# @reown/appkit@1.7.8 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:09:17.000Z
- Files reviewed: 43
- Findings: 1 medium, 13 low severity findings
- Report: https://security.togoder.click/npm/@reown/appkit
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @reown/appkit@1.7.8 on Oct 4, 2026. An AI review of 43 source files produced 1 medium, 13 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Network-related functionality

Finding ID: `NPS-EB84C01E3B15`

File: `dist/esm/exports/vue-core.js`

The imported `AppKit` from '@reown/appkit-controllers' and related classes likely perform network requests (wallet connection, blockchain interactions). While this is expected for a wallet connector library, it represents potential data exfiltration or interaction with external servers if maliciously tampered with. No direct suspicious network calls are present in this file.

### [low] Suspicious import pattern

Finding ID: `NPS-BC7E451E04DE`

File: `dist/esm/exports/react-core.js:1`

Empty import statement `import {} from '@reown/appkit-controllers';` is unusual and may be used to trigger side effects in the module without importing any bindings. Combined with the package being a third-party crypto wallet library, this warrants scrutiny for hidden behavior.

### [low] Global state mutation on import

Finding ID: `NPS-A4CA4D49D439`

File: `dist/esm/exports/react-core.js:15`

Exported mutable variable `modal` is undefined initially and can be set by `createAppKit`. While not inherently malicious, this creates a singleton pattern that could be exploited if the module is later tampered with. The `createAppKit` function instantiates `AppKit` with user-provided options and a hardcoded `sdkVersion`, which is normal for such libraries.

### [low] Use of optional chaining for network switch

Finding ID: `NPS-44995F6C5AFD`

File: `dist/esm/exports/react-core.js:33`

`modal?.switchNetwork(network)` silently fails if `modal` is not initialized. This is a design choice, not a security flaw, but could hide errors. No direct malicious intent detected.

### [low] Dynamic imports not observed

Finding ID: `NPS-11ACD88D6A35`

File: `dist/esm/exports/vue-core.js`

No dynamic imports or computed module loading are present.

### [low] Top-level code execution on import

Finding ID: `NPS-FCFF82250F6D`

File: `dist/esm/exports/vue-core.js:7`

The module initializes a mutable `modal` variable and uses top-level logic but no actual execution; however, the `createAppKit` function creates an AppKit instance and calls `getAppKit(modal)`, which could have side effects when invoked. Importing this module alone does not execute `createAppKit`, but consumers calling it could trigger network or state changes.

### [low] Global mutable state

Finding ID: `NPS-7B50CCCF4880`

File: `dist/esm/exports/vue-core.js:15`

The module-level `modal` variable may be shared across imports, leading to unexpected singleton behavior. This is not malicious but can cause security-relevant side effects if not intended.

### [low] wallet-connection-control

Finding ID: `NPS-0FAA5A5AA5F7`

File: `dist/esm/src/client/appkit-core.js:15`

The class extends AppKitBaseClient and imports controllers (ConnectionController, ConnectorController, AccountController) from '@reown/appkit-controllers'. This is a wallet-connection library. Wallet-related packages are common targets for supply-chain tampering (wallet drainers). No direct key/seed phrase handling or address rewriting is visible in this file, but the sink for wallet interactions exists here.

### [low] dynamic-import

Finding ID: `NPS-DA0909E79B73`

File: `dist/esm/src/client/appkit-core.js:24`

The injectModalUi method performs dynamic imports of '@reown/appkit-scaffold-ui/basic' and '@reown/appkit-scaffold-ui/w3m-modal'. While these are static string imports (not computed from user input), dynamic import() is a module loading mechanism that could be used to load arbitrary code if the package name or resolution is compromised/tampered with upstream. This is low risk here since the specifiers are hardcoded.

### [low] dom-manipulation

Finding ID: `NPS-03369F11B193`

File: `dist/esm/src/client/appkit-core.js:29`

The injectModalUi method creates and inserts a custom element ('w3m-modal') into document.body at runtime. This is UI injection and could be abused if the injected element or associated scaffold-ui modules contain malicious behavior. Insertion is guarded by disableAppend/enableEmbedded options, which is reasonable, but the runtime DOM injection into the host page is worth noting.

