Summary
Togoder Security scanned the npm package @wallet-standard/app@1.1.0 on Oct 4, 2026. An AI review of 6 source files produced 4 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 5
Dynamic code execution via event listener callback
NPS-6B55D69C8C03
The code registers a window event listener for 'wallet-standard:register-wallet' that extracts a callback from event.detail and invokes it directly (callback(api)). If an attacker can dispatch a crafted event with a malicious detail object, arbitrary code execution is possible in the page context. This is an intended part of the Wallet Standard API but represents a potential attack surface if other scripts can dispatch this event.
Re-export of external module
NPS-55259BDF65B3
The file re-exports all symbols from './wallets.js'. While the current file itself is clean, the security of the package depends entirely on the contents of wallets.js. If that file is malicious (e.g., contains wallet drainers or exfiltration), this re-export would propagate the problem. Since the codebase explicitly targets cryptocurrency wallets, a compromised or malicious wallets.js would be a severe risk.
Global event listener with dynamic callback invocation
NPS-648F171AFA16
The code adds a global 'wallet-standard:register-wallet' event listener on window that invokes an arbitrary callback provided in the event detail. Any script running on the same page (including malicious third-party scripts or injected code) could dispatch this event with a callback that gets executed synchronously inside the app, potentially leading to unauthorized wallet registration or callback execution. This is an intended design of the Wallet Standard, but it broadens the attack surface for any page on which this library runs.
Dynamic code execution via user-supplied callback
NPS-CA3D242611F4
DEPRECATED_getWallets reads window.navigator.wallets (which may be an array of callbacks) and invokes each callback function with a { register } object. If an attacker can control window.navigator.wallets before this code runs, arbitrary code execution is possible. Additionally, Object.defineProperty is used to overwrite window.navigator.wallets, which can interfere with other scripts and could be abused in a supply-chain context to intercept or replace wallet registration.
Global namespace pollution / prototype exposure
NPS-4DFE15DA420D
The deprecated getWallets function redefines window.navigator.wallets via Object.defineProperty using values derived from the page, which could allow interactions with other scripts on the page. This is by design for the Wallet Standard but modifies global browser APIs.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| lib/cjs/wallets.js | medium | This is the legitimate @wallet-standard/app wallet registry library; it contains no data exfiltration, credential harvesting, process spawning, or obfuscated payloads, but it does invoke event-supplied callbacks which is an inherent (and intended) attack surface of the Wallet Standard API. |
| lib/esm/index.js | medium | The file is a simple re-export with no direct malicious code, but it depends on the unvetted './wallets.js', which is a high-risk area for wallet-draining logic. |
| src/wallets.ts | medium | The code is the legitimate @wallet-standard/app implementation for registering and discovering crypto wallets, but it exposes a global window event listener that invokes externally-supplied callbacks and, in its deprecated path, dynamically invokes callbacks from window.navigator.wallets, representing an expanded attack surface if a malicious actor can inject scripts or control those globals. |
| lib/cjs/index.js | safe | No malicious patterns detected; the file only contains standard TypeScript-generated CJS export boilerplate re-exporting a local wallets module. |
| lib/esm/wallets.js | safe | No malicious patterns detected; the code is a legitimate implementation of the Wallet Standard's wallet registration and event dispatch API. |
| src/index.ts | safe | No malicious patterns detected; the file only re-exports from a local module. |
Scanned versions of @wallet-standard/app
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 1.1.0 | Needs review | 6 | Oct 4, 2026 |
Frequently asked questions
Is @wallet-standard/app safe to use?
No confirmed malware was found in @wallet-standard/app@1.1.0, but the review flagged 4 medium, 1 low severity findings for risky patterns worth checking before you rely on it.
Does @wallet-standard/app contain malware?
No malware was identified in @wallet-standard/app@1.1.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @wallet-standard/app checked?
Togoder Security downloaded the published npm package and had an AI model read its 6 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @wallet-standard/app together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @wallet-standard/app@1.1.0, cost nothing.