Summary
Togoder Security scanned the npm package @reown/appkit-controllers@1.7.8 on Oct 4, 2026. An AI review of 48 source files produced 7 medium, 19 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 26
Data exfiltration / analytics telemetry
NPS-F89DB0B72650
The controller sends analytics events to an external endpoint (CoreHelperUtil.getAnalyticsUrl() + '/e'). Payloads include the user's wallet address (AccountController.state.address), the current page URL (window.location.href), hostname, projectId, SDK type/version, and arbitrary event data. While this is expected telemetry for a wallet SDK, it constitutes transmission of potentially sensitive user data (wallet addresses, browsing context) to a third-party server and should be reviewed for privacy/compliance.
Sensitive information in error telemetry
NPS-F4BE04C86E0B
The telemetry payload includes raw error.message and error.stack. Stack traces and error messages can inadvertently contain credentials, tokens, file paths, or other sensitive data, which would be exfiltrated to the remote analytics server.
Data exfiltration / telemetry
NPS-317B0F997B7E
The code sends error telemetry to an external analytics endpoint via FetchUtil.post to '/e'. It collects window.location.href, hostname, projectId, SDK type/version, error message, and stack trace. While this appears to be intentional SDK analytics/telemetry, it transmits potentially sensitive runtime and environment data to an external server without explicit user consent in this file.
Hardcoded credential
NPS-467ABA5535E6
MELD_PUBLIC_KEY is hardcoded in the source code. While it is labeled 'public key', embedding API keys or credentials directly in a package's source exposes them to anyone who downloads the package and allows potential abuse or tracking if the key is reused elsewhere.
Potential open redirect
NPS-E2880BEEE956
The code sets popupWindow.location.href to a URI obtained from authConnector.provider.getSocialRedirectUri. If this URI is not properly validated, it could lead to open redirect vulnerabilities. However, the URI is expected to be from a trusted provider.
Data exfiltration / Telemetry transmission
NPS-A1348E13CEC4
The code imports and calls TelemetryController.sendError(error, error.category) which transmits error details to an external telemetry endpoint. Depending on the implementation of TelemetryController, this could leak sensitive information (error messages, stack traces, potentially user data) to a remote server without explicit user consent or clear disclosure.
Implicit telemetry on every error
NPS-3780EFB0176E
Every error thrown by any wrapped controller method is automatically reported to the telemetry system without opt-in control, which may violate privacy expectations and could be considered an unconsented data collection pattern.
Potential information disclosure via debug logging
NPS-FE4851313ED7
The open() method conditionally logs longMessage to console.error when debug mode is enabled. If longMessage contains sensitive user or application data, this could expose information in logs. However, this is a standard debugging pattern, not direct exfiltration.
Dynamic code execution via function callback
NPS-06E1C60C48AC
The code checks if longMessage is a function and invokes it if so. While this is typical for lazy message generation, invoking untrusted callables could be risky if the message source is externally controlled.
Dynamic network endpoint from configuration
NPS-A7CE95C84FE0
The analytics base URL is obtained at module load time via CoreHelperUtil.getAnalyticsUrl() and used to construct a FetchUtil client. If that utility can be influenced by runtime configuration or environment, event data could be redirected to an attacker-controlled endpoint.
Top-level side effect on import
NPS-667A2D799360
Module-level initialization creates a proxy state, instantiates a FetchUtil client, and captures Date.now(). While no network call fires at import, the module is immediately wired to send events when OptionsController features.analytics is enabled, so importing this module is not side-effect free.
external data sharing
NPS-56320C6DC5DE
The setSelectedProvider method constructs a URL with query parameters (publicKey, destinationCurrencyCode, walletAddress, externalCustomerId) from internal state and appends them to a third-party provider's URL. This is expected behavior for an on-ramp controller integrating with Meld, but it does share the wallet address and project ID with an external service. No credentials or environment variables are harvested.
Import-time network configuration
NPS-29F95A969D08
A FetchUtil instance is constructed at module load time with a base URL derived from CoreHelperUtil.getAnalyticsUrl(). This sets up external communication infrastructure at import time, though the actual network request is deferred until sendError is invoked.
Environment variable harvesting
NPS-2001B7B21043
The code reads process.env['NEXT_PUBLIC_SECURE_SITE_ORIGIN'] at import time. Although this specific variable is benign, dynamically reading environment variables from a third-party package can be abused to exfiltrate sensitive configuration or tokens if combined with network calls elsewhere in the package.
External origin configuration
NPS-C4659EF6C096
The default SECURE_SITE points to 'https://secure.walletconnect.org', and subsequent constants build URLs from it. If this value is overridden via an environment variable, any consumer of this package could be redirected to an attacker-controlled origin. No validation is performed on the provided URL.