### [low] Dynamic imports based on remote feature flags

Finding ID: `NPS-9004FF9D78FC`

File: `dist/esm/src/client/appkit.js`

loadModalComponents() dynamically imports multiple internal modules (embedded-wallet, email, socials, swaps, send, receive, onramp, transactions, pay) conditionally based on remoteFeatures sourced from a remote configuration server. While the import specifiers are static strings, the decision to load them is influenced by remote data, which could be abused if the remote config endpoint were compromised to control code loading behavior. This is a minor supply-chain/modularity concern rather than direct malicious behavior.

### [low] Reading URL search params and browser history manipulation

Finding ID: `NPS-E02BB94727AA`

File: `dist/esm/src/client/appkit.js`

checkExistingTelegramSocialConnection() reads window.location.href search params (result_uri) and uses window.history.replaceState to strip it. This is standard OAuth/social login redirect handling, but it does process externally-controlled URL parameters and passes them as socialUri into ConnectionController.connectExternal, which can initiate an external wallet connection. Not inherently malicious but worth noting as a trust boundary.

### [low] Remote feature gating for account/wallet UI

Finding ID: `NPS-2F20B3294DC7`

File: `dist/esm/src/client/appkit.js`

The client pulls remoteFeatures (email, socials, swaps, onramp, activity, etc.) from a remote source and enables financial UI features based on them. If the remote feature endpoint were tampered with, it could alter which wallet operations are exposed. This is a design-level trust dependency rather than an exploit in this file.

### [low] Third-party payload in iframe (W3mFrameProvider)

Finding ID: `NPS-A981A3841060`

File: `dist/esm/src/client/appkit.js`

The auth provider creates a W3mFrameProvider that communicates with an embedded modal/iframe to handle wallet operations, emails, and RPC requests. Interactions with an embedded wallet iframe can be a vector for XSS/data leakage if origin validation is weak; however no such validation logic is visible here and this appears to be the legitimate Reown AppKit auth flow.

