Togoder security

npm package security report

@metamask/sdk-communication-layer@0.33.1 security report

Risky patterns found that deserve a look.

Needs review Version 0.33.1 Files reviewed 5 Size 341.9 KB Scanned

Summary

Togoder Security scanned the npm package @metamask/sdk-communication-layer@0.33.1 on Oct 4, 2026. An AI review of 5 source files produced 3 high, 7 medium, 19 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
3
high
7
medium
19
low

Findings 29

high

Sensitive data logging

NPS-D52DA58B3537

The code logs private keys and other sensitive cryptographic material to debug output. For example, in the ECIES class: 'g.Ecies("[ECIES constructor()] initialized secret: ",this.ecies.toHex())' logs the private key, and 'g.Ecies("[ECIES: decrypt()] using privateKey",this.ecies.toHex())' logs the private key during decryption. Similar logging exists for public keys and other key exchange details. If debug logging is enabled, private keys could be exposed in logs.

dist/browser/es/metamask-sdk-communication-layer.js
high

Sensitive data logging

NPS-D52DA58B3537

The code logs private keys and other sensitive cryptographic material to debug output. For example, in the ECIES class: 'g.Ecies("[ECIES constructor()] initialized secret: ",this.ecies.toHex())' logs the private key, and 'g.Ecies("[ECIES: decrypt()] using privateKey",this.ecies.toHex())' logs the private key during decryption. Similar logging exists for public keys and other key exchange details. If debug logging is enabled, private keys could be exposed in logs.

dist/node/es/metamask-sdk-communication-layer.js
high

Sensitive data logging

NPS-D52DA58B3537

The code logs private keys and other sensitive cryptographic material to debug output. For example, in the ECIES class: 'g.Ecies("[ECIES constructor()] initialized secret: ",this.ecies.toHex())' logs the private key, and 'g.Ecies("[ECIES: decrypt()] using privateKey",this.ecies.toHex())' logs the private key during decryption. Similar logging exists for public keys and other key exchange details. If debug logging is enabled, private keys could be exposed in logs.

dist/react-native/es/metamask-sdk-communication-layer.js
medium

Data exfiltration / analytics telemetry

NPS-E28045E919F9

The code implements an analytics function (SendAnalytics) that collects originatorInfo (including dapp URL, title, dappId, anonId, icon, platform, API version, connector) and sends it via HTTP POST to the configured communication server URL (default https://metamask-sdk.api.cx.metamask.io/). Events include connection establishment, RPC method requests, and failures. While this appears to be legitimate MetaMask SDK telemetry, it represents external data transmission that could leak dapp metadata and user interaction patterns.

dist/browser/es/metamask-sdk-communication-layer.js
medium

Cryptographic key logging

NPS-1BBB97445026

The ECIES layer logs private keys and public keys to the console when debug logging is enabled. For example, in the constructor: g.Ecies("[ECIES constructor()] initialized secret: ",this.ecies.toHex()) and in getKeyInfo(). This could expose sensitive cryptographic material in logs if debug is enabled in production.

dist/browser/umd/metamask-sdk-communication-layer.js
medium

Data exfiltration / analytics collection

NPS-4E74C92C5443

The code collects analytics events (channel IDs, SDK version, wallet version, originator info, RPC method names, connection status, etc.) and sends them to a remote server (default https://metamask-sdk.api.cx.metamask.io/). The sendBufferedEvents function (C) POSTs JSON payloads to the communication server URL. While this appears to be intended Metamask SDK telemetry, it is a significant privacy concern because RPC method names and connection metadata are transmitted to a third-party endpoint.

dist/node/cjs/metamask-sdk-communication-layer.js:1
medium

Sensitive key material handling / logging

NPS-4F31DC91EDC2

The ECIES class logs private keys and decrypted/encrypted data to the debug logger in multiple places (e.g., initialized secret, private:, decrypt()] private:, data:). If debug logging is enabled (e.g., via DEBUG environment variable or logging option), private keys used for end-to-end encryption may be exposed in logs. This is a security weakness even if not intentionally malicious.

dist/node/cjs/metamask-sdk-communication-layer.js:1
medium

Network requests with configurable URL

NPS-C98989A76A12

The communication server URL is configurable and used for analytics (sendBufferedEvents), message relay, and channel setup. Data sent includes encrypted messages and plaintext field when hasPlaintext is true. In deployments using a non-default server URL, this could lead to exfiltration of user data. The code also sends originatorInfo and walletInfo to the server.

dist/node/cjs/metamask-sdk-communication-layer.js:1
medium

Data exfiltration / analytics telemetry

NPS-E28045E919F9

The code implements an analytics function (SendAnalytics) that collects originatorInfo (including dapp URL, title, dappId, anonId, icon, platform, API version, connector) and sends it via HTTP POST to the configured communication server URL (default https://metamask-sdk.api.cx.metamask.io/). Events include connection establishment, RPC method requests, and failures. While this appears to be legitimate MetaMask SDK telemetry, it represents external data transmission that could leak dapp metadata and user interaction patterns.

