# viem@2.23.2 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:54:42.000Z
- Files reviewed: 3209
- Findings: 27 medium, 37 low severity findings
- Report: https://security.togoder.click/npm/viem@2.23.2
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package viem@2.23.2 on Oct 4, 2026. An AI review of 3209 source files produced 27 medium, 37 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Malformed URL

Finding ID: `NPS-65A84F6BD16E`

File: `_cjs/chains/definitions/donatuz.js:12`

The RPC URL 'ttps://rpc.donatuz.com' is missing the leading 'h'. This could be a typo, but it also means the URL will be treated as a relative path or invalid protocol, potentially causing errors or unexpected behavior if the user relies on it for network requests.

### [medium] Suspicious network requests

Finding ID: `NPS-54715C84E6E8`

File: `_cjs/utils/ccip.js:93`

The ccipRequest function performs outbound HTTP requests to URLs provided in the OffchainLookup error data. In a real Ethereum/CCIP context these URLs come from a smart contract, but the code does not validate or restrict URLs (e.g., no allowlist, no scheme check). This could potentially be abused (SSRF-like) if an attacker controls the contract or error data, and it introduces data exfiltration surface by sending {data}/{sender} payloads to arbitrary endpoints.

### [medium] Resource exhaustion / unbounded recursion

Finding ID: `NPS-4624D8B9DC66`

File: `_cjs/utils/encoding/fromRlp.js:20`

The fromRlp function creates a cursor with recursiveReadLimit set to Number.POSITIVE_INFINITY, disabling the library's built-in protection against deeply nested RLP structures. Combined with recursive list parsing in readList/fromRlpCursor, a maliciously crafted deeply-nested RLP payload could cause stack exhaustion (RangeError: Maximum call stack size exceeded) or excessive memory consumption, resulting in a denial-of-service condition for callers that process untrusted RLP data.

### [medium] Server-Side Request Forgery / SSRF

Finding ID: `NPS-F10ACA6B93F4`

File: `_cjs/utils/ens/avatar/utils.js:14`

The isImageUri function performs fetch(uri, { method: 'HEAD' }) on a URI that may be attacker-controlled (e.g. from ENS avatar records or NFT tokenURI). This can be used to probe internal network services or metadata endpoints (e.g. 169.254.169.254) if the URI is not validated against private IP ranges. No URL scheme/host allowlist beyond what resolveAvatarUri does is applied before the fetch.

### [medium] Unvalidated URI passed to network fetch

Finding ID: `NPS-2DBDD488A91C`

File: `_cjs/utils/ens/avatar/utils.js:96`

getMetadataAvatarUri fetches an arbitrary URI and parses JSON, then passes the returned image field through parseAvatarUri, which may itself perform further fetches. This creates a chain of attacker-controlled outbound requests and potential JSON-based resource loading.

### [medium] Potential message boundary / protocol confusion in extractMessages

Finding ID: `NPS-9AD99A932848`

File: `_cjs/utils/rpc/ipc.js:8`

extractMessages tracks only brace nesting and ignores string literals and escapes. JSON strings containing unmatched braces (e.g. '{"a":"}"}') will corrupt the nesting level, causing incorrect message splitting, dropped messages, or merged payloads. Depending on the caller, this can be used to smuggle or truncate messages across the IPC boundary.

### [medium] Unvalidated filesystem path passed to net.connect

Finding ID: `NPS-B54831844B0C`

File: `_cjs/utils/rpc/ipc.js:33`

getIpcRpcClient(path) forwards the caller-supplied path directly to node:net connect() as an IPC endpoint with no normalization, allowlisting, or scope restriction. If path is influenced by untrusted input, it could connect to arbitrary local sockets (e.g. privileged daemons) rather than an intended package-scoped endpoint.

### [medium] Unbounded JSON parsing from untrusted socket input

Finding ID: `NPS-8F25A79D3461`

File: `_cjs/utils/rpc/ipc.js:50`

The onData handler parses every complete JSON message received over the IPC socket with JSON.parse(). There is no validation, size limit, or schema check before parsing. A malicious or compromised peer can send arbitrarily large or deeply nested JSON, causing high CPU/memory usage (JSON bombs / DoS). The parsed object is then passed directly to onResponse().

