# @reown/appkit-controllers@1.7.8 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:09:28.000Z
- Files reviewed: 48
- Findings: 7 medium, 19 low severity findings
- Report: https://security.togoder.click/npm/@reown/appkit-controllers
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @reown/appkit-controllers@1.7.8 on Oct 4, 2026. An AI review of 48 source files produced 7 medium, 19 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Data exfiltration / analytics telemetry

Finding ID: `NPS-F89DB0B72650`

File: `dist/esm/src/controllers/EventsController.js:30`

The controller sends analytics events to an external endpoint (CoreHelperUtil.getAnalyticsUrl() + '/e'). Payloads include the user's wallet address (AccountController.state.address), the current page URL (window.location.href), hostname, projectId, SDK type/version, and arbitrary event data. While this is expected telemetry for a wallet SDK, it constitutes transmission of potentially sensitive user data (wallet addresses, browsing context) to a third-party server and should be reviewed for privacy/compliance.

### [medium] Sensitive information in error telemetry

Finding ID: `NPS-F4BE04C86E0B`

File: `dist/esm/src/controllers/TelemetryController.js:60`

The telemetry payload includes raw error.message and error.stack. Stack traces and error messages can inadvertently contain credentials, tokens, file paths, or other sensitive data, which would be exfiltrated to the remote analytics server.

### [medium] Data exfiltration / telemetry

Finding ID: `NPS-317B0F997B7E`

File: `dist/esm/src/controllers/TelemetryController.js:63`

The code sends error telemetry to an external analytics endpoint via FetchUtil.post to '/e'. It collects window.location.href, hostname, projectId, SDK type/version, error message, and stack trace. While this appears to be intentional SDK analytics/telemetry, it transmits potentially sensitive runtime and environment data to an external server without explicit user consent in this file.

### [medium] Hardcoded credential

Finding ID: `NPS-467ABA5535E6`

File: `dist/esm/src/utils/ConstantsUtil.js:22`

MELD_PUBLIC_KEY is hardcoded in the source code. While it is labeled 'public key', embedding API keys or credentials directly in a package's source exposes them to anyone who downloads the package and allows potential abuse or tracking if the key is reused elsewhere.

### [medium] Potential open redirect

Finding ID: `NPS-E2880BEEE956`

File: `dist/esm/src/utils/SocialsUtil.js:52`

The code sets popupWindow.location.href to a URI obtained from authConnector.provider.getSocialRedirectUri. If this URI is not properly validated, it could lead to open redirect vulnerabilities. However, the URI is expected to be from a trusted provider.

### [medium] Data exfiltration / Telemetry transmission

Finding ID: `NPS-A1348E13CEC4`

File: `dist/esm/src/utils/withErrorBoundary.js:62`

The code imports and calls `TelemetryController.sendError(error, error.category)` which transmits error details to an external telemetry endpoint. Depending on the implementation of TelemetryController, this could leak sensitive information (error messages, stack traces, potentially user data) to a remote server without explicit user consent or clear disclosure.

### [medium] Implicit telemetry on every error

Finding ID: `NPS-3780EFB0176E`

File: `dist/esm/src/utils/withErrorBoundary.js:62`

Every error thrown by any wrapped controller method is automatically reported to the telemetry system without opt-in control, which may violate privacy expectations and could be considered an unconsented data collection pattern.

### [low] Potential information disclosure via debug logging

Finding ID: `NPS-FE4851313ED7`

File: `dist/esm/src/controllers/AlertController.js:21`

The open() method conditionally logs longMessage to console.error when debug mode is enabled. If longMessage contains sensitive user or application data, this could expose information in logs. However, this is a standard debugging pattern, not direct exfiltration.

### [low] Dynamic code execution via function callback

Finding ID: `NPS-06E1C60C48AC`

File: `dist/esm/src/controllers/AlertController.js:21`

The code checks if longMessage is a function and invokes it if so. While this is typical for lazy message generation, invoking untrusted callables could be risky if the message source is externally controlled.

### [low] Dynamic network endpoint from configuration

Finding ID: `NPS-A7CE95C84FE0`

File: `dist/esm/src/controllers/EventsController.js:10`

The analytics base URL is obtained at module load time via CoreHelperUtil.getAnalyticsUrl() and used to construct a FetchUtil client. If that utility can be influenced by runtime configuration or environment, event data could be redirected to an attacker-controlled endpoint.

