `dist/MetaMaskInpageProvider.js` (safe): No malicious patterns detected; the file only re-exports from internal chunk modules.
- `dist/chunk-3W5G4CYI.js` (safe): No malicious patterns detected; the code implements standard private-field access-check helpers with no network, filesystem, process, or dynamic execution activity.
- `dist/chunk-4EQNSGSR.js` (safe): No malicious patterns detected; the file contains only static MetaMask user-facing message strings and deprecation notices with no network, filesystem, process, or dynamic code execution activity.
- `dist/chunk-5FL6VRJJ.mjs` (safe): No malicious patterns detected; the code is a benign middleware that logs deprecation warnings for RPC methods.
- `dist/chunk-6QNVTE4W.js` (safe): No malicious patterns detected; the code is a benign RPC warning middleware for Ethereum JSON-RPC methods.
- `dist/chunk-A3W22U42.js` (safe): No malicious patterns detected; the code is a standard MetaMask BaseProvider implementation with no data exfiltration, credential harvesting, obfuscation, or other red flags.
- `dist/chunk-DD6YP3BV.js` (safe): No malicious patterns detected; the code is a legitimate MetaMask web3 shim that warns about deprecated APIs without exfiltrating data or executing harmful operations.
- `dist/chunk-DWR5HIZK.js` (safe): No malicious patterns detected; this is a legitimate MetaMask StreamProvider implementation with standard dependency imports and no suspicious behavior.
- `dist/chunk-F2Z5ZMH3.mjs` (safe): No malicious patterns detected
- `dist/chunk-HP7EYLLY.js` (safe): No malicious patterns detected; this is a legitimate MetaMask inpage provider implementation.
- `dist/chunk-I6HXGZRD.mjs` (safe): No malicious patterns detected
- `dist/chunk-IZY7ABOL.js` (safe): The code initializes a MetaMask in-page provider, which is standard for web3 wallets, and does not contain any malicious patterns such as data exfiltration, credential harvesting, or dynamic code execution.
- `dist/chunk-KUKZKOBU.js` (safe): This is a legitimate MetaMask extension provider shim that connects to the MetaMask browser extension using known IDs; no malicious patterns were detected.
- `dist/chunk-LF2KN6ZT.mjs` (safe): This code is a legitimate MetaMask inpage provider initialization module that sets up the window.ethereum object, with no malicious patterns detected.
- `dist/chunk-O5ECOCX2.js` (safe): No malicious patterns detected; the file contains standard MetaMask JSON-RPC middleware utilities with no exfiltration, obfuscation, or dynamic code execution.
- `dist/chunk-OGPA5Q76.mjs` (safe): No malicious patterns detected; this is a legitimate MetaMask BaseProvider implementation with standard RPC and event handling.
- `dist/chunk-PH5TX5IT.mjs` (safe): No malicious patterns detected; the code is legitimate MetaMask extension provider integration code using standard browser extension APIs.
- `dist/chunk-URMSZO7Z.mjs` (safe): This is the legitimate MetaMask inpage provider library; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning were detected.
- `dist/chunk-UTROHXPT.mjs` (safe): No malicious patterns detected; the code is a legitimate MetaMask stream provider implementation.
- `dist/chunk-WBB62AKC.js` (safe): No malicious patterns detected; the code implements the EIP-6963 Ethereum provider discovery standard using only event listeners and validation regexes, with no exfiltration, obfuscation, or process execution.
- `dist/chunk-X66SUIEF.mjs` (safe): This file contains only standard JavaScript private field access helper functions with no malicious patterns, network activity, or dynamic execution.
- `dist/chunk-ZGDQ3IYD.mjs` (safe): This file contains only static deprecation and error message strings for the MetaMask Ethereum provider, with no executable code, network access, filesystem access, or other malicious patterns.
- `dist/chunk-ZN7WV55J.mjs` (safe): No malicious patterns detected; the code only contains standard MetaMask JSON-RPC middleware utilities and validation helpers.
- `dist/chunk-ZOFGBGOM.js` (safe): No malicious patterns detected; file only exports three static string constants for token standards.
- `dist/chunk-ZUJYX37P.mjs` (safe): No malicious patterns detected; the code implements the EIP-6963 Ethereum provider discovery standard with proper input validation and no data exfiltration, dynamic execution, or suspicious behavior.
- `dist/constants.js` (safe): No malicious patterns detected; the file is a simple re-export of constants from internal chunks with no suspicious behavior.
- `dist/constants.mjs` (safe): No malicious patterns detected; the file is a simple re-export module for ERC token constants with no executable logic.
- `dist/extension-provider/createExternalExtensionProvider.js` (safe): No malicious patterns detected; the file is a simple re-export wrapper with only static require calls and no suspicious behavior.
- `dist/extension-provider/createExternalExtensionProvider.mjs` (safe): No malicious patterns detected in this simple re-export module.
- `dist/index.js` (safe): No malicious patterns detected; the file is a standard barrel export for a MetaMask-provider package that only re-exports symbols from sibling chunks without executing sensitive logic.
- `dist/index.mjs` (safe): This is an ESM entry point that only re-exports symbols from internal chunks, with no malicious patterns visible in the provided code.
- `dist/initializeInpageProvider.js` (safe): No malicious patterns detected; the file only re-exports functions from local chunks with no suspicious behavior.
- `dist/messages.js` (safe): No malicious patterns detected; file only re-exports a default value from a local chunk without suspicious behavior.
- `dist/messages.mjs` (safe): No malicious patterns detected
- `dist/middleware/createRpcWarningMiddleware.js` (safe): No malicious patterns detected
- `dist/middleware/createRpcWarningMiddleware.mjs` (safe): This is a simple re-export module that only imports and re-exports createRpcWarningMiddleware from internal chunks, with no malicious patterns detected.
- `dist/readable-stream.d.js` (safe): No malicious patterns detected
- `dist/readable-stream.d.mjs` (safe): This file contains only a source map reference comment with no executable code or suspicious behavior.
- `dist/shimWeb3.js` (safe): This is a simple, non-obfuscated re-export module with no malicious patterns detected.
- `dist/shimWeb3.mjs` (safe): No malicious patterns detected
- `dist/siteMetadata.js` (safe): No malicious patterns detected
- `dist/siteMetadata.mjs` (safe): No malicious patterns detected
- `dist/utils.js` (safe): No malicious patterns detected; the file is a simple module re-export with only static requires and exports.
- `dist/utils.mjs` (safe): This file only re-exports symbols from internal chunks and contains no executable logic or malicious patterns.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