### [medium] Sensitive data handling

Finding ID: `NPS-E2C6D874196C`

File: `_cjs/zksync/accounts/toMultisigSmartAccount.js:8`

The function receives private keys as parameters and uses them to sign hashes. While this is expected behavior for a multisig smart account utility, handling private keys in memory and passing them to a signing function introduces risk if the keys are logged, stored, or transmitted improperly. The code does not appear to exfiltrate keys, but the pattern warrants caution since private keys are highly sensitive credentials.

### [medium] Potential for malicious factory

Finding ID: `NPS-C0DB61B9C9EF`

File: `_esm/account-abstraction/accounts/implementations/toSoladySmartAccount.js:29`

The factoryAddress is configurable by the caller (parameters.factoryAddress) and defaults to a hardcoded address. If a malicious factory is provided, it could deploy a backdoored smart account or perform arbitrary calls during account creation. This is a design risk inherent in account abstraction but should be clearly documented.

### [medium] Hardcoded factory address

Finding ID: `NPS-0D939F4D733A`

File: `_esm/account-abstraction/accounts/implementations/toSoladySmartAccount.js:30`

A default factory address '0x5d82735936c6Cd5DE57cC3c1A799f6B2E6F933Df' is hardcoded instead of being derived from the provided entryPoint. This could lead to unexpected account creation address if the factory is not intended for the given chain/entryPoint, potentially causing loss of funds or incorrect account deployment.

### [medium] Owner parsing without validation

Finding ID: `NPS-122E16E38E49`

File: `_esm/account-abstraction/accounts/implementations/toSoladySmartAccount.js:34`

The owner account is parsed via parseAccount(parameters.owner) without verifying that it is a valid EOA or that the address matches the expected owner. If an attacker can influence the owner parameter, they could set themselves as owner and drain funds.

### [medium] External network request

Finding ID: `NPS-F59A5AEFCCB1`

File: `_esm/utils/ccip.js:88`

The ccipRequest function performs fetch() calls to URLs provided by the contract error data (urls array from on-chain OffchainLookup error). This is expected behavior for CCIP-read / EIP-3668 offchain lookup, but the URLs are fully attacker-controllable via the smart contract being called. This means a malicious contract could direct requests to any host, including localhost/internal services (SSRF), potentially leaking the request data (which includes sender address and callData) to arbitrary endpoints. Additionally, results from these URLs are trusted and passed back into an on-chain callback, forming a trust chain that relies entirely on user-supplied endpoints.

### [medium] Potential SSRF / trust boundary issue

Finding ID: `NPS-70A531D4BE29`

File: `_esm/utils/ccip.js:90`

fetch URL construction uses string replacement of {sender} and {data} into the URL without validation that the resulting URL is a well-formed http(s) URL or that it does not target internal/private addresses. No allowlist, protocol restriction, or redirect handling is present. In a package-supplied utility this is normal for CCIP read implementations but is a security-sensitive pattern worth noting.

### [medium] Potential denial of service via unbounded recursion

Finding ID: `NPS-7256C45E9EE3`

File: `_esm/utils/encoding/fromRlp.js:18`

The createCursor call sets recursiveReadLimit to Number.POSITIVE_INFINITY, disabling the library's built-in recursion limit. A deeply nested or maliciously crafted RLP input can cause unbounded recursion in readList/fromRlpCursor, leading to a stack overflow and process crash (DoS).

### [medium] Potential server-side request forgery (SSRF)

Finding ID: `NPS-6B7DB777C907`

File: `_esm/utils/ens/avatar/utils.js:12`

The function 'isImageUri' performs a 'fetch' request to an arbitrary user-supplied URI without validating the protocol or target. This could allow an attacker to make requests to internal services or local files if the library is used in a server-side context.

### [medium] Unvalidated external metadata fetching

Finding ID: `NPS-B7FA8D643D0E`

File: `_esm/utils/ens/avatar/utils.js:107`

The function 'getMetadataAvatarUri' fetches JSON from the provided 'uri' without validating the protocol or host. This could lead to SSRF or data exfiltration if the URI is controlled by an attacker.

### [medium] Undefined variable reference

Finding ID: `NPS-6B1F3DB2E6B4`

File: `_esm/utils/rpc/socket.js:6`

The code references a destructured variable `reconnect` in the expression `const { attempts = 5, delay = 2_000 } = typeof reconnect === 'object' ? reconnect : {};` but `reconnect` is never imported, declared, or passed into `getSocketRpcClient`. This will cause a ReferenceError at runtime and suggests the file is incomplete or was tampered with.