dist/node/es/metamask-sdk-communication-layer.js
medium

Data exfiltration / analytics telemetry

NPS-E28045E919F9

The code implements an analytics function (SendAnalytics) that collects originatorInfo (including dapp URL, title, dappId, anonId, icon, platform, API version, connector) and sends it via HTTP POST to the configured communication server URL (default https://metamask-sdk.api.cx.metamask.io/). Events include connection establishment, RPC method requests, and failures. While this appears to be legitimate MetaMask SDK telemetry, it represents external data transmission that could leak dapp metadata and user interaction patterns.

dist/react-native/es/metamask-sdk-communication-layer.js
low

Dynamic code execution / eval not present but uses Function constructor indirectly?

NPS-AC31220552A3

No direct eval, Function constructor, or other dynamic code execution mechanisms are present in the provided code. However, the code uses socket.io-client and cross-fetch which are standard libraries. No obfuscated code or encoded payloads were detected.

dist/browser/es/metamask-sdk-communication-layer.js
low

Environment variable or credential harvesting

NPS-2B6C9A3EB2BF

No evidence of harvesting environment variables, .npmrc, ~/.ssh, ~/.aws, or other credential files was found. The code does not read from the filesystem beyond standard module imports.

dist/browser/es/metamask-sdk-communication-layer.js
low

Cryptocurrency wallet drainer / key theft

NPS-DEA83E566C2F

The code handles ECIES encryption/decryption and key exchange for secure communication between dapps and MetaMask wallet. While it manages private keys, there is no evidence of stealing keys, seed phrases, or rewriting addresses. The key exchange protocol appears to be for establishing a secure channel, which is a legitimate use case for the MetaMask SDK.

dist/browser/es/metamask-sdk-communication-layer.js
low

Backdoor / reverse shell

NPS-E3690EC1DD0C

No backdoor, reverse shell, or unauthorized command execution was detected. The code uses socket.io for communication with the MetaMask communication server, which is expected for this SDK.

dist/browser/es/metamask-sdk-communication-layer.js
low

Install/build/import time execution

NPS-EB47DE717EF9

The code is a library that initializes on import but does not perform any malicious actions at install, build, or import time. It sets up event listeners and communication layers when instantiated, which is standard for a communication library. No child_process, shell commands, or filesystem manipulation outside the package scope were observed.

dist/browser/es/metamask-sdk-communication-layer.js
low

Data exfiltration / analytics telemetry

NPS-B9E5D8A3FECB

The code sends analytics events to an external server (https://metamask-sdk.api.cx.metamask.io/) via the sendBufferedEvents function. The events include channel IDs, RPC method names, SDK versions, wallet versions, and originator info. While this appears to be legitimate MetaMask SDK telemetry, it constitutes data exfiltration to an external endpoint.

dist/browser/umd/metamask-sdk-communication-layer.js
low

Dynamic code execution

NPS-5C7B060F2BC3

The UMD wrapper uses dynamic require and global variable assignment, which is standard for UMD modules but could be abused if the global scope is manipulated. No direct eval or new Function usage was found.

dist/browser/umd/metamask-sdk-communication-layer.js
low

Network requests with credentials

NPS-60CDB1A89F2C

Socket.IO client is initialized with withCredentials: true, which sends cookies and authentication headers to the communication server. This is expected for authenticated sessions but could leak credentials if the server is malicious or compromised.

dist/browser/umd/metamask-sdk-communication-layer.js
low

Persistent private key storage

NPS-A8957B84757F

Private ECIES keys and channel configuration (including localKey) are persisted via a storage manager (persistChannelConfig). This is expected for session resumption but means private keys are stored in client storage, increasing attack surface if storage is compromised.

dist/node/cjs/metamask-sdk-communication-layer.js:1
low

Dynamic code execution / eval not present but uses Function constructor indirectly?

NPS-AC31220552A3

No direct eval, Function constructor, or other dynamic code execution mechanisms are present in the provided code. However, the code uses socket.io-client and cross-fetch which are standard libraries. No obfuscated code or encoded payloads were detected.

dist/node/es/metamask-sdk-communication-layer.js
low

Environment variable or credential harvesting

NPS-2B6C9A3EB2BF

No evidence of harvesting environment variables, .npmrc, ~/.ssh, ~/.aws, or other credential files was found. The code does not read from the filesystem beyond standard module imports.

dist/node/es/metamask-sdk-communication-layer.js
low

Cryptocurrency wallet drainer / key theft

NPS-DEA83E566C2F

The code handles ECIES encryption/decryption and key exchange for secure communication between dapps and MetaMask wallet. While it manages private keys, there is no evidence of stealing keys, seed phrases, or rewriting addresses. The key exchange protocol appears to be for establishing a secure channel, which is a legitimate use case for the MetaMask SDK.

