Summary
Togoder Security scanned the npm package @reown/appkit-wallet@1.7.8 on Oct 4, 2026. An AI review of 11 source files produced 2 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 5
Insecure postMessage target origin
NPS-732033927C13
postAppEvent and postFrameEvent use postMessage with '*' as target origin, which allows any window to receive sensitive iframe/app event data. This can lead to data leakage if the page is embedded in an untrusted context.
Insecure message event handling
NPS-63EE43D27912
Event handlers (registerFrameEventHandler, onFrameEvent, onAppEvent) accept messages from any origin without validating event.origin. This allows any page to send fake frame/app events, potentially triggering callbacks with attacker-controlled data.
Potential credential leakage via RPC URLs
NPS-A90941FE77F5
The networks getter constructs RPC URLs containing the projectId (potentially a sensitive identifier) and embeds them in the iframe. If the iframe origin is compromised or the projectId is exposed, it could leak credentials.
Potential key/seed phrase regex matching for response classification
NPS-044008ECC340
getResponseType uses RegexUtil.transactionHash and RegexUtil.signedMessage to classify responses. While this code only classifies responses, the presence of 'signedMessage' regex in a wallet-related module (W3mFrame) could be a building block for detecting/processing signed messages (cryptographic material). Without seeing RegexUtil, this is flagged as a potential concern in a wallet SDK context.
Top-level code execution on import
NPS-4EFE552BACD7
isClient: typeof window !== 'undefined' executes at module import time. While benign (just a feature check), top-level evaluation in wallet SDKs should be noted. No side effects or network calls occur here.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/esm/src/W3mFrame.js | medium | The code contains insecure postMessage practices (wildcard target origin and missing origin validation) that could lead to data leakage or spoofing, but no direct malicious patterns such as exfiltration, eval, or backdoors were found. |
| dist/esm/src/W3mFrameHelpers.js | medium | No clearly malicious patterns; code appears to be legitimate helper utilities for a wallet frame with only minor contextual concerns related to signature regex matching. |
| dist/esm/exports/index.js | safe | No malicious patterns detected; the file is a standard ESM re-export module with a polyfill import and static exports only. |
| dist/esm/exports/utils.js | safe | This file only re-exports a constant from another module and contains no malicious patterns. |
| dist/esm/src/RegexUtil.js | safe | No malicious patterns detected |
| dist/esm/src/W3mFrameConstants.js | safe | No malicious patterns detected in this constants file; it only defines event keys, RPC method allowlists, and reads NEXT_PUBLIC_ environment variables at import time with benign fallbacks. |
| dist/esm/src/W3mFrameLogger.js | safe | The file contains only standard logging setup using the WalletConnect logger library, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/esm/src/W3mFrameProvider.js | safe | No malicious patterns detected |
| dist/esm/src/W3mFrameSchema.js | safe | No malicious patterns detected; the file only defines Zod validation schemas for a wallet connector and contains no execution, network, or filesystem operations. |
| dist/esm/src/W3mFrameStorage.js | safe | No malicious patterns detected |
| dist/esm/src/W3mFrameTypes.js | safe | No malicious patterns detected; file only re-exports Zod schema types for wallet connectivity. |
Frequently asked questions
Is @reown/appkit-wallet safe to use?
No confirmed malware was found in @reown/appkit-wallet@1.7.8, but the review flagged 2 medium, 3 low severity findings for risky patterns worth checking before you rely on it.
Does @reown/appkit-wallet contain malware?
No malware was identified in @reown/appkit-wallet@1.7.8 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @reown/appkit-wallet checked?
Togoder Security downloaded the published npm package and had an AI model read its 11 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @reown/appkit-wallet together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @reown/appkit-wallet@1.7.8, cost nothing.