### [medium] Implicit trust in client-supplied paymaster functions

Finding ID: `NPS-9C6A4AB13C9C`

File: `account-abstraction/actions/bundler/prepareUserOperation.ts:314`

When `paymaster` is an object, the code directly assigns and later invokes `getPaymasterStubData` and `getPaymasterData` from that object without validation. The logic `(getPaymasterData && getPaymasterStubData ? getPaymasterStubData : getPaymasterData)` can cause a single function to be used for both stub and final paymaster data, potentially leaking data twice or executing unintended behavior if attacker-controlled.

### [medium] Dynamic network request to user-controlled endpoints

Finding ID: `NPS-4087BDDCD3C1`

File: `account-abstraction/actions/bundler/prepareUserOperation.ts:388`

The code dynamically invokes paymaster action functions (`getPaymasterStubData`, `getPaymasterData`) that are provided either by the bundler client or via the `paymaster` parameter. These calls can send the full UserOperation request (including sender address, callData, signature, and paymaster context) to external paymaster URLs. While this is a legitimate ERC-4337 paymaster pattern, if an attacker can supply or override the paymaster configuration (e.g., through bundler client decorators, configuration injection, or a compromised dependency), user operation data and possibly signatures can be exfiltrated to an untrusted endpoint.

### [medium] Test/Development utilities exported in production entrypoint

Finding ID: `NPS-65130DA558E7`

File: `actions/index.ts`

The file exports a large number of test-only utilities (e.g., impersonateAccount, setBalance, setCode, setNonce, setStorageAt, setRpcUrl, mine, reset, revert, loadState, dumpState, increaseTime, setNextBlockTimestamp, etc.) from the main public entrypoint. These methods can manipulate blockchain state, impersonate accounts, and modify balances/nonces. If an application bundles these exports and an attacker can influence which action is called (e.g., via dynamic dispatch or exposed API), it could lead to unauthorized state manipulation. While these are explicitly test utilities, their presence in the primary barrel file increases attack surface.

### [medium] Embedded EVM Bytecode

Finding ID: `NPS-DC868158F8F9`

File: `constants/contracts.ts`

The file contains three large hardcoded EVM bytecode blobs exported as string constants. These are compiled smart contract bytecodes intended for on-chain deployment and calls (a deployless call pattern). While not malicious on their own, embedded bytecode is opaque and cannot be easily audited in source form; it is a common vector for hiding logic such as signature validation, delegatecall proxies, or subtle address-rewriting behavior.

### [medium] Signature Validation / ECDSA Recovery Logic

Finding ID: `NPS-CC6470400BEC`

File: `constants/contracts.ts`

The universalSignatureValidatorByteCode contains embedded Solidity logic for validating ECDSA signatures, including the magic value 0x1626ba7e (ERC-1271 isValidSignature selector) and selective recovery logic. If this validator is used to verify wallet ownership (e.g., account abstraction), a flaw in the embedded bytecode could allow signature forgery or bypass of authorization checks.

### [medium] Obfuscated / Non-Auditable Payload

Finding ID: `NPS-6A6C1F2DD9BA`

File: `constants/contracts.ts`

Bytecode strings in hex are effectively obfuscated relative to their source. Without decompilation or a matching verified source, the exact behavior of these contracts cannot be confirmed from this TypeScript file alone. This is a supply-chain risk: a tampered bytecode string would silently alter on-chain behavior while looking like normal constants.

### [medium] Outbound network requests to user-supplied (on-chain) URLs

Finding ID: `NPS-B8DFA312B226`

File: `utils/ccip.ts:143`

ccipRequest() performs fetch() to URLs that originate from on-chain OffchainLookup error data (urls array). The URL, sender, and data are interpolated directly into the request URL ({sender}/{data}) and POST body without allowlisting, scheme validation, or restriction to https. A malicious or compromised contract can supply attacker-controlled URLs, turning this utility into a generic fetch primitive from the host application.