### [low] Top-level side effect on import

Finding ID: `NPS-667A2D799360`

File: `dist/esm/src/controllers/EventsController.js:13`

Module-level initialization creates a proxy state, instantiates a FetchUtil client, and captures Date.now(). While no network call fires at import, the module is immediately wired to send events when OptionsController features.analytics is enabled, so importing this module is not side-effect free.

### [low] external data sharing

Finding ID: `NPS-56320C6DC5DE`

File: `dist/esm/src/controllers/OnRampController.js:85`

The setSelectedProvider method constructs a URL with query parameters (publicKey, destinationCurrencyCode, walletAddress, externalCustomerId) from internal state and appends them to a third-party provider's URL. This is expected behavior for an on-ramp controller integrating with Meld, but it does share the wallet address and project ID with an external service. No credentials or environment variables are harvested.

### [low] Import-time network configuration

Finding ID: `NPS-29F95A969D08`

File: `dist/esm/src/controllers/TelemetryController.js:10`

A FetchUtil instance is constructed at module load time with a base URL derived from CoreHelperUtil.getAnalyticsUrl(). This sets up external communication infrastructure at import time, though the actual network request is deferred until sendError is invoked.

### [low] Environment variable harvesting

Finding ID: `NPS-2001B7B21043`

File: `dist/esm/src/utils/ConstantsUtil.js:2`

The code reads process.env['NEXT_PUBLIC_SECURE_SITE_ORIGIN'] at import time. Although this specific variable is benign, dynamically reading environment variables from a third-party package can be abused to exfiltrate sensitive configuration or tokens if combined with network calls elsewhere in the package.

### [low] External origin configuration

Finding ID: `NPS-C4659EF6C096`

File: `dist/esm/src/utils/ConstantsUtil.js:5`

The default SECURE_SITE points to 'https://secure.walletconnect.org', and subsequent constants build URLs from it. If this value is overridden via an environment variable, any consumer of this package could be redirected to an attacker-controlled origin. No validation is performed on the provided URL.

### [low] Geo-restriction metadata

Finding ID: `NPS-C7C109CA64F1`

File: `dist/esm/src/utils/ConstantsUtil.js:33`

RESTRICTED_TIMEZONES includes several Asian timezones (Shanghai, Hong Kong, etc.). This is a feature-related list but could be used for region-based behavior differences; harmless by itself but worth noting for transparency.

### [low] clipboard-access

Finding ID: `NPS-5E32A11F05E2`

File: `dist/esm/src/utils/CoreHelperUtil.js:41`

copyToClopboard writes text to the clipboard. This is a normal utility function, but clipboard writes should only occur on explicit user action.

### [low] use-of-window-open

Finding ID: `NPS-EC8B3EC7E72E`

File: `dist/esm/src/utils/CoreHelperUtil.js:128`

openHref and returnOpenHref call window.open with user-influenced href values. The default features string includes 'noreferrer noopener' and getOpenTargetForPlatform restricts targets, so risk is low, but opening arbitrary URLs could be abused for phishing if callers pass untrusted input.

### [low] uuid-fallback-weak-randomness

Finding ID: `NPS-5065EE951E84`

File: `dist/esm/src/utils/CoreHelperUtil.js:222`

getUUID falls back to Math.random-based v4 UUID generation when crypto.randomUUID is unavailable. Math.random is not cryptographically secure; if used for security-sensitive identifiers this could be a weakness.

### [low] url-injection-helper

Finding ID: `NPS-CF1434D45271`

File: `dist/esm/src/utils/CoreHelperUtil.js:263`

formatTelegramSocialLoginUrl and injectIntoUrl manipulate URLs by injecting the current page href encoded into a 'state' parameter. This is intended for social login flows but could enable open redirect or state injection if the URL argument is attacker-controlled.

### [low] Telemetry event tracking

Finding ID: `NPS-6311594C38B1`

File: `dist/esm/src/utils/SIWXUtil.js:25`

The code sends telemetry events such as 'SIWX_AUTH_SUCCESS', 'SIWX_AUTH_ERROR', and 'CLICK_CANCEL_SIWX' via EventsController. This is standard analytics behavior but constitutes outbound reporting of authentication outcomes and network/account metadata. This is not clearly malicious, but it is notable data transmission.