Geo-restriction metadata
NPS-C7C109CA64F1
RESTRICTED_TIMEZONES includes several Asian timezones (Shanghai, Hong Kong, etc.). This is a feature-related list but could be used for region-based behavior differences; harmless by itself but worth noting for transparency.
clipboard-access
NPS-5E32A11F05E2
copyToClopboard writes text to the clipboard. This is a normal utility function, but clipboard writes should only occur on explicit user action.
use-of-window-open
NPS-EC8B3EC7E72E
openHref and returnOpenHref call window.open with user-influenced href values. The default features string includes 'noreferrer noopener' and getOpenTargetForPlatform restricts targets, so risk is low, but opening arbitrary URLs could be abused for phishing if callers pass untrusted input.
uuid-fallback-weak-randomness
NPS-5065EE951E84
getUUID falls back to Math.random-based v4 UUID generation when crypto.randomUUID is unavailable. Math.random is not cryptographically secure; if used for security-sensitive identifiers this could be a weakness.
url-injection-helper
NPS-CF1434D45271
formatTelegramSocialLoginUrl and injectIntoUrl manipulate URLs by injecting the current page href encoded into a 'state' parameter. This is intended for social login flows but could enable open redirect or state injection if the URL argument is attacker-controlled.
Telemetry event tracking
NPS-6311594C38B1
The code sends telemetry events such as 'SIWX_AUTH_SUCCESS', 'SIWX_AUTH_ERROR', and 'CLICK_CANCEL_SIWX' via EventsController. This is standard analytics behavior but constitutes outbound reporting of authentication outcomes and network/account metadata. This is not clearly malicious, but it is notable data transmission.
Console error logging of authentication failures
NPS-092EF6716026
Multiple catch blocks log errors to console, potentially including authentication or session-related error details. This is not malicious but could expose sensitive details in logs.
Signature handling and session storage
NPS-D243915B9864
The code creates SIWX authentication messages, requests wallet signatures via ConnectionController, and stores sessions including signatures. While expected for a Sign-In With X (SIWX) authentication utility, it interacts with sensitive wallet signing flows and stores auth sessions. Any bug here could impact authentication integrity, but no exfiltration or key theft patterns are present.
Suspicious network requests
NPS-F218AD3F7DC9
The code constructs and opens URLs to an external origin (ConstantsUtil.SECURE_SITE_SDK_ORIGIN) for social login popups. While this is likely a legitimate part of the appkit library for authentication, it does involve sending users to external sites and passing redirect URIs, which could be exploited if the origin is not trusted or if URIs are manipulated.
Dynamic code execution
NPS-95EE1590004A
The code uses setTimeout with a callback that throws an error. While not eval or function constructor, it schedules code execution. However, this is a common pattern and not inherently malicious.
Potential sensitive information leakage
NPS-D3A4E142199A
The custom error constructor captures and preserves original error stack traces and messages, which may contain sensitive data (file paths, tokens, internal identifiers), and these are then forwarded to the telemetry controller for transmission.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/esm/src/controllers/AlertController.js | medium | No malicious patterns detected; only minor low-risk logging and function-invocation patterns common in UI controller code. |
| dist/esm/src/controllers/EventsController.js | medium | This is legitimate wallet-SDK analytics telemetry code that transmits wallet addresses and page URLs to a configured remote endpoint; no malware, credential theft, obfuscation, or process execution was found, but the external data transmission warrants privacy review. |
| dist/esm/src/controllers/TelemetryController.js | medium | The file implements an opt-out telemetry controller that transmits error details and page URLs to an external analytics endpoint, posing a privacy/data-exfiltration risk despite lacking overtly malicious patterns like credential harvesting or code execution. |
| dist/esm/src/utils/ConstantsUtil.js | medium | The file contains constant configuration values for a wallet/onramp SDK with no execution, exfiltration, or obfuscation, but includes a hardcoded key and environment-variable-derived origin that warrant review. |
| dist/esm/src/utils/SIWXUtil.js | medium | The file contains no clear malicious patterns; it is a SIWX wallet authentication utility with standard telemetry and signing flows, though it does handle sensitive wallet session and signature data. |
| dist/esm/src/utils/SocialsUtil.js | medium | The code appears to be a legitimate social login utility with no clear malicious intent, but it involves external URL redirection and network requests that could pose low to medium security risks if not properly validated. |
| dist/esm/src/utils/withErrorBoundary.js | medium | The code does not contain obvious malicious patterns such as code execution, credential harvesting, or backdoors, but it automatically transmits error data to a telemetry service, which poses a privacy and potential data exfiltration risk that warrants caution. |
| dist/esm/exports/index.js | safe | This file is a simple barrel/export index that re-exports named entities from local source modules with no executable code, network access, file operations, or other malicious patterns. |
| dist/esm/exports/react.js | safe | No malicious patterns detected; the file contains benign React hooks for a Web3 wallet connection library. |
| dist/esm/exports/utils.js | safe | No malicious patterns detected |
| dist/esm/exports/vue.js | safe | No malicious patterns detected; the file contains only Vue composables for account state management and wallet disconnection using internal AppKit controllers. |
| dist/esm/src/controllers/AccountController.js | safe | No malicious patterns detected; the file is a standard wallet account state controller using Valtio and internal utilities. |
| dist/esm/src/controllers/ApiController.js | safe | No malicious patterns detected |