### [medium] Unvalidated dynamic URL construction / template injection

Finding ID: `NPS-AFCD9084AFC9`

File: `utils/ccip.ts:146`

url.replace('{sender}', sender).replace('{data}', data) blindly substitutes on-chain-provided values into the request URL. If a contract supplies a URL template with unexpected schemes (e.g., file:, gopher:, or internal hosts), the request target is fully attacker-influenced. No protocol/allowlist check exists.

### [medium] Weak Randomness for Identifier Generation

Finding ID: `NPS-D5A6EFB6168C`

File: `utils/uid.ts:10`

The uid() function uses Math.random() to generate identifiers. Math.random() is not cryptographically secure and is predictable, which is unsuitable for security-sensitive uses such as tokens, session IDs, CSRF nonces, or password reset links. If this utility is used for such purposes, it could allow attackers to predict or brute-force generated values. This is a code-quality/security weakness rather than an active malicious pattern.

### [low] dynamic property access with user input

Finding ID: `NPS-C8CDBB7DBAB2`

File: `_cjs/actions/getContract.js`

Uses Proxy objects to dynamically resolve function/event names from ABI onto contract methods; this is a legitimate pattern for building a contract interface, not obfuscation or dynamic code execution.

### [low] top-level module side effects

Finding ID: `NPS-DDCF0A001259`

File: `_cjs/actions/getContract.js`

Module exports functions but does not execute network, file system, or process operations at import time. All behavior is invoked only when consumers call getContract and execute returned methods.

### [low] dynamic module loading

Finding ID: `NPS-AE6157BFA7D4`

File: `_cjs/actions/public/call.js`

Lazy-loads the CCIP utility module via require('../../utils/ccip.js') only when handling offchain lookup errors. This is a normal optimization pattern, not obfuscated or externally controlled loading.

### [low] external network interaction

Finding ID: `NPS-C7F36ADABFB4`

File: `_cjs/actions/public/call.js`

Performs eth_call RPC requests and offchainLookup HTTP fetches, which are expected behaviors for an Ethereum client library handling CCIP reads. No exfiltration to hardcoded servers.

### [low] No dynamic code execution / file / process access

Finding ID: `NPS-D0193BDBD270`

File: `_cjs/utils/ccip.js`

No eval, new Function, child_process, fs, env var harvesting, or credential file access was found. Network access is limited to the CCIP offchain lookup mechanism.

### [low] Data exfiltration

Finding ID: `NPS-0D4A04613416`

File: `_cjs/utils/ccip.js:82`

The code sends user/contract-provided data (callData and sender address) via POST/GET to externally controlled URLs. While this is the documented CCIP read pattern, from a pure static-analysis standpoint it constitutes sending application data to external servers without an explicit URL allowlist.

### [low] Missing input bound validation

Finding ID: `NPS-B6020FCB1A3A`

File: `_cjs/utils/encoding/fromRlp.js:53`

readLength trusts the encoded length bytes (readUint8/16/24/32) and passes them to cursor.readBytes / list iteration without clamping against remaining buffer size. While cursor.readBytes may throw on out-of-bounds, the use of readUint32 and the absence of a maximum-length guard can facilitate memory/CPU exhaustion attacks when parsing untrusted input.

### [low] Use of global Image constructor with remote src

Finding ID: `NPS-5669630EDCF3`

File: `_cjs/utils/ens/avatar/utils.js:29`

In the catch branch of isImageUri, a new Image() is created with img.src = uri. This performs a browser-side request to an unvalidated URI, which can be used for tracking/pixel-style requests or to probe client networks.

### [low] External gateway requests with user-influenced URLs

Finding ID: `NPS-E0129329C8B7`

File: `_cjs/utils/ens/avatar/utils.js:62`

resolveAvatarUri constructs URLs pointing at ipfs.io, arweave.net, or custom gateways from attacker-influenced fields (target/subtarget from regex match). A malicious target value could potentially redirect requests to unintended hosts via the subtarget/path components.

### [low] Potential SVG/script payload handling

Finding ID: `NPS-E54325F19216`

File: `_cjs/utils/ens/avatar/utils.js:86`

resolveAvatarUri base64-encodes raw '<svg' content into a data:image/svg+xml URI. If the consuming application renders this SVG without sanitization, embedded scripts/event handlers could execute (XSS). The code does not sanitize SVG contents.

