Togoder security

npm package security report

@reown/appkit-controllers npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 1.7.8 Files reviewed 48 Size 259.2 KB Scanned

Summary

Togoder Security scanned the npm package @reown/appkit-controllers@1.7.8 on Oct 4, 2026. An AI review of 48 source files produced 7 medium, 19 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
7
medium
19
low

Findings 26

medium

Data exfiltration / analytics telemetry

NPS-F89DB0B72650

The controller sends analytics events to an external endpoint (CoreHelperUtil.getAnalyticsUrl() + '/e'). Payloads include the user's wallet address (AccountController.state.address), the current page URL (window.location.href), hostname, projectId, SDK type/version, and arbitrary event data. While this is expected telemetry for a wallet SDK, it constitutes transmission of potentially sensitive user data (wallet addresses, browsing context) to a third-party server and should be reviewed for privacy/compliance.

dist/esm/src/controllers/EventsController.js:30
medium

Sensitive information in error telemetry

NPS-F4BE04C86E0B

The telemetry payload includes raw error.message and error.stack. Stack traces and error messages can inadvertently contain credentials, tokens, file paths, or other sensitive data, which would be exfiltrated to the remote analytics server.

dist/esm/src/controllers/TelemetryController.js:60
medium

Data exfiltration / telemetry

NPS-317B0F997B7E

The code sends error telemetry to an external analytics endpoint via FetchUtil.post to '/e'. It collects window.location.href, hostname, projectId, SDK type/version, error message, and stack trace. While this appears to be intentional SDK analytics/telemetry, it transmits potentially sensitive runtime and environment data to an external server without explicit user consent in this file.

dist/esm/src/controllers/TelemetryController.js:63
medium

Hardcoded credential

NPS-467ABA5535E6

MELD_PUBLIC_KEY is hardcoded in the source code. While it is labeled 'public key', embedding API keys or credentials directly in a package's source exposes them to anyone who downloads the package and allows potential abuse or tracking if the key is reused elsewhere.

dist/esm/src/utils/ConstantsUtil.js:22
medium

Potential open redirect

NPS-E2880BEEE956

The code sets popupWindow.location.href to a URI obtained from authConnector.provider.getSocialRedirectUri. If this URI is not properly validated, it could lead to open redirect vulnerabilities. However, the URI is expected to be from a trusted provider.

dist/esm/src/utils/SocialsUtil.js:52
medium

Data exfiltration / Telemetry transmission

NPS-A1348E13CEC4

The code imports and calls TelemetryController.sendError(error, error.category) which transmits error details to an external telemetry endpoint. Depending on the implementation of TelemetryController, this could leak sensitive information (error messages, stack traces, potentially user data) to a remote server without explicit user consent or clear disclosure.

dist/esm/src/utils/withErrorBoundary.js:62
medium

Implicit telemetry on every error

NPS-3780EFB0176E

Every error thrown by any wrapped controller method is automatically reported to the telemetry system without opt-in control, which may violate privacy expectations and could be considered an unconsented data collection pattern.

dist/esm/src/utils/withErrorBoundary.js:62
low

Potential information disclosure via debug logging

NPS-FE4851313ED7

The open() method conditionally logs longMessage to console.error when debug mode is enabled. If longMessage contains sensitive user or application data, this could expose information in logs. However, this is a standard debugging pattern, not direct exfiltration.

dist/esm/src/controllers/AlertController.js:21
low

Dynamic code execution via function callback

NPS-06E1C60C48AC

The code checks if longMessage is a function and invokes it if so. While this is typical for lazy message generation, invoking untrusted callables could be risky if the message source is externally controlled.

dist/esm/src/controllers/AlertController.js:21
low

Dynamic network endpoint from configuration

NPS-A7CE95C84FE0

The analytics base URL is obtained at module load time via CoreHelperUtil.getAnalyticsUrl() and used to construct a FetchUtil client. If that utility can be influenced by runtime configuration or environment, event data could be redirected to an attacker-controlled endpoint.

dist/esm/src/controllers/EventsController.js:10
low

Top-level side effect on import

NPS-667A2D799360

Module-level initialization creates a proxy state, instantiates a FetchUtil client, and captures Date.now(). While no network call fires at import, the module is immediately wired to send events when OptionsController features.analytics is enabled, so importing this module is not side-effect free.

