Togoder security

npm package security report

@wallet-standard/app npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 1.1.0 Files reviewed 6 Size 21.8 KB Scanned

Summary

Togoder Security scanned the npm package @wallet-standard/app@1.1.0 on Oct 4, 2026. An AI review of 6 source files produced 4 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
4
medium
1
low

Findings 5

medium

Dynamic code execution via event listener callback

NPS-6B55D69C8C03

The code registers a window event listener for 'wallet-standard:register-wallet' that extracts a callback from event.detail and invokes it directly (callback(api)). If an attacker can dispatch a crafted event with a malicious detail object, arbitrary code execution is possible in the page context. This is an intended part of the Wallet Standard API but represents a potential attack surface if other scripts can dispatch this event.

lib/cjs/wallets.js:74
medium

Re-export of external module

NPS-55259BDF65B3

The file re-exports all symbols from './wallets.js'. While the current file itself is clean, the security of the package depends entirely on the contents of wallets.js. If that file is malicious (e.g., contains wallet drainers or exfiltration), this re-export would propagate the problem. Since the codebase explicitly targets cryptocurrency wallets, a compromised or malicious wallets.js would be a severe risk.

lib/esm/index.js:1
medium

Global event listener with dynamic callback invocation

NPS-648F171AFA16

The code adds a global 'wallet-standard:register-wallet' event listener on window that invokes an arbitrary callback provided in the event detail. Any script running on the same page (including malicious third-party scripts or injected code) could dispatch this event with a callback that gets executed synchronously inside the app, potentially leading to unauthorized wallet registration or callback execution. This is an intended design of the Wallet Standard, but it broadens the attack surface for any page on which this library runs.

src/wallets.ts:60
medium

Dynamic code execution via user-supplied callback

NPS-CA3D242611F4

DEPRECATED_getWallets reads window.navigator.wallets (which may be an array of callbacks) and invokes each callback function with a { register } object. If an attacker can control window.navigator.wallets before this code runs, arbitrary code execution is possible. Additionally, Object.defineProperty is used to overwrite window.navigator.wallets, which can interfere with other scripts and could be abused in a supply-chain context to intercept or replace wallet registration.

src/wallets.ts:235
low

Global namespace pollution / prototype exposure

NPS-4DFE15DA420D

The deprecated getWallets function redefines window.navigator.wallets via Object.defineProperty using values derived from the page, which could allow interactions with other scripts on the page. This is by design for the Wallet Standard but modifies global browser APIs.

lib/cjs/wallets.js:178

Files reviewed

FileVerdictWhat the reviewer saw
lib/cjs/wallets.js medium This is the legitimate @wallet-standard/app wallet registry library; it contains no data exfiltration, credential harvesting, process spawning, or obfuscated payloads, but it does invoke event-supplied callbacks which is an inherent (and intended) attack surface of the Wallet Standard API.
lib/esm/index.js medium The file is a simple re-export with no direct malicious code, but it depends on the unvetted './wallets.js', which is a high-risk area for wallet-draining logic.
src/wallets.ts medium The code is the legitimate @wallet-standard/app implementation for registering and discovering crypto wallets, but it exposes a global window event listener that invokes externally-supplied callbacks and, in its deprecated path, dynamically invokes callbacks from window.navigator.wallets, representing an expanded attack surface if a malicious actor can inject scripts or control those globals.
lib/cjs/index.js safe No malicious patterns detected; the file only contains standard TypeScript-generated CJS export boilerplate re-exporting a local wallets module.
lib/esm/wallets.js safe No malicious patterns detected; the code is a legitimate implementation of the Wallet Standard's wallet registration and event dispatch API.
src/index.ts safe No malicious patterns detected; the file only re-exports from a local module.

Scanned versions of @wallet-standard/app

VersionVerdictFilesScanned
1.1.0 Needs review 6 Oct 4, 2026

Frequently asked questions

Is @wallet-standard/app safe to use?

No confirmed malware was found in @wallet-standard/app@1.1.0, but the review flagged 4 medium, 1 low severity findings for risky patterns worth checking before you rely on it.

Does @wallet-standard/app contain malware?

No malware was identified in @wallet-standard/app@1.1.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @wallet-standard/app checked?

Togoder Security downloaded the published npm package and had an AI model read its 6 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @wallet-standard/app together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @wallet-standard/app@1.1.0, cost nothing.

Related security reports