### [low] Trusted Setup File Loading

Finding ID: `NPS-755FBAB9CA91`

File: `_cjs/utils/kzg/setupKzg.js:6`

The function loads a trusted setup from a file path provided as an argument. Depending on how this function is called, an attacker-controlled path could lead to reading arbitrary files. However, this is a standard pattern for KZG libraries and is not inherently malicious.

### [low] Unhandled exceptions in socket data handler

Finding ID: `NPS-7461616AD45A`

File: `_cjs/utils/rpc/ipc.js:50`

JSON.parse() inside onData is not wrapped in try/catch. A malformed frame throws synchronously from the socket 'data' event, which can crash the process or leave the RPC client in an inconsistent state (message corruption after partial parsing).

### [low] weak randomness

Finding ID: `NPS-AC156082C37F`

File: `_cjs/utils/uid.js:12`

The uid function uses Math.random() for generating identifiers, which is not cryptographically secure. If these IDs are used for security-sensitive purposes (e.g., session tokens, password reset tokens), they could be predictable. However, this is a common pattern for non-security-related unique IDs and does not indicate malicious intent.

### [low] Stub signature hardcoded

Finding ID: `NPS-A0639238031F`

File: `_esm/account-abstraction/accounts/implementations/toSoladySmartAccount.js:95`

The getStubSignature method returns a fixed 65-byte signature (0xffff...1c) that is not derived from any input. This is typically used for gas estimation, but a static stub can be misused for replay attacks if not properly validated by the EntryPoint. However, this is standard practice in ERC-4337 account abstractions.

### [low] network-request

Finding ID: `NPS-591DFDE6BFAA`

File: `_esm/actions/public/call.js:155`

The code performs network requests via client.request for eth_call, which is the intended functionality of this blockchain library (viem). No exfiltration or suspicious endpoints are present.

### [low] dynamic-import

Finding ID: `NPS-3CD1E2E2A1D8`

File: `_esm/actions/public/call.js:168`

The code uses a dynamic import of '../../utils/ccip.js' inside a catch block for CCIP-Read offchain lookup handling. The path is hardcoded and static, not influenced by external input, so it is not a security concern.

### [low] Malformed URL containing whitespace

Finding ID: `NPS-51399D01B848`

File: `_esm/chains/definitions/swanProximaTestnet.js:7`

The default RPC HTTP URL 'https://rpc-proxima.swanchain.io\t' contains a trailing tab character. While this may be an accidental formatting artifact, a malformed endpoint could cause errors or, in some tooling, be normalized in unexpected ways. It is not an exfiltration or code-execution pattern, but it reduces confidence in the definition and may point to sloppy generation.

### [low] External network requests

Finding ID: `NPS-33C7D9DC5794`

File: `_esm/utils/ens/avatar/parseAvatarRecord.js`

The function ultimately resolves and returns a URI (via getMetadataAvatarUri or parseAvatarUri) that may point to external gateways (gatewayUrls). This is expected behavior for an avatar resolver but could be used for tracking or fetching malicious content if the URI is attacker-controlled. No direct exfiltration of sensitive data is present.

### [low] Potential data URI parsing with atob

Finding ID: `NPS-BD6F3251F8DF`

File: `_esm/utils/ens/avatar/parseAvatarRecord.js:33`

The code decodes a base64-encoded data URI using atob() and then parses it as JSON. While not malicious by itself, this could allow for injection of arbitrary JSON data if the source (NFT tokenURI) is attacker-controlled, potentially leading to denial of service or unexpected behavior, though not direct code execution.

### [low] Use of user-controlled image source

Finding ID: `NPS-131C1C44B1D9`

File: `_esm/utils/ens/avatar/utils.js:27`

In the error fallback of 'isImageUri', a new Image object is created with 'src' set to the user-provided URI. While this occurs only in browser environments, it could be exploited for client-side requests to internal resources or for tracking purposes.

### [low] Dynamic network connection to arbitrary URL

Finding ID: `NPS-A566E359E740`

File: `_esm/utils/rpc/socket.js:11`

The function accepts a caller-supplied `url` and passes it to `getSocket`, opening a WebSocket connection to that endpoint. Combined with the permissive caching keyed only on `key:url` and the ability to pass arbitrary JSON-RPC bodies (including `eth_subscribe`), this is a standard JSON-RPC client primitive, but any consumer supplying a malicious URL could be leveraged for SSRF or data exfiltration. No allowlist or scheme validation is present.

