Togoder security

npm package security report

@reown/appkit-pay@1.7.8 security report

Risky patterns found that deserve a look.

Needs review Version 1.7.8 Files reviewed 17 Size 49.9 KB Scanned

Summary

Togoder Security scanned the npm package @reown/appkit-pay@1.7.8 on Oct 4, 2026. An AI review of 17 source files produced 3 medium, 7 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
3
medium
7
low

Findings 10

medium

Dynamic navigation

NPS-4942E1CC71C3

The openPayUrl method uses CoreHelperUtil.openHref(payUrl.url, target) to open a URL received from an external API. If the API is compromised or returns a malicious URL, this could lead to phishing or drive-by downloads. However, the URL is generated based on the exchange and user parameters, and the risk is mitigated if the API is trusted.

dist/esm/src/controllers/PayController.js
medium

External API dependency

NPS-D10BAEBC5213

The code fetches data from an external API controlled by a third party. If API_URL or the reown controllers package were compromised, responses could contain malicious payloads. No validation is performed on the response structure beyond checking json.error.

dist/esm/src/utils/ApiUtil.js:18
medium

Unvalidated recipient address in payment flows

NPS-0A272A6CA4CE

processEvmNativePayment and processEvmErc20Payment send funds/ERC20 transfers to params.recipient without validating the recipient address format, checksum, or comparing against an allowlist. If params.recipient can be influenced by untrusted input (e.g. a dapp or redirect parameter), funds may be misdirected. This is a financial-safety concern rather than a confirmed malicious pattern.

dist/esm/src/utils/PaymentUtil.js:47
low

Cryptocurrency wallet interaction

NPS-97726A2EC8FF

The controller handles cryptocurrency payments, interacting with wallet providers and processing EVM native and ERC20 payments. While this appears to be legitimate payment functionality, it involves sending funds to a recipient address. The recipient address and payment asset are configurable, which could theoretically be exploited if the configuration is tampered with, but no malicious intent is evident.

dist/esm/src/controllers/PayController.js
low

External network requests

NPS-8E4227650304

The code makes network requests to external APIs via getExchanges, getPayUrl, and getBuyStatus from ApiUtil.js. These are likely legitimate services for fetching exchange data and payment URLs, but the destinations are not visible in this file, so their safety cannot be fully verified.

dist/esm/src/controllers/PayController.js
low

Network request / data exfiltration

NPS-F5646492323C

The module sends JSON-RPC requests containing the application's projectId to an external API endpoint (API_URL). While this appears to be legitimate functionality for the reown/appkit library, the projectId is embedded in the URL query string and sent to an external server on every request, which could be considered data collection/exfiltration if the endpoint is not trusted.

dist/esm/src/utils/ApiUtil.js:6
low

Error handling / information disclosure

NPS-BCD361F2FB2C

Errors from the remote server are surfaced directly via JsonRpcError(json.error.message), which could leak internal details if not sanitized by callers.

dist/esm/src/utils/ApiUtil.js:26
low

Implicit network switching based on asset metadata

NPS-104F7C0CF788

ensureCorrectNetwork automatically invokes ChainController.switchActiveNetwork based on an asset-supplied network id. If payment asset metadata is attacker-influenced, the wallet could be prompted to switch to an unintended network during payment operations.

dist/esm/src/utils/PaymentUtil.js:20
low

Float parsing of payment amounts

NPS-F277976B820F

processEvmNativePayment uses parseFloat on string amounts before converting to BigInt via parseUnits. Binary floating-point rounding can silently alter payment amounts, leading to incorrect transfer values.

dist/esm/src/utils/PaymentUtil.js:30
low

Silent undefined propagation on ERC20 amount parse

NPS-88B01B762FFE

processEvmErc20Payment only checks for undefined from parseUnits, but not for null/invalid results, and passes the derived amountBigInt directly into writeContract. Combined with number coercion of params.amount, unexpected values could reach the contract call.

dist/esm/src/utils/PaymentUtil.js:67

Files reviewed

FileVerdictWhat the reviewer saw
dist/esm/src/controllers/PayController.js medium The code appears to be a legitimate payment controller for a cryptocurrency wallet application, with no clear malicious patterns, but it involves external API calls and cryptocurrency transactions that carry inherent risks if the external services are compromised.
dist/esm/src/utils/ApiUtil.js medium The file implements a JSON-RPC client that sends the application projectId and requests to an external API endpoint; no obfuscation, credential harvesting, shell execution, or wallet draining patterns are present, but outbound network communication to a third-party service is a mild concern.
dist/esm/src/utils/PaymentUtil.js medium No malicious patterns (exfiltration, credential harvesting, obfuscation, process spawning, or install-time hooks) were detected; findings are limited to payment-flow validation and safety concerns.
dist/esm/exports/index.js safe No malicious patterns detected; the file only re-exports modules from the package's own source tree.
dist/esm/exports/react.js safe No malicious patterns detected; the file contains standard React hooks for payment integration without data exfiltration, credential harvesting, obfuscation, or suspicious system interactions.
dist/esm/src/client.js safe No malicious patterns detected; the file is a thin wrapper exposing PayController methods.
dist/esm/src/controllers/index.js safe No malicious patterns detected
dist/esm/src/types/assets.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/types/errors.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/types/exchange.js safe No malicious patterns detected
dist/esm/src/types/options.js safe No malicious patterns detected
dist/esm/src/ui/w3m-pay-loading-view/index.js safe No malicious patterns detected; the file is a legitimate LitElement UI component for a payment loading view within the Reown AppKit library.
dist/esm/src/ui/w3m-pay-loading-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/ui/w3m-pay-view/index.js safe No malicious patterns detected; the file is a standard Lit-based payment UI component with no data exfiltration, obfuscation, or suspicious behavior.
dist/esm/src/ui/w3m-pay-view/styles.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/utils/AssetUtil.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/utils/ConstantsUtil.js safe This file only defines a single constant URL for WalletConnect's public RPC endpoint with no executable, obfuscated, or exfiltrating code.

Frequently asked questions

Is @reown/appkit-pay safe to use?

No confirmed malware was found in @reown/appkit-pay@1.7.8, but the review flagged 3 medium, 7 low severity findings for risky patterns worth checking before you rely on it.

Does @reown/appkit-pay contain malware?

No malware was identified in @reown/appkit-pay@1.7.8 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @reown/appkit-pay checked?

Togoder Security downloaded the published npm package and had an AI model read its 17 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @reown/appkit-pay together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @reown/appkit-pay@1.7.8, cost nothing.

Related security reports