# @metamask/sdk-communication-layer@0.33.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:08:33.000Z
- Files reviewed: 5
- Findings: 3 high, 7 medium, 19 low severity findings
- Report: https://security.togoder.click/npm/@metamask/sdk-communication-layer
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @metamask/sdk-communication-layer@0.33.1 on Oct 4, 2026. An AI review of 5 source files produced 3 high, 7 medium, 19 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [high] Sensitive data logging

Finding ID: `NPS-D52DA58B3537`

File: `dist/browser/es/metamask-sdk-communication-layer.js`

The code logs private keys and other sensitive cryptographic material to debug output. For example, in the ECIES class: 'g.Ecies("[ECIES constructor()] initialized secret: ",this.ecies.toHex())' logs the private key, and 'g.Ecies("[ECIES: decrypt()] using privateKey",this.ecies.toHex())' logs the private key during decryption. Similar logging exists for public keys and other key exchange details. If debug logging is enabled, private keys could be exposed in logs.

### [high] Sensitive data logging

Finding ID: `NPS-D52DA58B3537`

File: `dist/node/es/metamask-sdk-communication-layer.js`

The code logs private keys and other sensitive cryptographic material to debug output. For example, in the ECIES class: 'g.Ecies("[ECIES constructor()] initialized secret: ",this.ecies.toHex())' logs the private key, and 'g.Ecies("[ECIES: decrypt()] using privateKey",this.ecies.toHex())' logs the private key during decryption. Similar logging exists for public keys and other key exchange details. If debug logging is enabled, private keys could be exposed in logs.

### [high] Sensitive data logging

Finding ID: `NPS-D52DA58B3537`

File: `dist/react-native/es/metamask-sdk-communication-layer.js`

The code logs private keys and other sensitive cryptographic material to debug output. For example, in the ECIES class: 'g.Ecies("[ECIES constructor()] initialized secret: ",this.ecies.toHex())' logs the private key, and 'g.Ecies("[ECIES: decrypt()] using privateKey",this.ecies.toHex())' logs the private key during decryption. Similar logging exists for public keys and other key exchange details. If debug logging is enabled, private keys could be exposed in logs.

### [medium] Data exfiltration / analytics telemetry

Finding ID: `NPS-E28045E919F9`

File: `dist/browser/es/metamask-sdk-communication-layer.js`

The code implements an analytics function (SendAnalytics) that collects originatorInfo (including dapp URL, title, dappId, anonId, icon, platform, API version, connector) and sends it via HTTP POST to the configured communication server URL (default https://metamask-sdk.api.cx.metamask.io/). Events include connection establishment, RPC method requests, and failures. While this appears to be legitimate MetaMask SDK telemetry, it represents external data transmission that could leak dapp metadata and user interaction patterns.

### [medium] Cryptographic key logging

Finding ID: `NPS-1BBB97445026`

File: `dist/browser/umd/metamask-sdk-communication-layer.js`

The ECIES layer logs private keys and public keys to the console when debug logging is enabled. For example, in the constructor: g.Ecies("[ECIES constructor()] initialized secret: ",this.ecies.toHex()) and in getKeyInfo(). This could expose sensitive cryptographic material in logs if debug is enabled in production.

### [medium] Data exfiltration / analytics collection

Finding ID: `NPS-4E74C92C5443`

File: `dist/node/cjs/metamask-sdk-communication-layer.js:1`

The code collects analytics events (channel IDs, SDK version, wallet version, originator info, RPC method names, connection status, etc.) and sends them to a remote server (default https://metamask-sdk.api.cx.metamask.io/). The `sendBufferedEvents` function (C) POSTs JSON payloads to the communication server URL. While this appears to be intended Metamask SDK telemetry, it is a significant privacy concern because RPC method names and connection metadata are transmitted to a third-party endpoint.

### [medium] Sensitive key material handling / logging

Finding ID: `NPS-4F31DC91EDC2`

File: `dist/node/cjs/metamask-sdk-communication-layer.js:1`

The ECIES class logs private keys and decrypted/encrypted data to the debug logger in multiple places (e.g., `initialized secret`, `private:`, `decrypt()] private:`, `data:`). If debug logging is enabled (e.g., via DEBUG environment variable or logging option), private keys used for end-to-end encryption may be exposed in logs. This is a security weakness even if not intentionally malicious.

### [medium] Network requests with configurable URL

Finding ID: `NPS-C98989A76A12`

File: `dist/node/cjs/metamask-sdk-communication-layer.js:1`

The communication server URL is configurable and used for analytics (`sendBufferedEvents`), message relay, and channel setup. Data sent includes encrypted messages and `plaintext` field when `hasPlaintext` is true. In deployments using a non-default server URL, this could lead to exfiltration of user data. The code also sends `originatorInfo` and `walletInfo` to the server.