### [low] Unbounded retry/reconnect loop

Finding ID: `NPS-49E374D5B458`

File: `_esm/utils/rpc/socket.js:45`

The reconnect logic uses `setTimeout` with a fixed `delay` and increments a `reconnectCount` that is only reset on `onOpen`. Because `reconnect` is undefined, the object-destructuring path yields `{}`, so `attempts` and `delay` remain defaults; however if `reconnect` were later supplied with a large value this could create a sustained connect/disconnect loop. Minor concern in current form.

### [low] Unvalidated callback invocation with parsed response

Finding ID: `NPS-F95EAD6C0E7B`

File: `_esm/utils/rpc/socket.js:88`

`onResponse` receives the raw decoded JSON-RPC message and immediately looks up `data.params.subscription` without checking that `data` or `data.params` exist for non-subscription methods, and without validating the `id` type. Malformed or attacker-controlled server responses could cause type confusion or crashes, though no code execution is possible in plain JS here.

### [low] Dynamic import

Finding ID: `NPS-B322085BE4C1`

File: `_esm/utils/rpc/webSocket.js:8`

The module dynamically imports 'isows' to obtain the WebSocket implementation. This is a standard pattern for cross-environment WebSocket support and the import target is a hardcoded package name, not computed from external input.

### [low] Network communication

Finding ID: `NPS-A99892041E03`

File: `_esm/utils/rpc/webSocket.js:9`

The code opens a WebSocket connection to the provided 'url' and sends JSON-RPC requests (notably 'net_version'). This is the intended functionality of an RPC client and the URL is supplied by the caller, not harvested from credentials or environment.

### [low] Dynamic import

Finding ID: `NPS-7ABB10B18922`

File: `_esm/utils/signature/recoverPublicKey.js:6`

The code uses a dynamic import() for '@noble/curves/secp256k1'. This is not computed or based on external input, and is a common pattern for lazy-loading dependencies. No malicious intent is evident.

### [low] hardcoded_trusted_contract_address

Finding ID: `NPS-DAA1BAC472E2`

File: `account-abstraction/accounts/implementations/toSoladySmartAccount.ts`

The factory address default '0x5d82735936c6Cd5DE57cC3c1A799f6B2E6F933Df' is hardcoded. This is a normal design choice for a Solady Smart Account factory wrapper. It is not a malicious pattern, but integrators should verify this address independently if they do not override it.

### [low] Unbounded fee estimation buffer using Number conversion

Finding ID: `NPS-6F5F52CEFF06`

File: `account-abstraction/actions/bundler/prepareUserOperation.ts:472`

Fee values are converted using `Number(2n * fees.maxFeePerGas)` and similar expressions. For very large `maxFeePerGas` values this can exceed `Number.MAX_SAFE_INTEGER` and introduce precision loss, potentially altering transaction economics. This is a correctness issue that an attacker could exploit to craft unexpected fee values in edge cases, though not direct exfiltration.

### [low] Potential for address/account manipulation

Finding ID: `NPS-DA85E46AA04F`

File: `actions/index.ts`

Several exported wallet actions (e.g., requestAddresses, getAddresses, watchAsset, switchChain) interact with user wallets. A malicious dependency could potentially use these to trick users into approving malicious chains or assets. However, no direct malicious behavior is evident in this file; the risk depends on the implementation of the imported modules.

### [low] dynamic-import

Finding ID: `NPS-96754AEE1BD2`

File: `actions/public/call.ts`

Dynamic import of '../../utils/ccip.js' is performed inside the catch block. While this is a legitimate feature for CCIP-Read offchain lookup, dynamic imports can be abused in general if the path were computed from external input. Here the path is static, so risk is low, but noted as a potential red flag category.

### [low] external-network-request

Finding ID: `NPS-90E12025B55B`

File: `actions/public/call.ts`

The function performs RPC calls (client.request with eth_call) and can trigger offchainLookup which may fetch data from external URLs defined in the contract's CCIP-Read response. This is expected behavior for an Ethereum client library, not data exfiltration, but involves network requests to endpoints that could be attacker-controlled if the 'to' address or chain is untrusted.

