# @wallet-standard/app@1.1.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:19:16.000Z
- Files reviewed: 6
- Findings: 4 medium, 1 low severity findings
- Report: https://security.togoder.click/npm/@wallet-standard/app
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @wallet-standard/app@1.1.0 on Oct 4, 2026. An AI review of 6 source files produced 4 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic code execution via event listener callback

Finding ID: `NPS-6B55D69C8C03`

File: `lib/cjs/wallets.js:74`

The code registers a window event listener for 'wallet-standard:register-wallet' that extracts a callback from event.detail and invokes it directly (callback(api)). If an attacker can dispatch a crafted event with a malicious detail object, arbitrary code execution is possible in the page context. This is an intended part of the Wallet Standard API but represents a potential attack surface if other scripts can dispatch this event.

### [medium] Re-export of external module

Finding ID: `NPS-55259BDF65B3`

File: `lib/esm/index.js:1`

The file re-exports all symbols from './wallets.js'. While the current file itself is clean, the security of the package depends entirely on the contents of wallets.js. If that file is malicious (e.g., contains wallet drainers or exfiltration), this re-export would propagate the problem. Since the codebase explicitly targets cryptocurrency wallets, a compromised or malicious wallets.js would be a severe risk.

### [medium] Global event listener with dynamic callback invocation

Finding ID: `NPS-648F171AFA16`

File: `src/wallets.ts:60`

The code adds a global 'wallet-standard:register-wallet' event listener on window that invokes an arbitrary callback provided in the event detail. Any script running on the same page (including malicious third-party scripts or injected code) could dispatch this event with a callback that gets executed synchronously inside the app, potentially leading to unauthorized wallet registration or callback execution. This is an intended design of the Wallet Standard, but it broadens the attack surface for any page on which this library runs.

### [medium] Dynamic code execution via user-supplied callback

Finding ID: `NPS-CA3D242611F4`

File: `src/wallets.ts:235`

DEPRECATED_getWallets reads window.navigator.wallets (which may be an array of callbacks) and invokes each callback function with a { register } object. If an attacker can control window.navigator.wallets before this code runs, arbitrary code execution is possible. Additionally, Object.defineProperty is used to overwrite window.navigator.wallets, which can interfere with other scripts and could be abused in a supply-chain context to intercept or replace wallet registration.

### [low] Global namespace pollution / prototype exposure

Finding ID: `NPS-4DFE15DA420D`

File: `lib/cjs/wallets.js:178`

The deprecated getWallets function redefines window.navigator.wallets via Object.defineProperty using values derived from the page, which could allow interactions with other scripts on the page. This is by design for the Wallet Standard but modifies global browser APIs.

## Files reviewed

- `lib/cjs/wallets.js` (medium): This is the legitimate @wallet-standard/app wallet registry library; it contains no data exfiltration, credential harvesting, process spawning, or obfuscated payloads, but it does invoke event-supplied callbacks which is an inherent (and intended) attack surface of the Wallet Standard API.
- `lib/esm/index.js` (medium): The file is a simple re-export with no direct malicious code, but it depends on the unvetted './wallets.js', which is a high-risk area for wallet-draining logic.
- `src/wallets.ts` (medium): The code is the legitimate @wallet-standard/app implementation for registering and discovering crypto wallets, but it exposes a global window event listener that invokes externally-supplied callbacks and, in its deprecated path, dynamically invokes callbacks from window.navigator.wallets, representing an expanded attack surface if a malicious actor can inject scripts or control those globals.
- `lib/cjs/index.js` (safe): No malicious patterns detected; the file only contains standard TypeScript-generated CJS export boilerplate re-exporting a local wallets module.
- `lib/esm/wallets.js` (safe): No malicious patterns detected; the code is a legitimate implementation of the Wallet Standard's wallet registration and event dispatch API.
- `src/index.ts` (safe): No malicious patterns detected; the file only re-exports from a local module.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