### [medium] Data exfiltration / analytics telemetry

Finding ID: `NPS-E28045E919F9`

File: `dist/node/es/metamask-sdk-communication-layer.js`

The code implements an analytics function (SendAnalytics) that collects originatorInfo (including dapp URL, title, dappId, anonId, icon, platform, API version, connector) and sends it via HTTP POST to the configured communication server URL (default https://metamask-sdk.api.cx.metamask.io/). Events include connection establishment, RPC method requests, and failures. While this appears to be legitimate MetaMask SDK telemetry, it represents external data transmission that could leak dapp metadata and user interaction patterns.

### [medium] Data exfiltration / analytics telemetry

Finding ID: `NPS-E28045E919F9`

File: `dist/react-native/es/metamask-sdk-communication-layer.js`

The code implements an analytics function (SendAnalytics) that collects originatorInfo (including dapp URL, title, dappId, anonId, icon, platform, API version, connector) and sends it via HTTP POST to the configured communication server URL (default https://metamask-sdk.api.cx.metamask.io/). Events include connection establishment, RPC method requests, and failures. While this appears to be legitimate MetaMask SDK telemetry, it represents external data transmission that could leak dapp metadata and user interaction patterns.

### [low] Dynamic code execution / eval not present but uses Function constructor indirectly?

Finding ID: `NPS-AC31220552A3`

File: `dist/browser/es/metamask-sdk-communication-layer.js`

No direct eval, Function constructor, or other dynamic code execution mechanisms are present in the provided code. However, the code uses socket.io-client and cross-fetch which are standard libraries. No obfuscated code or encoded payloads were detected.

### [low] Environment variable or credential harvesting

Finding ID: `NPS-2B6C9A3EB2BF`

File: `dist/browser/es/metamask-sdk-communication-layer.js`

No evidence of harvesting environment variables, .npmrc, ~/.ssh, ~/.aws, or other credential files was found. The code does not read from the filesystem beyond standard module imports.

### [low] Cryptocurrency wallet drainer / key theft

Finding ID: `NPS-DEA83E566C2F`

File: `dist/browser/es/metamask-sdk-communication-layer.js`

The code handles ECIES encryption/decryption and key exchange for secure communication between dapps and MetaMask wallet. While it manages private keys, there is no evidence of stealing keys, seed phrases, or rewriting addresses. The key exchange protocol appears to be for establishing a secure channel, which is a legitimate use case for the MetaMask SDK.

### [low] Backdoor / reverse shell

Finding ID: `NPS-E3690EC1DD0C`

File: `dist/browser/es/metamask-sdk-communication-layer.js`

No backdoor, reverse shell, or unauthorized command execution was detected. The code uses socket.io for communication with the MetaMask communication server, which is expected for this SDK.

### [low] Install/build/import time execution

Finding ID: `NPS-EB47DE717EF9`

File: `dist/browser/es/metamask-sdk-communication-layer.js`

The code is a library that initializes on import but does not perform any malicious actions at install, build, or import time. It sets up event listeners and communication layers when instantiated, which is standard for a communication library. No child_process, shell commands, or filesystem manipulation outside the package scope were observed.

### [low] Data exfiltration / analytics telemetry

Finding ID: `NPS-B9E5D8A3FECB`

File: `dist/browser/umd/metamask-sdk-communication-layer.js`

The code sends analytics events to an external server (https://metamask-sdk.api.cx.metamask.io/) via the sendBufferedEvents function. The events include channel IDs, RPC method names, SDK versions, wallet versions, and originator info. While this appears to be legitimate MetaMask SDK telemetry, it constitutes data exfiltration to an external endpoint.

### [low] Dynamic code execution

Finding ID: `NPS-5C7B060F2BC3`

File: `dist/browser/umd/metamask-sdk-communication-layer.js`

The UMD wrapper uses dynamic require and global variable assignment, which is standard for UMD modules but could be abused if the global scope is manipulated. No direct eval or new Function usage was found.

### [low] Network requests with credentials

Finding ID: `NPS-60CDB1A89F2C`

File: `dist/browser/umd/metamask-sdk-communication-layer.js`

Socket.IO client is initialized with withCredentials: true, which sends cookies and authentication headers to the communication server. This is expected for authenticated sessions but could leak credentials if the server is malicious or compromised.

### [low] Persistent private key storage

Finding ID: `NPS-A8957B84757F`

File: `dist/node/cjs/metamask-sdk-communication-layer.js:1`

Private ECIES keys and channel configuration (including localKey) are persisted via a storage manager (`persistChannelConfig`). This is expected for session resumption but means private keys are stored in client storage, increasing attack surface if storage is compromised.

### [low] Dynamic code execution / eval not present but uses Function constructor indirectly?

Finding ID: `NPS-AC31220552A3`

File: `dist/node/es/metamask-sdk-communication-layer.js`

No direct eval, Function constructor, or other dynamic code execution mechanisms are present in the provided code. However, the code uses socket.io-client and cross-fetch which are standard libraries. No obfuscated code or encoded payloads were detected.

