# @metamask/sdk-analytics@0.0.5 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:08:05.000Z
- Files reviewed: 6
- Findings: 4 medium, 4 low severity findings
- Report: https://security.togoder.click/npm/@metamask/sdk-analytics
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @metamask/sdk-analytics@0.0.5 on Oct 4, 2026. An AI review of 6 source files produced 4 medium, 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Data exfiltration

Finding ID: `NPS-A511AF55F617`

File: `dist/index.js:137`

The analytics module collects and sends event data (including arbitrary properties and global properties set via setGlobalProperty) to an externally controlled endpoint. The endpoint is configurable via environment variables (METAMASK_ANALYTICS_ENDPOINT or NEXT_PUBLIC_METAMASK_ANALYTICS_ENDPOINT), defaulting to 'https://mm-sdk-analytics.api.cx.metamask.io/'. While this is expected behavior for an analytics SDK, the configurable endpoint could be abused to redirect data to an attacker-controlled server if the environment is compromised.

### [medium] Data exfiltration

Finding ID: `NPS-F80AC80FAB75`

File: `src/analytics.ts`

The Analytics class collects user-defined event properties and sends them in batches to an external server at a configurable base URL via the '/v1/events' endpoint. No opt-in for the user beyond a global 'enable' flag is present, and the base URL is not constrained or validated.

### [medium] Data exfiltration

Finding ID: `NPS-8D500CD77857`

File: `src/index.ts:10`

The code initializes an analytics client that sends data to an external endpoint (default: https://mm-sdk-analytics.api.cx.metamask.io/). While the analytics package is presumably legitimate, this is an outbound data transmission that could exfiltrate user data if the package is malicious or if the endpoint is compromised.

### [medium] Import-time code execution

Finding ID: `NPS-4F6013010FB0`

File: `src/index.ts:12`

Top-level code runs immediately when the module is imported, instantiating an Analytics client with a potentially attacker-controlled endpoint from environment variables. This could lead to data being sent to an attacker-controlled server if the environment variables are set maliciously.

### [low] Environment variable harvesting

Finding ID: `NPS-0EFC705608A9`

File: `dist/index.js:132`

The code reads the METAMASK_ANALYTICS_ENDPOINT and NEXT_PUBLIC_METAMASK_ANALYTICS_ENDPOINT environment variables at import time (lines 132-134). This is a common pattern but could be used to extract sensitive endpoint information if not properly secured.

### [low] Import-time network activity

Finding ID: `NPS-5E614AE2036F`

File: `dist/index.js:133`

The analytics client is instantiated at import time, and although it does not immediately send data until enable() and track() are called, the network client is initialized and the endpoint is resolved from environment variables at module load. This means any code importing this module will trigger the environment variable lookup and client setup.

### [low] Potential telemetry / privacy concern

Finding ID: `NPS-8C482EAF0337`

File: `src/analytics.ts`

The module is designed to send analytics events to a remote endpoint. Depending on how it is used by the package consumer, this could constitute undisclosed telemetry or data exfiltration.

### [low] Environment variable harvesting

Finding ID: `NPS-C9D660883964`

File: `src/index.ts:5`

The code reads METAMASK_ANALYTICS_ENDPOINT and NEXT_PUBLIC_METAMASK_ANALYTICS_ENDPOINT environment variables. While these are specific to analytics configuration, it demonstrates environment variable access that could be abused in a malicious package.

## Files reviewed

- `dist/index.js` (medium): The package is a functional analytics SDK that sends event data to a configurable endpoint, which is expected behavior but could pose a risk if the endpoint is maliciously configured or if the SDK is used to exfiltrate sensitive data without user awareness.
- `src/analytics.ts` (medium): The code implements a client-side analytics library that sends batched event data to a remote server, which is a normal but privacy-sensitive pattern rather than an outright malicious one.
- `src/index.ts` (medium): The code imports and configures an analytics client that sends data to an external endpoint, with the endpoint configurable via environment variables, posing a potential data exfiltration risk if the package is malicious or the endpoint is compromised.
- `eslint.config.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `src/schema.ts` (safe): No malicious patterns detected
- `src/sender.ts` (safe): No malicious patterns detected; the code is a straightforward batching sender implementation with no exfiltration, credential harvesting, obfuscation, or other red flags.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
