Togoder security

npm package security report

@metamask/sdk-analytics npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 0.0.5 Files reviewed 6 Size 26.0 KB Scanned

Summary

Togoder Security scanned the npm package @metamask/sdk-analytics@0.0.5 on Oct 4, 2026. An AI review of 6 source files produced 4 medium, 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
4
medium
4
low

Findings 8

medium

Data exfiltration

NPS-A511AF55F617

The analytics module collects and sends event data (including arbitrary properties and global properties set via setGlobalProperty) to an externally controlled endpoint. The endpoint is configurable via environment variables (METAMASK_ANALYTICS_ENDPOINT or NEXT_PUBLIC_METAMASK_ANALYTICS_ENDPOINT), defaulting to 'https://mm-sdk-analytics.api.cx.metamask.io/'. While this is expected behavior for an analytics SDK, the configurable endpoint could be abused to redirect data to an attacker-controlled server if the environment is compromised.

dist/index.js:137
medium

Data exfiltration

NPS-F80AC80FAB75

The Analytics class collects user-defined event properties and sends them in batches to an external server at a configurable base URL via the '/v1/events' endpoint. No opt-in for the user beyond a global 'enable' flag is present, and the base URL is not constrained or validated.

src/analytics.ts
medium

Data exfiltration

NPS-8D500CD77857

The code initializes an analytics client that sends data to an external endpoint (default: https://mm-sdk-analytics.api.cx.metamask.io/). While the analytics package is presumably legitimate, this is an outbound data transmission that could exfiltrate user data if the package is malicious or if the endpoint is compromised.

src/index.ts:10
medium

Import-time code execution

NPS-4F6013010FB0

Top-level code runs immediately when the module is imported, instantiating an Analytics client with a potentially attacker-controlled endpoint from environment variables. This could lead to data being sent to an attacker-controlled server if the environment variables are set maliciously.

src/index.ts:12
low

Environment variable harvesting

NPS-0EFC705608A9

The code reads the METAMASK_ANALYTICS_ENDPOINT and NEXT_PUBLIC_METAMASK_ANALYTICS_ENDPOINT environment variables at import time (lines 132-134). This is a common pattern but could be used to extract sensitive endpoint information if not properly secured.

dist/index.js:132
low

Import-time network activity

NPS-5E614AE2036F

The analytics client is instantiated at import time, and although it does not immediately send data until enable() and track() are called, the network client is initialized and the endpoint is resolved from environment variables at module load. This means any code importing this module will trigger the environment variable lookup and client setup.

dist/index.js:133
low

Potential telemetry / privacy concern

NPS-8C482EAF0337

The module is designed to send analytics events to a remote endpoint. Depending on how it is used by the package consumer, this could constitute undisclosed telemetry or data exfiltration.

src/analytics.ts
low

Environment variable harvesting

NPS-C9D660883964

The code reads METAMASK_ANALYTICS_ENDPOINT and NEXT_PUBLIC_METAMASK_ANALYTICS_ENDPOINT environment variables. While these are specific to analytics configuration, it demonstrates environment variable access that could be abused in a malicious package.

src/index.ts:5

Files reviewed

FileVerdictWhat the reviewer saw
dist/index.js medium The package is a functional analytics SDK that sends event data to a configurable endpoint, which is expected behavior but could pose a risk if the endpoint is maliciously configured or if the SDK is used to exfiltrate sensitive data without user awareness.
src/analytics.ts medium The code implements a client-side analytics library that sends batched event data to a remote server, which is a normal but privacy-sensitive pattern rather than an outright malicious one.
src/index.ts medium The code imports and configures an analytics client that sends data to an external endpoint, with the endpoint configurable via environment variables, posing a potential data exfiltration risk if the package is malicious or the endpoint is compromised.
eslint.config.mjs safe Cleared by Jev triage; no further analysis needed
src/schema.ts safe No malicious patterns detected
src/sender.ts safe No malicious patterns detected; the code is a straightforward batching sender implementation with no exfiltration, credential harvesting, obfuscation, or other red flags.

Scanned versions of @metamask/sdk-analytics

VersionVerdictFilesScanned
0.0.5 Needs review 6 Oct 4, 2026

Frequently asked questions

Is @metamask/sdk-analytics safe to use?

No confirmed malware was found in @metamask/sdk-analytics@0.0.5, but the review flagged 4 medium, 4 low severity findings for risky patterns worth checking before you rely on it.

Does @metamask/sdk-analytics contain malware?

No malware was identified in @metamask/sdk-analytics@0.0.5 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @metamask/sdk-analytics checked?

Togoder Security downloaded the published npm package and had an AI model read its 6 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @metamask/sdk-analytics together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @metamask/sdk-analytics@0.0.5, cost nothing.

Related security reports