| dist/esm/src/controllers/AssetController.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/controllers/BlockchainApiController.js | safe | No malicious patterns detected; the file contains standard API controller logic for blockchain operations using a centralized FetchUtil with no exfiltration, credential harvesting, obfuscation, or harmful behaviors. |
| dist/esm/src/controllers/ChainController.js | safe | No malicious patterns detected; the file is a standard state management controller for a blockchain wallet connection library with no exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| dist/esm/src/controllers/ConnectionController.js | safe | No malicious patterns detected; the code is a standard wallet connection controller with no data exfiltration, obfuscation, or suspicious behavior. |
| dist/esm/src/controllers/ConnectorController.js | safe | No malicious patterns detected; the file is a legitimate wallet connector controller with no data exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/esm/src/controllers/EnsController.js | safe | No malicious patterns detected; the file contains standard ENS controller logic with API calls to a configured BlockchainApiController. |
| dist/esm/src/controllers/ModalController.js | safe | No malicious patterns detected; the file is a standard UI modal controller for a wallet connect library with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior. |
| dist/esm/src/controllers/OnRampController.js | safe | The code is a standard cryptocurrency on-ramp controller with no malicious patterns; the only notable behavior is passing wallet address and project ID to a third-party on-ramp provider, which is expected functionality. |
| dist/esm/src/controllers/OptionsController.js | safe | No malicious patterns detected |
| dist/esm/src/controllers/OptionsStateController.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/controllers/PublicStateController.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/controllers/RouterController.js | safe | No malicious patterns detected; the file contains only router/navigation controller logic with no network exfiltration, credential access, dynamic execution, or suspicious behavior. |
Show 23 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/esm/src/controllers/SendController.js | safe | No malicious patterns detected; the file is a standard Web3 wallet SendController with no exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/esm/src/controllers/SnackController.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/controllers/SwapController.js | safe | This is a legitimate swap controller from the Reown AppKit (WalletConnect) library with no malicious patterns; all network calls go to expected backend APIs and no sensitive data harvesting, code execution, or file system manipulation is present. |
| dist/esm/src/controllers/ThemeController.js | safe | No malicious patterns detected; the code is a legitimate theme controller with no data exfiltration, credential harvesting, code execution, or suspicious behaviors. |
| dist/esm/src/controllers/TooltipController.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/controllers/TransactionsController.js | safe | No malicious patterns detected |
| dist/esm/src/utils/AssetUtil.js | safe | No malicious patterns detected |
| dist/esm/src/utils/ChainControllerUtil.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/utils/ConnectorControllerUtil.js | safe | No malicious patterns detected; the code is a simple utility function that delegates to an imported controller without any data exfiltration, credential harvesting, obfuscation, or dynamic execution. |
| dist/esm/src/utils/CoreHelperUtil.js | safe | Utility module with minor low-severity concerns (window.open with variable URLs, clipboard write, URL state injection, weak UUID fallback) but no malicious patterns or data exfiltration detected. |
| dist/esm/src/utils/ERC7811Util.js | safe | No malicious patterns detected; the code is a utility module for ERC-7811 asset handling with no network, file system, or process manipulation. |
| dist/esm/src/utils/EnsUtil.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/utils/FetchUtil.js | safe | No malicious patterns detected; the code is a standard fetch utility wrapper with no data exfiltration, credential harvesting, obfuscation, or other suspicious behavior. |
| dist/esm/src/utils/MobileWallet.js | safe | No malicious patterns detected; the code only performs legitimate wallet deeplink redirects to well-known services based on hardcoded IDs. |
| dist/esm/src/utils/ModalUtil.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/utils/NetworkUtil.js | safe | No malicious patterns detected; the file only contains legitimate internal wallet network-switching logic. |
| dist/esm/src/utils/OptionsUtil.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/utils/RouterUtil.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/utils/SendApiUtil.js | safe | No malicious patterns detected |
| dist/esm/src/utils/StorageUtil.js | safe | This utility module only performs localStorage reads/writes for caching and connection state; no exfiltration, dynamic code execution, or suspicious patterns were detected. |
| dist/esm/src/utils/SwapApiUtil.js | safe | No malicious patterns detected; the file contains legitimate swap-related API utilities with no data exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/esm/src/utils/SwapCalculationUtil.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/utils/TypeUtil.js | safe | No malicious patterns detected |
Scanned versions of @reown/appkit-controllers
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 1.7.8 | Needs review | 48 | Oct 4, 2026 |
Frequently asked questions
Is @reown/appkit-controllers safe to use?
No confirmed malware was found in @reown/appkit-controllers@1.7.8, but the review flagged 7 medium, 19 low severity findings for risky patterns worth checking before you rely on it.
Does @reown/appkit-controllers contain malware?
No malware was identified in @reown/appkit-controllers@1.7.8 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @reown/appkit-controllers checked?
Togoder Security downloaded the published npm package and had an AI model read its 48 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @reown/appkit-controllers together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @reown/appkit-controllers@1.7.8, cost nothing.