dist/esm/src/controllers/EventsController.js:13
low

external data sharing

NPS-56320C6DC5DE

The setSelectedProvider method constructs a URL with query parameters (publicKey, destinationCurrencyCode, walletAddress, externalCustomerId) from internal state and appends them to a third-party provider's URL. This is expected behavior for an on-ramp controller integrating with Meld, but it does share the wallet address and project ID with an external service. No credentials or environment variables are harvested.

dist/esm/src/controllers/OnRampController.js:85
low

Import-time network configuration

NPS-29F95A969D08

A FetchUtil instance is constructed at module load time with a base URL derived from CoreHelperUtil.getAnalyticsUrl(). This sets up external communication infrastructure at import time, though the actual network request is deferred until sendError is invoked.

dist/esm/src/controllers/TelemetryController.js:10
low

Environment variable harvesting

NPS-2001B7B21043

The code reads process.env['NEXT_PUBLIC_SECURE_SITE_ORIGIN'] at import time. Although this specific variable is benign, dynamically reading environment variables from a third-party package can be abused to exfiltrate sensitive configuration or tokens if combined with network calls elsewhere in the package.

dist/esm/src/utils/ConstantsUtil.js:2
low

External origin configuration

NPS-C4659EF6C096

The default SECURE_SITE points to 'https://secure.walletconnect.org', and subsequent constants build URLs from it. If this value is overridden via an environment variable, any consumer of this package could be redirected to an attacker-controlled origin. No validation is performed on the provided URL.

dist/esm/src/utils/ConstantsUtil.js:5
low

Geo-restriction metadata

NPS-C7C109CA64F1

RESTRICTED_TIMEZONES includes several Asian timezones (Shanghai, Hong Kong, etc.). This is a feature-related list but could be used for region-based behavior differences; harmless by itself but worth noting for transparency.

dist/esm/src/utils/ConstantsUtil.js:33
low

clipboard-access

NPS-5E32A11F05E2

copyToClopboard writes text to the clipboard. This is a normal utility function, but clipboard writes should only occur on explicit user action.

dist/esm/src/utils/CoreHelperUtil.js:41
low

use-of-window-open

NPS-EC8B3EC7E72E

openHref and returnOpenHref call window.open with user-influenced href values. The default features string includes 'noreferrer noopener' and getOpenTargetForPlatform restricts targets, so risk is low, but opening arbitrary URLs could be abused for phishing if callers pass untrusted input.

dist/esm/src/utils/CoreHelperUtil.js:128
low

uuid-fallback-weak-randomness

NPS-5065EE951E84

getUUID falls back to Math.random-based v4 UUID generation when crypto.randomUUID is unavailable. Math.random is not cryptographically secure; if used for security-sensitive identifiers this could be a weakness.

dist/esm/src/utils/CoreHelperUtil.js:222
low

url-injection-helper

NPS-CF1434D45271

formatTelegramSocialLoginUrl and injectIntoUrl manipulate URLs by injecting the current page href encoded into a 'state' parameter. This is intended for social login flows but could enable open redirect or state injection if the URL argument is attacker-controlled.

dist/esm/src/utils/CoreHelperUtil.js:263
low

Telemetry event tracking

NPS-6311594C38B1

The code sends telemetry events such as 'SIWX_AUTH_SUCCESS', 'SIWX_AUTH_ERROR', and 'CLICK_CANCEL_SIWX' via EventsController. This is standard analytics behavior but constitutes outbound reporting of authentication outcomes and network/account metadata. This is not clearly malicious, but it is notable data transmission.

dist/esm/src/utils/SIWXUtil.js:25
low

Console error logging of authentication failures

NPS-092EF6716026

Multiple catch blocks log errors to console, potentially including authentication or session-related error details. This is not malicious but could expose sensitive details in logs.

dist/esm/src/utils/SIWXUtil.js:30
low

Signature handling and session storage

NPS-D243915B9864

The code creates SIWX authentication messages, requests wallet signatures via ConnectionController, and stores sessions including signatures. While expected for a Sign-In With X (SIWX) authentication utility, it interacts with sensitive wallet signing flows and stores auth sessions. Any bug here could impact authentication integrity, but no exfiltration or key theft patterns are present.

