Togoder security

npm package security report

@reown/appkit npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 1.7.8 Files reviewed 43 Size 142.1 KB Scanned

Summary

Togoder Security scanned the npm package @reown/appkit@1.7.8 on Oct 4, 2026. An AI review of 43 source files produced 1 medium, 13 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
13
low

Findings 14

medium

Network-related functionality

NPS-EB84C01E3B15

The imported AppKit from '@reown/appkit-controllers' and related classes likely perform network requests (wallet connection, blockchain interactions). While this is expected for a wallet connector library, it represents potential data exfiltration or interaction with external servers if maliciously tampered with. No direct suspicious network calls are present in this file.

dist/esm/exports/vue-core.js
low

Suspicious import pattern

NPS-BC7E451E04DE

Empty import statement import {} from '@reown/appkit-controllers'; is unusual and may be used to trigger side effects in the module without importing any bindings. Combined with the package being a third-party crypto wallet library, this warrants scrutiny for hidden behavior.

dist/esm/exports/react-core.js:1
low

Global state mutation on import

NPS-A4CA4D49D439

Exported mutable variable modal is undefined initially and can be set by createAppKit. While not inherently malicious, this creates a singleton pattern that could be exploited if the module is later tampered with. The createAppKit function instantiates AppKit with user-provided options and a hardcoded sdkVersion, which is normal for such libraries.

dist/esm/exports/react-core.js:15
low

Use of optional chaining for network switch

NPS-44995F6C5AFD

modal?.switchNetwork(network) silently fails if modal is not initialized. This is a design choice, not a security flaw, but could hide errors. No direct malicious intent detected.

dist/esm/exports/react-core.js:33
low

Dynamic imports not observed

NPS-11ACD88D6A35

No dynamic imports or computed module loading are present.

dist/esm/exports/vue-core.js
low

Top-level code execution on import

NPS-FCFF82250F6D

The module initializes a mutable modal variable and uses top-level logic but no actual execution; however, the createAppKit function creates an AppKit instance and calls getAppKit(modal), which could have side effects when invoked. Importing this module alone does not execute createAppKit, but consumers calling it could trigger network or state changes.

dist/esm/exports/vue-core.js:7
low

Global mutable state

NPS-7B50CCCF4880

The module-level modal variable may be shared across imports, leading to unexpected singleton behavior. This is not malicious but can cause security-relevant side effects if not intended.

dist/esm/exports/vue-core.js:15
low

wallet-connection-control

NPS-0FAA5A5AA5F7

The class extends AppKitBaseClient and imports controllers (ConnectionController, ConnectorController, AccountController) from '@reown/appkit-controllers'. This is a wallet-connection library. Wallet-related packages are common targets for supply-chain tampering (wallet drainers). No direct key/seed phrase handling or address rewriting is visible in this file, but the sink for wallet interactions exists here.

dist/esm/src/client/appkit-core.js:15
low

dynamic-import

NPS-DA0909E79B73

The injectModalUi method performs dynamic imports of '@reown/appkit-scaffold-ui/basic' and '@reown/appkit-scaffold-ui/w3m-modal'. While these are static string imports (not computed from user input), dynamic import() is a module loading mechanism that could be used to load arbitrary code if the package name or resolution is compromised/tampered with upstream. This is low risk here since the specifiers are hardcoded.

dist/esm/src/client/appkit-core.js:24
low

dom-manipulation

NPS-03369F11B193

The injectModalUi method creates and inserts a custom element ('w3m-modal') into document.body at runtime. This is UI injection and could be abused if the injected element or associated scaffold-ui modules contain malicious behavior. Insertion is guarded by disableAppend/enableEmbedded options, which is reasonable, but the runtime DOM injection into the host page is worth noting.

