Summary
Togoder Security scanned the npm package @metamask/utils@11.8.1 on Oct 4, 2026. An AI review of 50 source files produced 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 3
file system manipulation
NPS-1178C16E1162
The module provides file system operations (readFile, writeFile, readJsonFile, writeJsonFile, forceRemove) that accept arbitrary paths from the caller. While these are expected utilities, they could be used to read or write sensitive files outside the intended package scope if the caller is not careful. The functions themselves do not enforce any path restrictions or sandboxing.
potential arbitrary code execution via custom parser
NPS-0811DA3A5FA0
readJsonFile and writeJsonFile accept a custom parser/stringifier object. If an attacker can control the options passed to these functions, they could supply a malicious parser that executes arbitrary code (e.g., using JSON5 with prototype pollution). However, the parser is provided by the caller, not hardcoded, and the module itself does not dynamically import or eval.
sensitive directory usage
NPS-56DDBB280E78
createSandbox uses os.tmpdir() to create a temporary directory. While this is standard practice, an attacker with local access could potentially predict or interfere with the sandbox directory. The directory name uses uuid.v4() which is cryptographically random, mitigating this risk.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/fs.cjs | medium | The module provides standard filesystem utilities with no apparent malicious intent, but its functions accept arbitrary paths and custom parsers, which could be misused if integrated into a larger application without proper input validation. |
| dist/assert.cjs | safe | Cleared by Jev triage; no further analysis needed |
| dist/assert.mjs | safe | Cleared by Jev triage; no further analysis needed |
| dist/base64.cjs | safe | The code implements a simple base64 validation utility using superstruct patterns with no suspicious behavior. |
| dist/base64.mjs | safe | No malicious patterns detected; the code is a straightforward base64 validation utility with no network, filesystem, process, or dynamic code execution behavior. |
| dist/bytes.cjs | safe | No malicious patterns detected; the module contains only standard byte/hex/base64 conversion utilities with no network, filesystem, process, or dynamic execution behavior. |
| dist/bytes.mjs | safe | This is a legitimate byte manipulation utility library with no malicious patterns; all imports are local or from a well-known base encoding library, and there is no network, filesystem, process execution, or dynamic code loading behavior. |
| dist/caip-types.cjs | safe | No malicious patterns detected; the code only defines CAIP validation regexes, type structs, and pure validation/formatting functions with no network, filesystem, process, or dynamic execution behavior. |
| dist/caip-types.mjs | safe | This file contains only CAIP validation regexes, type parsers, and constructors with no network, file system, process, eval, or credential access patterns. |
| dist/checksum.cjs | safe | No malicious patterns detected |
| dist/checksum.mjs | safe | The file only defines a Superstruct validation schema for base64 checksums with no network, filesystem, process, or dynamic execution behavior. |
| dist/coercers.cjs | safe | No malicious patterns detected; the code is a straightforward type coercer utility from a legitimate MetaMask package with no network, filesystem, process, or dynamic execution capabilities. |
| dist/coercers.mjs | safe | No malicious patterns detected; the code only performs value coercions and validations using @metamask/superstruct. |
| dist/collections.cjs | safe | No malicious patterns detected; the code is a standard implementation of immutable Map and Set collections using private fields and Object.freeze. |
| dist/collections.mjs | safe | No malicious patterns detected; the code implements immutable FrozenMap and FrozenSet collections using private fields without any suspicious behavior. |
| dist/encryption-types.cjs | safe | No malicious patterns detected |
| dist/encryption-types.mjs | safe | No malicious patterns detected |
| dist/errors.cjs | safe | No malicious patterns detected; the code only provides error handling utilities with no network, filesystem, process, or dynamic execution behavior. |
| dist/errors.mjs | safe | No malicious patterns detected |