### [low] state-override

Finding ID: `NPS-B57DDC6239D9`

File: `actions/public/call.ts`

Accepts 'stateOverride' parameter and serializes it for 'eth_call' RPC. State overrides can be used to manipulate contract state during calls and could be abused if input is not validated by the caller. However, this is an intended feature of the library.

### [low] Suspicious URL formatting

Finding ID: `NPS-8BEC0F4518E8`

File: `chains/definitions/swanProximaTestnet.ts:6`

The RPC HTTP URL contains a trailing tab character ('https://rpc-proxima.swanchain.io	'), which is likely unintended and could cause connection failures or unexpected behavior. While not malicious, it is a code quality/security concern.

### [low] No Runtime Code Execution in Module Scope

Finding ID: `NPS-28423784331B`

File: `constants/contracts.ts`

No top-level code, dynamic imports, eval, child_process, network calls, or filesystem access are present in this module. The constants are inert strings until consumed by another module, so no install-time or import-time execution risk exists in this file itself.

### [low] Custom user hook overriding request behavior

Finding ID: `NPS-C45A7FA661B9`

File: `utils/ccip.ts:76`

client.ccipRead?.request can be user-supplied and completely replaces the default ccipRequest implementation, allowing arbitrary network behavior in an otherwise controlled code path. This is by design in the library, but it means callers can inject arbitrary request logic without auditing.

### [low] Untrusted response handling without size/content constraints

Finding ID: `NPS-FF6622F9F7A4`

File: `utils/ccip.ts:155`

The response is read as JSON or text without size limits or content validation before being re-encoded into an eth_call callback payload. A malicious CCIP server could return very large payloads (DoS) or unexpected content types, which are only loosely validated by isHex().

### [low] dynamic import

Finding ID: `NPS-171703481727`

File: `utils/signature/recoverPublicKey.ts:34`

The function dynamically imports @noble/curves/secp256k1 inside the function. This is a legitimate library for cryptographic operations and not an external input-controlled module load. No suspicious network or file access is present.