dist/esm/src/client/appkit-core.js:29
low

Dynamic imports based on remote feature flags

NPS-9004FF9D78FC

loadModalComponents() dynamically imports multiple internal modules (embedded-wallet, email, socials, swaps, send, receive, onramp, transactions, pay) conditionally based on remoteFeatures sourced from a remote configuration server. While the import specifiers are static strings, the decision to load them is influenced by remote data, which could be abused if the remote config endpoint were compromised to control code loading behavior. This is a minor supply-chain/modularity concern rather than direct malicious behavior.

dist/esm/src/client/appkit.js
low

Reading URL search params and browser history manipulation

NPS-E02BB94727AA

checkExistingTelegramSocialConnection() reads window.location.href search params (result_uri) and uses window.history.replaceState to strip it. This is standard OAuth/social login redirect handling, but it does process externally-controlled URL parameters and passes them as socialUri into ConnectionController.connectExternal, which can initiate an external wallet connection. Not inherently malicious but worth noting as a trust boundary.

dist/esm/src/client/appkit.js
low

Remote feature gating for account/wallet UI

NPS-2F20B3294DC7

The client pulls remoteFeatures (email, socials, swaps, onramp, activity, etc.) from a remote source and enables financial UI features based on them. If the remote feature endpoint were tampered with, it could alter which wallet operations are exposed. This is a design-level trust dependency rather than an exploit in this file.

dist/esm/src/client/appkit.js
low

Third-party payload in iframe (W3mFrameProvider)

NPS-A981A3841060

The auth provider creates a W3mFrameProvider that communicates with an embedded modal/iframe to handle wallet operations, emails, and RPC requests. Interactions with an embedded wallet iframe can be a vector for XSS/data leakage if origin validation is weak; however no such validation logic is visible here and this appears to be the legitimate Reown AppKit auth flow.

