# @reown/appkit-wallet@1.7.8 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:16:05.000Z
- Files reviewed: 11
- Findings: 2 medium, 3 low severity findings
- Report: https://security.togoder.click/npm/@reown/appkit-wallet
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @reown/appkit-wallet@1.7.8 on Oct 4, 2026. An AI review of 11 source files produced 2 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Insecure postMessage target origin

Finding ID: `NPS-732033927C13`

File: `dist/esm/src/W3mFrame.js`

postAppEvent and postFrameEvent use postMessage with '*' as target origin, which allows any window to receive sensitive iframe/app event data. This can lead to data leakage if the page is embedded in an untrusted context.

### [medium] Insecure message event handling

Finding ID: `NPS-63EE43D27912`

File: `dist/esm/src/W3mFrame.js`

Event handlers (registerFrameEventHandler, onFrameEvent, onAppEvent) accept messages from any origin without validating event.origin. This allows any page to send fake frame/app events, potentially triggering callbacks with attacker-controlled data.

### [low] Potential credential leakage via RPC URLs

Finding ID: `NPS-A90941FE77F5`

File: `dist/esm/src/W3mFrame.js`

The networks getter constructs RPC URLs containing the projectId (potentially a sensitive identifier) and embeds them in the iframe. If the iframe origin is compromised or the projectId is exposed, it could leak credentials.

### [low] Potential key/seed phrase regex matching for response classification

Finding ID: `NPS-044008ECC340`

File: `dist/esm/src/W3mFrameHelpers.js:33`

getResponseType uses RegexUtil.transactionHash and RegexUtil.signedMessage to classify responses. While this code only classifies responses, the presence of 'signedMessage' regex in a wallet-related module (W3mFrame) could be a building block for detecting/processing signed messages (cryptographic material). Without seeing RegexUtil, this is flagged as a potential concern in a wallet SDK context.

### [low] Top-level code execution on import

Finding ID: `NPS-4EFE552BACD7`

File: `dist/esm/src/W3mFrameHelpers.js:51`

`isClient: typeof window !== 'undefined'` executes at module import time. While benign (just a feature check), top-level evaluation in wallet SDKs should be noted. No side effects or network calls occur here.

## Files reviewed

- `dist/esm/src/W3mFrame.js` (medium): The code contains insecure postMessage practices (wildcard target origin and missing origin validation) that could lead to data leakage or spoofing, but no direct malicious patterns such as exfiltration, eval, or backdoors were found.
- `dist/esm/src/W3mFrameHelpers.js` (medium): No clearly malicious patterns; code appears to be legitimate helper utilities for a wallet frame with only minor contextual concerns related to signature regex matching.
- `dist/esm/exports/index.js` (safe): No malicious patterns detected; the file is a standard ESM re-export module with a polyfill import and static exports only.
- `dist/esm/exports/utils.js` (safe): This file only re-exports a constant from another module and contains no malicious patterns.
- `dist/esm/src/RegexUtil.js` (safe): No malicious patterns detected
- `dist/esm/src/W3mFrameConstants.js` (safe): No malicious patterns detected in this constants file; it only defines event keys, RPC method allowlists, and reads NEXT_PUBLIC_ environment variables at import time with benign fallbacks.
- `dist/esm/src/W3mFrameLogger.js` (safe): The file contains only standard logging setup using the WalletConnect logger library, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process execution.
- `dist/esm/src/W3mFrameProvider.js` (safe): No malicious patterns detected
- `dist/esm/src/W3mFrameSchema.js` (safe): No malicious patterns detected; the file only defines Zod validation schemas for a wallet connector and contains no execution, network, or filesystem operations.
- `dist/esm/src/W3mFrameStorage.js` (safe): No malicious patterns detected
- `dist/esm/src/W3mFrameTypes.js` (safe): No malicious patterns detected; file only re-exports Zod schema types for wallet connectivity.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