## Files reviewed

- `dist/esm/exports/react-core.js` (medium): The code appears to be a legitimate React wrapper for the Reown AppKit cryptocurrency wallet library, with no clear malicious patterns such as data exfiltration, credential harvesting, or dynamic code execution.
- `dist/esm/exports/vue-core.js` (medium): The code appears to be a legitimate Vue integration for AppKit, with no direct malicious patterns, but it includes network-capable wallet functionality and global mutable state that could be risky if abused.
- `dist/esm/src/client/appkit-core.js` (medium): No direct malicious patterns (exfiltration, credential harvesting, eval, shell exec, install-time hooks) are present; findings are limited to low-risk dynamic imports and runtime DOM injection typical of this legitimate wallet-connection UI package, though supply-chain integrity of the referenced @reown packages should be verified.
- `dist/esm/src/client/appkit.js` (medium): This is legitimate Reown AppKit client code; no classic malicious patterns (exfiltration, credential harvesting, obfuscation, shells, mining, wallet draining) are present, but remote-feature-driven dynamic imports and embedded iframe interactions represent minor trust-boundary concerns.
- `dist/esm/exports/adapters.js` (safe): This file is a simple ESM re-export shim pointing to the package's own internal adapters module and contains no malicious patterns.
- `dist/esm/exports/auth-provider.js` (safe): No malicious patterns detected
- `dist/esm/exports/connectors.js` (safe): This file is a simple ES module re-export with no executable logic or suspicious patterns.
- `dist/esm/exports/constants.js` (safe): No malicious patterns detected
- `dist/esm/exports/core.js` (safe): No malicious patterns detected
- `dist/esm/exports/index.js` (safe): No malicious patterns detected; this is a clean entry point re-exporting public AppKit modules and creating an AppKit instance.
- `dist/esm/exports/library/react.js` (safe): No malicious patterns detected
- `dist/esm/exports/library/vue.js` (safe): No malicious patterns detected
- `dist/esm/exports/networks.js` (safe): The file is a simple re-export module with no malicious patterns detected.
- `dist/esm/exports/react.js` (safe): No malicious patterns detected in the analyzed React export module.
- `dist/esm/exports/store.js` (safe): No malicious patterns detected in the re-export file; it only forwards exports from the internal store module.
- `dist/esm/exports/utils.js` (safe): This is a simple ES module re-export barrel file with a source map reference; no malicious patterns or suspicious behavior detected.
- `dist/esm/exports/vue.js` (safe): No malicious patterns detected; the code is a standard Vue integration layer for a wallet connection SDK.
- `dist/esm/src/adapters/ChainAdapterBlueprint.js` (safe): No malicious patterns detected; the code is a standard abstract adapter blueprint for WalletConnect integration with no exfiltration, obfuscation, or harmful behavior.
- `dist/esm/src/adapters/ChainAdapterConnector.js` (safe): No malicious patterns detected
- `dist/esm/src/adapters/index.js` (safe): No malicious patterns detected; the file is a simple re-export of a class from a sibling module.
- `dist/esm/src/auth-provider/W3MFrameProviderSingleton.js` (safe): No malicious patterns detected; this is a simple singleton wrapper around W3mFrameProvider with no network, filesystem, or process activity.
- `dist/esm/src/auth-provider/index.js` (safe): No malicious patterns detected
- `dist/esm/src/client/appkit-base-client.js` (safe): No malicious patterns detected; this is a legitimate WalletConnect/AppKit client library implementing standard wallet integration, connection management, and account synchronization functionality.
- `dist/esm/src/connectors/WalletConnectConnector.js` (safe): No malicious patterns detected; the file is a legitimate WalletConnect connector implementation for a web3 wallet library with standard connection and authentication logic.
- `dist/esm/src/connectors/index.js` (safe): This file only re-exports a WalletConnect connector module and contains no malicious patterns, dynamic imports, or executable code beyond a standard ES module export.
- `dist/esm/src/library/react/index.js` (safe): No malicious patterns detected; the file contains standard React hooks for wallet integration with no data exfiltration, credential harvesting, obfuscation, or suspicious system operations.
- `dist/esm/src/library/vue/index.js` (safe): No malicious patterns detected; the code is a standard Vue integration layer for Reown AppKit with hooks and subscriptions.
- `dist/esm/src/networks/bitcoin.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/networks/index.js` (safe): No malicious patterns detected
- `dist/esm/src/networks/solana/index.js` (safe): No malicious patterns detected; the file only re-exports three local Solana network modules and contains no executable logic.
- `dist/esm/src/networks/solana/solana.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/networks/solana/solanaDevnet.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/networks/solana/solanaTestnet.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/networks/utils.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/store/index.js` (safe): No malicious patterns detected; the file only re-exports a utility from a known dependency.
- `dist/esm/src/universal-adapter/client.js` (safe): No malicious patterns detected; the code is a legitimate blockchain wallet adapter implementation with standard cryptographic operations and no exfiltration, obfuscation, or backdoor behavior.
- `dist/esm/src/universal-adapter/index.js` (safe): No malicious patterns detected
- `dist/esm/src/utils/BalanceUtil.js` (safe): No malicious patterns detected
- `dist/esm/src/utils/ConfigUtil.js` (safe): No malicious patterns detected; the code is a legitimate feature-configuration utility for Reown AppKit that fetches remote project settings and manages feature flags without any exfiltration, credential harvesting, or code execution.
- `dist/esm/src/utils/ConstantsUtil.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/utils/HelpersUtil.js` (safe): No malicious patterns detected; the code contains only standard wallet-connection helper utilities for Reown/WalletConnect with no exfiltration, dynamic execution, or credential harvesting.
- `dist/esm/src/utils/TypesUtil.js` (safe): No malicious patterns detected
- `dist/esm/src/utils/index.js` (safe): No malicious patterns detected; the file only re-exports other modules and contains a source map comment.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