dist/esm/src/client/appkit.js

Files reviewed

FileVerdictWhat the reviewer saw
dist/esm/exports/react-core.js medium The code appears to be a legitimate React wrapper for the Reown AppKit cryptocurrency wallet library, with no clear malicious patterns such as data exfiltration, credential harvesting, or dynamic code execution.
dist/esm/exports/vue-core.js medium The code appears to be a legitimate Vue integration for AppKit, with no direct malicious patterns, but it includes network-capable wallet functionality and global mutable state that could be risky if abused.
dist/esm/src/client/appkit-core.js medium No direct malicious patterns (exfiltration, credential harvesting, eval, shell exec, install-time hooks) are present; findings are limited to low-risk dynamic imports and runtime DOM injection typical of this legitimate wallet-connection UI package, though supply-chain integrity of the referenced @reown packages should be verified.
dist/esm/src/client/appkit.js medium This is legitimate Reown AppKit client code; no classic malicious patterns (exfiltration, credential harvesting, obfuscation, shells, mining, wallet draining) are present, but remote-feature-driven dynamic imports and embedded iframe interactions represent minor trust-boundary concerns.
dist/esm/exports/adapters.js safe This file is a simple ESM re-export shim pointing to the package's own internal adapters module and contains no malicious patterns.
dist/esm/exports/auth-provider.js safe No malicious patterns detected
dist/esm/exports/connectors.js safe This file is a simple ES module re-export with no executable logic or suspicious patterns.
dist/esm/exports/constants.js safe No malicious patterns detected
dist/esm/exports/core.js safe No malicious patterns detected
dist/esm/exports/index.js safe No malicious patterns detected; this is a clean entry point re-exporting public AppKit modules and creating an AppKit instance.
dist/esm/exports/library/react.js safe No malicious patterns detected
dist/esm/exports/library/vue.js safe No malicious patterns detected
dist/esm/exports/networks.js safe The file is a simple re-export module with no malicious patterns detected.
dist/esm/exports/react.js safe No malicious patterns detected in the analyzed React export module.
dist/esm/exports/store.js safe No malicious patterns detected in the re-export file; it only forwards exports from the internal store module.
dist/esm/exports/utils.js safe This is a simple ES module re-export barrel file with a source map reference; no malicious patterns or suspicious behavior detected.
dist/esm/exports/vue.js safe No malicious patterns detected; the code is a standard Vue integration layer for a wallet connection SDK.
dist/esm/src/adapters/ChainAdapterBlueprint.js safe No malicious patterns detected; the code is a standard abstract adapter blueprint for WalletConnect integration with no exfiltration, obfuscation, or harmful behavior.
dist/esm/src/adapters/ChainAdapterConnector.js safe No malicious patterns detected
dist/esm/src/adapters/index.js safe No malicious patterns detected; the file is a simple re-export of a class from a sibling module.
dist/esm/src/auth-provider/W3MFrameProviderSingleton.js safe No malicious patterns detected; this is a simple singleton wrapper around W3mFrameProvider with no network, filesystem, or process activity.
dist/esm/src/auth-provider/index.js safe No malicious patterns detected
dist/esm/src/client/appkit-base-client.js safe No malicious patterns detected; this is a legitimate WalletConnect/AppKit client library implementing standard wallet integration, connection management, and account synchronization functionality.
dist/esm/src/connectors/WalletConnectConnector.js safe No malicious patterns detected; the file is a legitimate WalletConnect connector implementation for a web3 wallet library with standard connection and authentication logic.
dist/esm/src/connectors/index.js safe This file only re-exports a WalletConnect connector module and contains no malicious patterns, dynamic imports, or executable code beyond a standard ES module export.
Show 18 more files
FileVerdictWhat the reviewer saw
dist/esm/src/library/react/index.js safe No malicious patterns detected; the file contains standard React hooks for wallet integration with no data exfiltration, credential harvesting, obfuscation, or suspicious system operations.
dist/esm/src/library/vue/index.js safe No malicious patterns detected; the code is a standard Vue integration layer for Reown AppKit with hooks and subscriptions.
dist/esm/src/networks/bitcoin.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/networks/index.js safe No malicious patterns detected
dist/esm/src/networks/solana/index.js safe No malicious patterns detected; the file only re-exports three local Solana network modules and contains no executable logic.
dist/esm/src/networks/solana/solana.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/networks/solana/solanaDevnet.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/networks/solana/solanaTestnet.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/networks/utils.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/store/index.js safe No malicious patterns detected; the file only re-exports a utility from a known dependency.
dist/esm/src/universal-adapter/client.js safe No malicious patterns detected; the code is a legitimate blockchain wallet adapter implementation with standard cryptographic operations and no exfiltration, obfuscation, or backdoor behavior.
dist/esm/src/universal-adapter/index.js safe No malicious patterns detected
dist/esm/src/utils/BalanceUtil.js safe No malicious patterns detected
dist/esm/src/utils/ConfigUtil.js safe No malicious patterns detected; the code is a legitimate feature-configuration utility for Reown AppKit that fetches remote project settings and manages feature flags without any exfiltration, credential harvesting, or code execution.
dist/esm/src/utils/ConstantsUtil.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/utils/HelpersUtil.js safe No malicious patterns detected; the code contains only standard wallet-connection helper utilities for Reown/WalletConnect with no exfiltration, dynamic execution, or credential harvesting.
dist/esm/src/utils/TypesUtil.js safe No malicious patterns detected
dist/esm/src/utils/index.js safe No malicious patterns detected; the file only re-exports other modules and contains a source map comment.

Scanned versions of @reown/appkit

VersionVerdictFilesScanned
1.7.8 Needs review 43 Oct 4, 2026

Frequently asked questions

Is @reown/appkit safe to use?

No confirmed malware was found in @reown/appkit@1.7.8, but the review flagged 1 medium, 13 low severity findings for risky patterns worth checking before you rely on it.

Does @reown/appkit contain malware?

No malware was identified in @reown/appkit@1.7.8 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @reown/appkit checked?

Togoder Security downloaded the published npm package and had an AI model read its 43 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @reown/appkit together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @reown/appkit@1.7.8, cost nothing.

Related security reports