### [low] Console error logging of authentication failures

Finding ID: `NPS-092EF6716026`

File: `dist/esm/src/utils/SIWXUtil.js:30`

Multiple catch blocks log errors to console, potentially including authentication or session-related error details. This is not malicious but could expose sensitive details in logs.

### [low] Signature handling and session storage

Finding ID: `NPS-D243915B9864`

File: `dist/esm/src/utils/SIWXUtil.js:84`

The code creates SIWX authentication messages, requests wallet signatures via ConnectionController, and stores sessions including signatures. While expected for a Sign-In With X (SIWX) authentication utility, it interacts with sensitive wallet signing flows and stores auth sessions. Any bug here could impact authentication integrity, but no exfiltration or key theft patterns are present.

### [low] Suspicious network requests

Finding ID: `NPS-F218AD3F7DC9`

File: `dist/esm/src/utils/SocialsUtil.js:10`

The code constructs and opens URLs to an external origin (ConstantsUtil.SECURE_SITE_SDK_ORIGIN) for social login popups. While this is likely a legitimate part of the appkit library for authentication, it does involve sending users to external sites and passing redirect URIs, which could be exploited if the origin is not trusted or if URIs are manipulated.

### [low] Dynamic code execution

Finding ID: `NPS-95EE1590004A`

File: `dist/esm/src/utils/SocialsUtil.js:38`

The code uses setTimeout with a callback that throws an error. While not eval or function constructor, it schedules code execution. However, this is a common pattern and not inherently malicious.

### [low] Potential sensitive information leakage

Finding ID: `NPS-D3A4E142199A`

File: `dist/esm/src/utils/withErrorBoundary.js:20`

The custom error constructor captures and preserves original error stack traces and messages, which may contain sensitive data (file paths, tokens, internal identifiers), and these are then forwarded to the telemetry controller for transmission.