dist/esm/src/utils/SIWXUtil.js:84
low

Suspicious network requests

NPS-F218AD3F7DC9

The code constructs and opens URLs to an external origin (ConstantsUtil.SECURE_SITE_SDK_ORIGIN) for social login popups. While this is likely a legitimate part of the appkit library for authentication, it does involve sending users to external sites and passing redirect URIs, which could be exploited if the origin is not trusted or if URIs are manipulated.

dist/esm/src/utils/SocialsUtil.js:10
low

Dynamic code execution

NPS-95EE1590004A

The code uses setTimeout with a callback that throws an error. While not eval or function constructor, it schedules code execution. However, this is a common pattern and not inherently malicious.

dist/esm/src/utils/SocialsUtil.js:38
low

Potential sensitive information leakage

NPS-D3A4E142199A

The custom error constructor captures and preserves original error stack traces and messages, which may contain sensitive data (file paths, tokens, internal identifiers), and these are then forwarded to the telemetry controller for transmission.

dist/esm/src/utils/withErrorBoundary.js:20

Files reviewed

FileVerdictWhat the reviewer saw
dist/esm/src/controllers/AlertController.js medium No malicious patterns detected; only minor low-risk logging and function-invocation patterns common in UI controller code.
dist/esm/src/controllers/EventsController.js medium This is legitimate wallet-SDK analytics telemetry code that transmits wallet addresses and page URLs to a configured remote endpoint; no malware, credential theft, obfuscation, or process execution was found, but the external data transmission warrants privacy review.
dist/esm/src/controllers/TelemetryController.js medium The file implements an opt-out telemetry controller that transmits error details and page URLs to an external analytics endpoint, posing a privacy/data-exfiltration risk despite lacking overtly malicious patterns like credential harvesting or code execution.
dist/esm/src/utils/ConstantsUtil.js medium The file contains constant configuration values for a wallet/onramp SDK with no execution, exfiltration, or obfuscation, but includes a hardcoded key and environment-variable-derived origin that warrant review.
dist/esm/src/utils/SIWXUtil.js medium The file contains no clear malicious patterns; it is a SIWX wallet authentication utility with standard telemetry and signing flows, though it does handle sensitive wallet session and signature data.
dist/esm/src/utils/SocialsUtil.js medium The code appears to be a legitimate social login utility with no clear malicious intent, but it involves external URL redirection and network requests that could pose low to medium security risks if not properly validated.
dist/esm/src/utils/withErrorBoundary.js medium The code does not contain obvious malicious patterns such as code execution, credential harvesting, or backdoors, but it automatically transmits error data to a telemetry service, which poses a privacy and potential data exfiltration risk that warrants caution.
dist/esm/exports/index.js safe This file is a simple barrel/export index that re-exports named entities from local source modules with no executable code, network access, file operations, or other malicious patterns.
dist/esm/exports/react.js safe No malicious patterns detected; the file contains benign React hooks for a Web3 wallet connection library.
dist/esm/exports/utils.js safe No malicious patterns detected
dist/esm/exports/vue.js safe No malicious patterns detected; the file contains only Vue composables for account state management and wallet disconnection using internal AppKit controllers.
dist/esm/src/controllers/AccountController.js safe No malicious patterns detected; the file is a standard wallet account state controller using Valtio and internal utilities.
dist/esm/src/controllers/ApiController.js safe No malicious patterns detected
dist/esm/src/controllers/AssetController.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/controllers/BlockchainApiController.js safe No malicious patterns detected; the file contains standard API controller logic for blockchain operations using a centralized FetchUtil with no exfiltration, credential harvesting, obfuscation, or harmful behaviors.
dist/esm/src/controllers/ChainController.js safe No malicious patterns detected; the file is a standard state management controller for a blockchain wallet connection library with no exfiltration, credential harvesting, obfuscation, or suspicious behavior.
dist/esm/src/controllers/ConnectionController.js safe No malicious patterns detected; the code is a standard wallet connection controller with no data exfiltration, obfuscation, or suspicious behavior.
dist/esm/src/controllers/ConnectorController.js safe No malicious patterns detected; the file is a legitimate wallet connector controller with no data exfiltration, credential harvesting, obfuscation, or process execution.
dist/esm/src/controllers/EnsController.js safe No malicious patterns detected; the file contains standard ENS controller logic with API calls to a configured BlockchainApiController.