### [low] Environment variable or credential harvesting

Finding ID: `NPS-2B6C9A3EB2BF`

File: `dist/node/es/metamask-sdk-communication-layer.js`

No evidence of harvesting environment variables, .npmrc, ~/.ssh, ~/.aws, or other credential files was found. The code does not read from the filesystem beyond standard module imports.

### [low] Cryptocurrency wallet drainer / key theft

Finding ID: `NPS-DEA83E566C2F`

File: `dist/node/es/metamask-sdk-communication-layer.js`

The code handles ECIES encryption/decryption and key exchange for secure communication between dapps and MetaMask wallet. While it manages private keys, there is no evidence of stealing keys, seed phrases, or rewriting addresses. The key exchange protocol appears to be for establishing a secure channel, which is a legitimate use case for the MetaMask SDK.

### [low] Backdoor / reverse shell

Finding ID: `NPS-E3690EC1DD0C`

File: `dist/node/es/metamask-sdk-communication-layer.js`

No backdoor, reverse shell, or unauthorized command execution was detected. The code uses socket.io for communication with the MetaMask communication server, which is expected for this SDK.

### [low] Install/build/import time execution

Finding ID: `NPS-EB47DE717EF9`

File: `dist/node/es/metamask-sdk-communication-layer.js`

The code is a library that initializes on import but does not perform any malicious actions at install, build, or import time. It sets up event listeners and communication layers when instantiated, which is standard for a communication library. No child_process, shell commands, or filesystem manipulation outside the package scope were observed.

### [low] Dynamic code execution / eval not present but uses Function constructor indirectly?

Finding ID: `NPS-AC31220552A3`

File: `dist/react-native/es/metamask-sdk-communication-layer.js`

No direct eval, Function constructor, or other dynamic code execution mechanisms are present in the provided code. However, the code uses socket.io-client and cross-fetch which are standard libraries. No obfuscated code or encoded payloads were detected.

### [low] Environment variable or credential harvesting

Finding ID: `NPS-2B6C9A3EB2BF`

File: `dist/react-native/es/metamask-sdk-communication-layer.js`

No evidence of harvesting environment variables, .npmrc, ~/.ssh, ~/.aws, or other credential files was found. The code does not read from the filesystem beyond standard module imports.

### [low] Cryptocurrency wallet drainer / key theft

Finding ID: `NPS-DEA83E566C2F`

File: `dist/react-native/es/metamask-sdk-communication-layer.js`

The code handles ECIES encryption/decryption and key exchange for secure communication between dapps and MetaMask wallet. While it manages private keys, there is no evidence of stealing keys, seed phrases, or rewriting addresses. The key exchange protocol appears to be for establishing a secure channel, which is a legitimate use case for the MetaMask SDK.

### [low] Backdoor / reverse shell

Finding ID: `NPS-E3690EC1DD0C`

File: `dist/react-native/es/metamask-sdk-communication-layer.js`

No backdoor, reverse shell, or unauthorized command execution was detected. The code uses socket.io for communication with the MetaMask communication server, which is expected for this SDK.

### [low] Install/build/import time execution

Finding ID: `NPS-EB47DE717EF9`

File: `dist/react-native/es/metamask-sdk-communication-layer.js`

The code is a library that initializes on import but does not perform any malicious actions at install, build, or import time. It sets up event listeners and communication layers when instantiated, which is standard for a communication library. No child_process, shell commands, or filesystem manipulation outside the package scope were observed.

## Files reviewed

- `dist/browser/es/metamask-sdk-communication-layer.js` (medium): The code is part of the legitimate MetaMask SDK for secure communication between dapps and wallets, but it includes analytics telemetry that sends dapp metadata to MetaMask servers and logs sensitive cryptographic keys when debug logging is enabled, posing a moderate privacy and security risk if misused.
- `dist/browser/umd/metamask-sdk-communication-layer.js` (medium): The code is a legitimate MetaMask SDK communication layer that includes expected telemetry and debugging features, but it logs sensitive cryptographic keys when debug mode is enabled and sends analytics data to an external server.
- `dist/node/cjs/metamask-sdk-communication-layer.js` (medium): The file is the legitimate MetaMask SDK communication layer but contains privacy-sensitive telemetry (sending analytics and metadata to a remote server) and logs private ECIES keys under debug settings; no overtly malicious backdoors, credential harvesting, or code execution were found.
- `dist/node/es/metamask-sdk-communication-layer.js` (medium): The code is part of the legitimate MetaMask SDK for secure communication between dapps and wallets, but it includes analytics telemetry that sends dapp metadata to MetaMask servers and logs sensitive cryptographic keys when debug logging is enabled, posing a moderate privacy and security risk if misused.
- `dist/react-native/es/metamask-sdk-communication-layer.js` (medium): The code is part of the legitimate MetaMask SDK for secure communication between dapps and wallets, but it includes analytics telemetry that sends dapp metadata to MetaMask servers and logs sensitive cryptographic keys when debug logging is enabled, posing a moderate privacy and security risk if misused.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