## Files reviewed

- `dist/esm/src/controllers/AlertController.js` (medium): No malicious patterns detected; only minor low-risk logging and function-invocation patterns common in UI controller code.
- `dist/esm/src/controllers/EventsController.js` (medium): This is legitimate wallet-SDK analytics telemetry code that transmits wallet addresses and page URLs to a configured remote endpoint; no malware, credential theft, obfuscation, or process execution was found, but the external data transmission warrants privacy review.
- `dist/esm/src/controllers/TelemetryController.js` (medium): The file implements an opt-out telemetry controller that transmits error details and page URLs to an external analytics endpoint, posing a privacy/data-exfiltration risk despite lacking overtly malicious patterns like credential harvesting or code execution.
- `dist/esm/src/utils/ConstantsUtil.js` (medium): The file contains constant configuration values for a wallet/onramp SDK with no execution, exfiltration, or obfuscation, but includes a hardcoded key and environment-variable-derived origin that warrant review.
- `dist/esm/src/utils/SIWXUtil.js` (medium): The file contains no clear malicious patterns; it is a SIWX wallet authentication utility with standard telemetry and signing flows, though it does handle sensitive wallet session and signature data.
- `dist/esm/src/utils/SocialsUtil.js` (medium): The code appears to be a legitimate social login utility with no clear malicious intent, but it involves external URL redirection and network requests that could pose low to medium security risks if not properly validated.
- `dist/esm/src/utils/withErrorBoundary.js` (medium): The code does not contain obvious malicious patterns such as code execution, credential harvesting, or backdoors, but it automatically transmits error data to a telemetry service, which poses a privacy and potential data exfiltration risk that warrants caution.
- `dist/esm/exports/index.js` (safe): This file is a simple barrel/export index that re-exports named entities from local source modules with no executable code, network access, file operations, or other malicious patterns.
- `dist/esm/exports/react.js` (safe): No malicious patterns detected; the file contains benign React hooks for a Web3 wallet connection library.
- `dist/esm/exports/utils.js` (safe): No malicious patterns detected
- `dist/esm/exports/vue.js` (safe): No malicious patterns detected; the file contains only Vue composables for account state management and wallet disconnection using internal AppKit controllers.
- `dist/esm/src/controllers/AccountController.js` (safe): No malicious patterns detected; the file is a standard wallet account state controller using Valtio and internal utilities.
- `dist/esm/src/controllers/ApiController.js` (safe): No malicious patterns detected
- `dist/esm/src/controllers/AssetController.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/controllers/BlockchainApiController.js` (safe): No malicious patterns detected; the file contains standard API controller logic for blockchain operations using a centralized FetchUtil with no exfiltration, credential harvesting, obfuscation, or harmful behaviors.
- `dist/esm/src/controllers/ChainController.js` (safe): No malicious patterns detected; the file is a standard state management controller for a blockchain wallet connection library with no exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `dist/esm/src/controllers/ConnectionController.js` (safe): No malicious patterns detected; the code is a standard wallet connection controller with no data exfiltration, obfuscation, or suspicious behavior.
- `dist/esm/src/controllers/ConnectorController.js` (safe): No malicious patterns detected; the file is a legitimate wallet connector controller with no data exfiltration, credential harvesting, obfuscation, or process execution.
- `dist/esm/src/controllers/EnsController.js` (safe): No malicious patterns detected; the file contains standard ENS controller logic with API calls to a configured BlockchainApiController.
- `dist/esm/src/controllers/ModalController.js` (safe): No malicious patterns detected; the file is a standard UI modal controller for a wallet connect library with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior.
- `dist/esm/src/controllers/OnRampController.js` (safe): The code is a standard cryptocurrency on-ramp controller with no malicious patterns; the only notable behavior is passing wallet address and project ID to a third-party on-ramp provider, which is expected functionality.
- `dist/esm/src/controllers/OptionsController.js` (safe): No malicious patterns detected
- `dist/esm/src/controllers/OptionsStateController.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/controllers/PublicStateController.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/controllers/RouterController.js` (safe): No malicious patterns detected; the file contains only router/navigation controller logic with no network exfiltration, credential access, dynamic execution, or suspicious behavior.
- `dist/esm/src/controllers/SendController.js` (safe): No malicious patterns detected; the file is a standard Web3 wallet SendController with no exfiltration, credential harvesting, obfuscation, or process execution.
- `dist/esm/src/controllers/SnackController.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/controllers/SwapController.js` (safe): This is a legitimate swap controller from the Reown AppKit (WalletConnect) library with no malicious patterns; all network calls go to expected backend APIs and no sensitive data harvesting, code execution, or file system manipulation is present.
- `dist/esm/src/controllers/ThemeController.js` (safe): No malicious patterns detected; the code is a legitimate theme controller with no data exfiltration, credential harvesting, code execution, or suspicious behaviors.
- `dist/esm/src/controllers/TooltipController.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/controllers/TransactionsController.js` (safe): No malicious patterns detected
- `dist/esm/src/utils/AssetUtil.js` (safe): No malicious patterns detected
- `dist/esm/src/utils/ChainControllerUtil.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/utils/ConnectorControllerUtil.js` (safe): No malicious patterns detected; the code is a simple utility function that delegates to an imported controller without any data exfiltration, credential harvesting, obfuscation, or dynamic execution.
- `dist/esm/src/utils/CoreHelperUtil.js` (safe): Utility module with minor low-severity concerns (window.open with variable URLs, clipboard write, URL state injection, weak UUID fallback) but no malicious patterns or data exfiltration detected.
- `dist/esm/src/utils/ERC7811Util.js` (safe): No malicious patterns detected; the code is a utility module for ERC-7811 asset handling with no network, file system, or process manipulation.
- `dist/esm/src/utils/EnsUtil.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/utils/FetchUtil.js` (safe): No malicious patterns detected; the code is a standard fetch utility wrapper with no data exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
- `dist/esm/src/utils/MobileWallet.js` (safe): No malicious patterns detected; the code only performs legitimate wallet deeplink redirects to well-known services based on hardcoded IDs.
- `dist/esm/src/utils/ModalUtil.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/utils/NetworkUtil.js` (safe): No malicious patterns detected; the file only contains legitimate internal wallet network-switching logic.
- `dist/esm/src/utils/OptionsUtil.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/utils/RouterUtil.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/utils/SendApiUtil.js` (safe): No malicious patterns detected
- `dist/esm/src/utils/StorageUtil.js` (safe): This utility module only performs localStorage reads/writes for caching and connection state; no exfiltration, dynamic code execution, or suspicious patterns were detected.
- `dist/esm/src/utils/SwapApiUtil.js` (safe): No malicious patterns detected; the file contains legitimate swap-related API utilities with no data exfiltration, credential harvesting, obfuscation, or process execution.
- `dist/esm/src/utils/SwapCalculationUtil.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/utils/TypeUtil.js` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
