Togoder security

npm package security report

@reown/appkit-wallet@1.7.8 security report

Risky patterns found that deserve a look.

Needs review Version 1.7.8 Files reviewed 11 Size 61.9 KB Scanned

Summary

Togoder Security scanned the npm package @reown/appkit-wallet@1.7.8 on Oct 4, 2026. An AI review of 11 source files produced 2 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
3
low

Findings 5

medium

Insecure postMessage target origin

NPS-732033927C13

postAppEvent and postFrameEvent use postMessage with '*' as target origin, which allows any window to receive sensitive iframe/app event data. This can lead to data leakage if the page is embedded in an untrusted context.

dist/esm/src/W3mFrame.js
medium

Insecure message event handling

NPS-63EE43D27912

Event handlers (registerFrameEventHandler, onFrameEvent, onAppEvent) accept messages from any origin without validating event.origin. This allows any page to send fake frame/app events, potentially triggering callbacks with attacker-controlled data.

dist/esm/src/W3mFrame.js
low

Potential credential leakage via RPC URLs

NPS-A90941FE77F5

The networks getter constructs RPC URLs containing the projectId (potentially a sensitive identifier) and embeds them in the iframe. If the iframe origin is compromised or the projectId is exposed, it could leak credentials.

dist/esm/src/W3mFrame.js
low

Potential key/seed phrase regex matching for response classification

NPS-044008ECC340

getResponseType uses RegexUtil.transactionHash and RegexUtil.signedMessage to classify responses. While this code only classifies responses, the presence of 'signedMessage' regex in a wallet-related module (W3mFrame) could be a building block for detecting/processing signed messages (cryptographic material). Without seeing RegexUtil, this is flagged as a potential concern in a wallet SDK context.

dist/esm/src/W3mFrameHelpers.js:33
low

Top-level code execution on import

NPS-4EFE552BACD7

isClient: typeof window !== 'undefined' executes at module import time. While benign (just a feature check), top-level evaluation in wallet SDKs should be noted. No side effects or network calls occur here.

dist/esm/src/W3mFrameHelpers.js:51

Files reviewed

FileVerdictWhat the reviewer saw
dist/esm/src/W3mFrame.js medium The code contains insecure postMessage practices (wildcard target origin and missing origin validation) that could lead to data leakage or spoofing, but no direct malicious patterns such as exfiltration, eval, or backdoors were found.
dist/esm/src/W3mFrameHelpers.js medium No clearly malicious patterns; code appears to be legitimate helper utilities for a wallet frame with only minor contextual concerns related to signature regex matching.
dist/esm/exports/index.js safe No malicious patterns detected; the file is a standard ESM re-export module with a polyfill import and static exports only.
dist/esm/exports/utils.js safe This file only re-exports a constant from another module and contains no malicious patterns.
dist/esm/src/RegexUtil.js safe No malicious patterns detected
dist/esm/src/W3mFrameConstants.js safe No malicious patterns detected in this constants file; it only defines event keys, RPC method allowlists, and reads NEXT_PUBLIC_ environment variables at import time with benign fallbacks.
dist/esm/src/W3mFrameLogger.js safe The file contains only standard logging setup using the WalletConnect logger library, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process execution.
dist/esm/src/W3mFrameProvider.js safe No malicious patterns detected
dist/esm/src/W3mFrameSchema.js safe No malicious patterns detected; the file only defines Zod validation schemas for a wallet connector and contains no execution, network, or filesystem operations.
dist/esm/src/W3mFrameStorage.js safe No malicious patterns detected
dist/esm/src/W3mFrameTypes.js safe No malicious patterns detected; file only re-exports Zod schema types for wallet connectivity.

Frequently asked questions

Is @reown/appkit-wallet safe to use?

No confirmed malware was found in @reown/appkit-wallet@1.7.8, but the review flagged 2 medium, 3 low severity findings for risky patterns worth checking before you rely on it.

Does @reown/appkit-wallet contain malware?

No malware was identified in @reown/appkit-wallet@1.7.8 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @reown/appkit-wallet checked?

Togoder Security downloaded the published npm package and had an AI model read its 11 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @reown/appkit-wallet together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @reown/appkit-wallet@1.7.8, cost nothing.

Related security reports