| dist/fs.mjs | safe | No malicious patterns detected; the file contains only standard Node.js filesystem utilities with no exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/hex.cjs | safe | No malicious patterns detected; the code is a legitimate utility for hex string validation and ERC-55 checksum address handling. |
| dist/hex.mjs | safe | No malicious patterns detected |
| dist/index.cjs | safe | No malicious patterns detected; the file is a standard CommonJS re-export entry point with only relative module imports. |
| dist/index.mjs | safe | This file is a standard barrel re-export module with no executable logic, network requests, file system access, or other malicious patterns. |
| dist/json.cjs | safe | No malicious patterns detected; the code is a legitimate JSON-RPC validation module from MetaMask's superstruct-based utilities. |
Show 25 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/json.mjs | safe | No malicious patterns detected; the code is a legitimate JSON/JSON-RPC validation utility using MetaMask superstruct, with explicit protection against prototype pollution. |
| dist/keyring.cjs | safe | No malicious patterns detected |
| dist/keyring.mjs | safe | No malicious patterns detected |
| dist/logging.cjs | safe | The file is a straightforward logging utility that wraps the debug library with no malicious patterns detected. |
| dist/logging.mjs | safe | Cleared by Jev triage; no further analysis needed |
| dist/misc.cjs | safe | No malicious patterns detected; the file contains only utility functions for type guards and JSON size calculations. |
| dist/misc.mjs | safe | Cleared by Jev triage; no further analysis needed |
| dist/node.cjs | safe | No malicious patterns detected |
| dist/node.mjs | safe | This file only re-exports modules from other local files with no suspicious or malicious patterns. |
| dist/number.cjs | safe | Cleared by Jev triage; no further analysis needed |
| dist/number.mjs | safe | Cleared by Jev triage; no further analysis needed |
| dist/opaque.cjs | safe | No malicious patterns detected |
| dist/opaque.mjs | safe | No malicious patterns detected |
| dist/promise.cjs | safe | Cleared by Jev triage; no further analysis needed |
| dist/promise.mjs | safe | Cleared by Jev triage; no further analysis needed |
| dist/superstruct.cjs | safe | Cleared by Jev triage; no further analysis needed |
| dist/superstruct.mjs | safe | Cleared by Jev triage; no further analysis needed |
| dist/time.cjs | safe | No malicious patterns detected; the file only defines duration constants and simple timestamp utility functions with input validation. |
| dist/time.mjs | safe | No malicious patterns detected; the code only provides duration constants and simple time utilities with input validation. |
| dist/transaction-types.cjs | safe | The file is a minimal CommonJS module stub containing only standard export and source map directives, with no executable or malicious logic. |
| dist/transaction-types.mjs | safe | No malicious patterns detected; the file is an empty ES module with only a sourcemap reference. |
| dist/unitsConversion.cjs | safe | No malicious patterns detected |
| dist/unitsConversion.mjs | safe | Cleared by Jev triage; no further analysis needed |
| dist/versions.cjs | safe | No malicious patterns detected; the file contains only SemVer validation utilities from MetaMask's superstruct/semver wrappers. |
| dist/versions.mjs | safe | The code is a standard SemVer validation and comparison utility using @metamask/superstruct and semver, with no malicious patterns detected. |
Affected version ranges
None of the 5 scanned versions of @metamask/utils are flagged high or critical. The latest scanned version, 12.0.0, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 12.0.0 | No issues | 1 | 12.0.0 | |
| 11.11.0 – 11.12.1 | Not scanned | 2 | >=11.11.0 <=11.12.1 | |
| 8.5.0 – 11.8.1 | Needs review | 3 | >=8.5.0 <=11.8.1 | file system manipulation |
| 5.0.2 | No issues | 1 | 5.0.2 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of @metamask/utils
Frequently asked questions
Is @metamask/utils safe to use?
No confirmed malware was found in @metamask/utils@11.8.1, but the review flagged 1 medium, 2 low severity findings for risky patterns worth checking before you rely on it.
Does @metamask/utils contain malware?
No malware was identified in @metamask/utils@11.8.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @metamask/utils checked?
Togoder Security downloaded the published npm package and had an AI model read its 50 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @metamask/utils together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @metamask/utils@11.8.1, cost nothing.