dist/esm/src/controllers/ModalController.js safe No malicious patterns detected; the file is a standard UI modal controller for a wallet connect library with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior.
dist/esm/src/controllers/OnRampController.js safe The code is a standard cryptocurrency on-ramp controller with no malicious patterns; the only notable behavior is passing wallet address and project ID to a third-party on-ramp provider, which is expected functionality.
dist/esm/src/controllers/OptionsController.js safe No malicious patterns detected
dist/esm/src/controllers/OptionsStateController.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/controllers/PublicStateController.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/controllers/RouterController.js safe No malicious patterns detected; the file contains only router/navigation controller logic with no network exfiltration, credential access, dynamic execution, or suspicious behavior.
Show 23 more files
FileVerdictWhat the reviewer saw
dist/esm/src/controllers/SendController.js safe No malicious patterns detected; the file is a standard Web3 wallet SendController with no exfiltration, credential harvesting, obfuscation, or process execution.
dist/esm/src/controllers/SnackController.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/controllers/SwapController.js safe This is a legitimate swap controller from the Reown AppKit (WalletConnect) library with no malicious patterns; all network calls go to expected backend APIs and no sensitive data harvesting, code execution, or file system manipulation is present.
dist/esm/src/controllers/ThemeController.js safe No malicious patterns detected; the code is a legitimate theme controller with no data exfiltration, credential harvesting, code execution, or suspicious behaviors.
dist/esm/src/controllers/TooltipController.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/controllers/TransactionsController.js safe No malicious patterns detected
dist/esm/src/utils/AssetUtil.js safe No malicious patterns detected
dist/esm/src/utils/ChainControllerUtil.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/utils/ConnectorControllerUtil.js safe No malicious patterns detected; the code is a simple utility function that delegates to an imported controller without any data exfiltration, credential harvesting, obfuscation, or dynamic execution.
dist/esm/src/utils/CoreHelperUtil.js safe Utility module with minor low-severity concerns (window.open with variable URLs, clipboard write, URL state injection, weak UUID fallback) but no malicious patterns or data exfiltration detected.
dist/esm/src/utils/ERC7811Util.js safe No malicious patterns detected; the code is a utility module for ERC-7811 asset handling with no network, file system, or process manipulation.
dist/esm/src/utils/EnsUtil.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/utils/FetchUtil.js safe No malicious patterns detected; the code is a standard fetch utility wrapper with no data exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
dist/esm/src/utils/MobileWallet.js safe No malicious patterns detected; the code only performs legitimate wallet deeplink redirects to well-known services based on hardcoded IDs.
dist/esm/src/utils/ModalUtil.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/utils/NetworkUtil.js safe No malicious patterns detected; the file only contains legitimate internal wallet network-switching logic.
dist/esm/src/utils/OptionsUtil.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/utils/RouterUtil.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/utils/SendApiUtil.js safe No malicious patterns detected
dist/esm/src/utils/StorageUtil.js safe This utility module only performs localStorage reads/writes for caching and connection state; no exfiltration, dynamic code execution, or suspicious patterns were detected.
dist/esm/src/utils/SwapApiUtil.js safe No malicious patterns detected; the file contains legitimate swap-related API utilities with no data exfiltration, credential harvesting, obfuscation, or process execution.
dist/esm/src/utils/SwapCalculationUtil.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/utils/TypeUtil.js safe No malicious patterns detected

Scanned versions of @reown/appkit-controllers

VersionVerdictFilesScanned
1.7.8 Needs review 48 Oct 4, 2026

Frequently asked questions

Is @reown/appkit-controllers safe to use?

No confirmed malware was found in @reown/appkit-controllers@1.7.8, but the review flagged 7 medium, 19 low severity findings for risky patterns worth checking before you rely on it.

Does @reown/appkit-controllers contain malware?

No malware was identified in @reown/appkit-controllers@1.7.8 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @reown/appkit-controllers checked?

Togoder Security downloaded the published npm package and had an AI model read its 48 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @reown/appkit-controllers together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @reown/appkit-controllers@1.7.8, cost nothing.

Related security reports