dist/node/es/metamask-sdk-communication-layer.js
low

Backdoor / reverse shell

NPS-E3690EC1DD0C

No backdoor, reverse shell, or unauthorized command execution was detected. The code uses socket.io for communication with the MetaMask communication server, which is expected for this SDK.

dist/node/es/metamask-sdk-communication-layer.js
low

Install/build/import time execution

NPS-EB47DE717EF9

The code is a library that initializes on import but does not perform any malicious actions at install, build, or import time. It sets up event listeners and communication layers when instantiated, which is standard for a communication library. No child_process, shell commands, or filesystem manipulation outside the package scope were observed.

dist/node/es/metamask-sdk-communication-layer.js
low

Dynamic code execution / eval not present but uses Function constructor indirectly?

NPS-AC31220552A3

No direct eval, Function constructor, or other dynamic code execution mechanisms are present in the provided code. However, the code uses socket.io-client and cross-fetch which are standard libraries. No obfuscated code or encoded payloads were detected.

dist/react-native/es/metamask-sdk-communication-layer.js
low

Environment variable or credential harvesting

NPS-2B6C9A3EB2BF

No evidence of harvesting environment variables, .npmrc, ~/.ssh, ~/.aws, or other credential files was found. The code does not read from the filesystem beyond standard module imports.

dist/react-native/es/metamask-sdk-communication-layer.js
low

Cryptocurrency wallet drainer / key theft

NPS-DEA83E566C2F

The code handles ECIES encryption/decryption and key exchange for secure communication between dapps and MetaMask wallet. While it manages private keys, there is no evidence of stealing keys, seed phrases, or rewriting addresses. The key exchange protocol appears to be for establishing a secure channel, which is a legitimate use case for the MetaMask SDK.

dist/react-native/es/metamask-sdk-communication-layer.js
low

Backdoor / reverse shell

NPS-E3690EC1DD0C

No backdoor, reverse shell, or unauthorized command execution was detected. The code uses socket.io for communication with the MetaMask communication server, which is expected for this SDK.

dist/react-native/es/metamask-sdk-communication-layer.js
low

Install/build/import time execution

NPS-EB47DE717EF9

The code is a library that initializes on import but does not perform any malicious actions at install, build, or import time. It sets up event listeners and communication layers when instantiated, which is standard for a communication library. No child_process, shell commands, or filesystem manipulation outside the package scope were observed.

dist/react-native/es/metamask-sdk-communication-layer.js

Files reviewed

FileVerdictWhat the reviewer saw
dist/browser/es/metamask-sdk-communication-layer.js medium The code is part of the legitimate MetaMask SDK for secure communication between dapps and wallets, but it includes analytics telemetry that sends dapp metadata to MetaMask servers and logs sensitive cryptographic keys when debug logging is enabled, posing a moderate privacy and security risk if misused.
dist/browser/umd/metamask-sdk-communication-layer.js medium The code is a legitimate MetaMask SDK communication layer that includes expected telemetry and debugging features, but it logs sensitive cryptographic keys when debug mode is enabled and sends analytics data to an external server.
dist/node/cjs/metamask-sdk-communication-layer.js medium The file is the legitimate MetaMask SDK communication layer but contains privacy-sensitive telemetry (sending analytics and metadata to a remote server) and logs private ECIES keys under debug settings; no overtly malicious backdoors, credential harvesting, or code execution were found.
dist/node/es/metamask-sdk-communication-layer.js medium The code is part of the legitimate MetaMask SDK for secure communication between dapps and wallets, but it includes analytics telemetry that sends dapp metadata to MetaMask servers and logs sensitive cryptographic keys when debug logging is enabled, posing a moderate privacy and security risk if misused.
dist/react-native/es/metamask-sdk-communication-layer.js medium The code is part of the legitimate MetaMask SDK for secure communication between dapps and wallets, but it includes analytics telemetry that sends dapp metadata to MetaMask servers and logs sensitive cryptographic keys when debug logging is enabled, posing a moderate privacy and security risk if misused.

Frequently asked questions

Is @metamask/sdk-communication-layer safe to use?

No confirmed malware was found in @metamask/sdk-communication-layer@0.33.1, but the review flagged 3 high, 7 medium, 19 low severity findings for risky patterns worth checking before you rely on it.

Does @metamask/sdk-communication-layer contain malware?

No malware was identified in @metamask/sdk-communication-layer@0.33.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @metamask/sdk-communication-layer checked?

Togoder Security downloaded the published npm package and had an AI model read its 5 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @metamask/sdk-communication-layer together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @metamask/sdk-communication-layer@0.33.1, cost nothing.

Related security reports