# @metamask/utils@8.5.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:06:54.000Z
- Files reviewed: 46
- Findings: 1 medium, 3 low severity findings
- Report: https://security.togoder.click/npm/@metamask/utils@8.5.0
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @metamask/utils@8.5.0 on Oct 4, 2026. An AI review of 46 source files produced 1 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] file system manipulation

Finding ID: `NPS-1178C16E1162`

File: `dist/fs.cjs`

The module provides file system operations (readFile, writeFile, readJsonFile, writeJsonFile, forceRemove) that accept arbitrary paths from the caller. While these are expected utilities, they could be used to read or write sensitive files outside the intended package scope if the caller is not careful. The functions themselves do not enforce any path restrictions or sandboxing.

### [low] potential arbitrary code execution via custom parser

Finding ID: `NPS-0811DA3A5FA0`

File: `dist/fs.cjs`

readJsonFile and writeJsonFile accept a custom parser/stringifier object. If an attacker can control the options passed to these functions, they could supply a malicious parser that executes arbitrary code (e.g., using JSON5 with prototype pollution). However, the parser is provided by the caller, not hardcoded, and the module itself does not dynamically import or eval.

### [low] sensitive directory usage

Finding ID: `NPS-56DDBB280E78`

File: `dist/fs.cjs`

createSandbox uses os.tmpdir() to create a temporary directory. While this is standard practice, an attacker with local access could potentially predict or interfere with the sandbox directory. The directory name uses uuid.v4() which is cryptographically random, mitigating this risk.

### [low] JSON parsing safety

Finding ID: `NPS-13A97C51D03D`

File: `dist/json.cjs:80`

The code uses JSON.parse(JSON.stringify(...)) to sanitize untrusted JSON and strips __proto__ and constructor properties to prevent prototype pollution. This is a defensive security measure, not a vulnerability.

## Files reviewed

- `dist/fs.cjs` (medium): The module provides standard filesystem utilities with no apparent malicious intent, but its functions accept arbitrary paths and custom parsers, which could be misused if integrated into a larger application without proper input validation.
- `dist/assert.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/assert.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/base64.cjs` (safe): The code implements a simple base64 validation utility using superstruct patterns with no suspicious behavior.
- `dist/base64.mjs` (safe): No malicious patterns detected; the code is a straightforward base64 validation utility with no network, filesystem, process, or dynamic code execution behavior.
- `dist/bytes.cjs` (safe): No malicious patterns detected; the code is a standard utility library for byte conversion.
- `dist/bytes.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/caip-types.cjs` (safe): No malicious patterns detected; the code only defines CAIP-2/CAIP-10 validation regexes and parsing utilities without network, filesystem, or process interactions.
- `dist/caip-types.mjs` (safe): No malicious patterns detected; the file contains only CAIP validation regexes and helper functions using @metamask/superstruct.
- `dist/checksum.cjs` (safe): No malicious patterns detected
- `dist/checksum.mjs` (safe): The file only defines a Superstruct validation schema for base64 checksums with no network, filesystem, process, or dynamic execution behavior.
- `dist/coercers.cjs` (safe): No malicious patterns detected; the code is a straightforward type coercer utility from a legitimate MetaMask package with no network, filesystem, process, or dynamic execution capabilities.
- `dist/coercers.mjs` (safe): No malicious patterns detected; the code only performs value coercions and validations using @metamask/superstruct.
- `dist/collections.cjs` (safe): No malicious patterns detected; the code is a standard implementation of immutable Map and Set collections using private fields and Object.freeze.
- `dist/collections.mjs` (safe): No malicious patterns detected; the code implements immutable FrozenMap and FrozenSet collections using private fields without any suspicious behavior.
- `dist/encryption-types.cjs` (safe): No malicious patterns detected
- `dist/encryption-types.mjs` (safe): No malicious patterns detected
- `dist/errors.cjs` (safe): No malicious patterns detected; the code only provides error handling utilities with no network, filesystem, process, or dynamic execution behavior.
- `dist/errors.mjs` (safe): No malicious patterns detected
- `dist/fs.mjs` (safe): No malicious patterns detected; the file contains only standard Node.js filesystem utilities with no exfiltration, credential harvesting, obfuscation, or process execution.
- `dist/hex.cjs` (safe): No malicious patterns detected; the code is a standard utility library for Ethereum address validation and hex string handling.
- `dist/hex.mjs` (safe): No malicious patterns detected
- `dist/index.cjs` (safe): No malicious patterns detected; the file only contains standard TypeScript/CommonJS re-export boilerplate for a utility library.
- `dist/index.mjs` (safe): No malicious patterns detected
- `dist/json.cjs` (safe): No malicious patterns detected; the code implements JSON-RPC validation with explicit prototype pollution protections.
- `dist/json.mjs` (safe): No malicious patterns detected; the code performs JSON-RPC schema validation and safe JSON sanitization using the superstruct library without network, filesystem, process execution, or dynamic code evaluation.
- `dist/keyring.cjs` (safe): No malicious patterns detected
- `dist/keyring.mjs` (safe): No malicious patterns detected
- `dist/logging.cjs` (safe): The file is a straightforward logging utility that wraps the debug library with no malicious patterns detected.
- `dist/logging.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/misc.cjs` (safe): No malicious patterns detected; the file contains only utility functions for type guards and JSON size calculations.
- `dist/misc.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/node.cjs` (safe): No malicious patterns detected
- `dist/node.mjs` (safe): This file only re-exports modules from other local files with no suspicious or malicious patterns.
- `dist/number.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/number.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/opaque.cjs` (safe): No malicious patterns detected
- `dist/opaque.mjs` (safe): No malicious patterns detected
- `dist/promise.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/promise.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `dist/time.cjs` (safe): No malicious patterns detected; the file only defines duration constants and simple timestamp utility functions with input validation.
- `dist/time.mjs` (safe): No malicious patterns detected; the code only provides duration constants and simple time utilities with input validation.
- `dist/transaction-types.cjs` (safe): The file is a minimal CommonJS module stub containing only standard export and source map directives, with no executable or malicious logic.
- `dist/transaction-types.mjs` (safe): No malicious patterns detected; the file is an empty ES module with only a sourcemap reference.
- `dist/versions.cjs` (safe): No malicious patterns detected; the file contains only SemVer validation utilities from MetaMask's superstruct/semver wrappers.
- `dist/versions.mjs` (safe): The code is a standard SemVer validation and comparison utility using @metamask/superstruct and semver, with no malicious patterns detected.

## Version ranges

None of the 5 scanned versions of @metamask/utils are flagged high or critical. The latest scanned version, 12.0.0, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 12.0.0 (`12.0.0`): clean
- 11.11.0 – 11.12.1 (`>=11.11.0 <=11.12.1`): not scanned
- 8.5.0 – 11.8.1 (`>=8.5.0 <=11.8.1`): medium (file system manipulation)
- 5.0.2 (`5.0.2`): clean

## Scanned versions

- [12.0.0](https://security.togoder.click/npm/@metamask/utils@12.0.0): safe, 2026-10-04T21:27:24.000Z
- [11.8.1](https://security.togoder.click/npm/@metamask/utils@11.8.1): medium, 2026-10-04T16:08:47.000Z
- [9.3.0](https://security.togoder.click/npm/@metamask/utils@9.3.0): medium, 2026-10-04T16:06:58.000Z
- [8.5.0](https://security.togoder.click/npm/@metamask/utils@8.5.0): medium, 2026-10-04T16:06:54.000Z
- [5.0.2](https://security.togoder.click/npm/@metamask/utils@5.0.2): safe, 2026-10-04T16:07:01.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