## Files reviewed

- `_cjs/chains/definitions/donatuz.js` (medium): The file defines a blockchain chain configuration with a malformed RPC URL, likely a typo, but no other malicious patterns were detected.
- `_cjs/utils/ccip.js` (medium): The file implements the standard EIP-3668 CCIP-read offchain lookup, but makes unvalidated network requests to URLs supplied in error data, which is a moderate concern in a third-party package context; no other malicious patterns were detected.
- `_cjs/utils/encoding/fromRlp.js` (medium): The file contains no malicious patterns (no exfiltration, credential harvesting, code execution, or network/file/process access), but it disables recursion limits and lacks length bounds, creating a potential denial-of-service risk when parsing untrusted RLP input.
- `_cjs/utils/ens/avatar/utils.js` (medium): No outright malicious patterns (no exfiltration, credential harvesting, eval, mining, or process spawning) were found, but the module performs fetches on attacker-influenced URIs without SSRF protections and base64-encodes unsanitized SVG content, which warrants security review.
- `_cjs/utils/rpc/ipc.js` (medium): The IPC RPC client contains no exfiltration, credential harvesting, obfuscation, mining, backdoor, or process-spawning code, but it parses untrusted socket data with unbounded JSON.parse, has a brace-counting parser that mishandles JSON strings, and forwards an unvalidated path to net.connect, creating DoS and potential local-socket-abuse risks.
- `_cjs/zksync/accounts/toMultisigSmartAccount.js` (medium): The code implements multisig signing with private keys as expected, but handling private keys in a third-party package poses a medium risk if the package is compromised or keys are mishandled.
- `_esm/account-abstraction/accounts/implementations/toSoladySmartAccount.js` (medium): The code is part of a legitimate smart account implementation but contains several design risks such as hardcoded factory address, stub signature, and configurable factory that could lead to fund loss if parameters are not trusted.
- `_esm/chains/definitions/swanProximaTestnet.js` (medium): The file defines a static blockchain chain configuration with no executable, network, credential, or obfuscation red flags; only a minor malformed RPC URL containing a trailing tab character was observed.
- `_esm/utils/ccip.js` (medium): This is legitimate CCIP-read / EIP-3668 offchain lookup code with no malicious exfiltration of local files or credentials, but it performs user/contract-controlled outbound HTTP requests (potential SSRF surface) and trusts returned data in a callback, which is a low-to-medium security concern inherent to the protocol.
- `_esm/utils/encoding/fromRlp.js` (medium): The RLP decoding logic appears functionally benign with no exfiltration, credential harvesting, or code execution patterns, but explicitly disables the recursive read limit, exposing consumers to stack-overflow denial-of-service on untrusted input.
- `_esm/utils/ens/avatar/parseAvatarRecord.js` (medium): The code is a legitimate ENS avatar parser with no clear malicious patterns, but it processes external URIs and decodes base64 JSON, which pose minor risks if inputs are untrusted.
- `_esm/utils/ens/avatar/utils.js` (medium): The code contains potential SSRF risks through unvalidated fetch requests to user-supplied URIs, but no direct malicious patterns such as data exfiltration, credential harvesting, or backdoors were detected.
- `_esm/utils/rpc/socket.js` (medium): Standard JSON-RPC WebSocket client with no exfiltration, credential harvesting, eval, child_process, or backdoor patterns, but it contains an undefined `reconnect` variable that would break execution and includes an unvalidated URL/response handling path.
- `account-abstraction/actions/bundler/prepareUserOperation.ts` (medium): No direct malicious patterns (exfiltration, credential harvesting, shell execution, obfuscation) are present, but the code legitimately forwards UserOperation data to dynamically resolved paymaster functions, which represents a potential data exposure risk if the paymaster configuration is attacker-controlled.
- `actions/index.ts` (medium): The file is a barrel export of many blockchain utility functions, including test-only state manipulation methods, but contains no direct malicious patterns such as exfiltration, credential harvesting, or code execution.
- `actions/public/call.ts` (medium): This is the standard viem library 'call' action implementing eth_call with multicall batching, deployless calls, and CCIP-Read support; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or process spawning were detected.
- `chains/definitions/swanProximaTestnet.ts` (medium): The file defines a blockchain chain configuration and appears benign, but contains a minor URL formatting issue with a trailing tab character.
- `constants/contracts.ts` (medium): The file exports hardcoded EVM bytecode for deployless contract calls and signature validation; no direct malicious runtime behavior is present, but the opaque embedded bytecode cannot be verified from source and could conceal unsafe on-chain logic if tampered with.
- `utils/ccip.ts` (medium): This is standard viem CCIP-read code with no exfiltration, credential harvesting, process spawning, or obfuscation, but it makes outbound HTTP requests to on-chain-controlled URLs without allowlisting, which is an inherent SSRF-style risk surface if used with untrusted contracts.
- `utils/uid.ts` (medium): No malicious behavior detected, but the uid() helper relies on non-cryptographic Math.random(), making it unsafe for security-sensitive identifier generation.
- `_cjs/account-abstraction/accounts/createWebAuthnCredential.js` (safe): The code is a straightforward wrapper around WebAuthn credential creation with no malicious patterns detected.
- `_cjs/account-abstraction/accounts/implementations/toCoinbaseSmartAccount.js` (safe): This is a legitimate Coinbase Smart Wallet account abstraction module with no malicious patterns detected.
- `_cjs/account-abstraction/accounts/implementations/toSoladySmartAccount.js` (safe): The code is a standard ERC-4337 smart account implementation for Solady accounts, with no malicious patterns detected.
- `_cjs/account-abstraction/accounts/toSmartAccount.js` (safe): No malicious patterns detected
- `_cjs/account-abstraction/accounts/toWebAuthnAccount.js` (safe): No malicious patterns detected; the file implements a WebAuthn account abstraction with no exfiltration, obfuscation, or suspicious behavior.
- `_cjs/account-abstraction/accounts/types.js` (safe): No malicious patterns detected
- `_cjs/account-abstraction/actions/bundler/estimateUserOperationGas.js` (safe): No malicious patterns detected; the code is a standard account abstraction utility for estimating user operation gas via an RPC call.
- `_cjs/account-abstraction/actions/bundler/getSupportedEntryPoints.js` (safe): No malicious patterns detected
- `_cjs/account-abstraction/actions/bundler/getUserOperation.js` (safe): No malicious patterns detected; the code performs a standard JSON-RPC request to fetch user operation data and formats the response.
- `_cjs/account-abstraction/actions/bundler/getUserOperationReceipt.js` (safe): The code performs a standard JSON-RPC request to fetch a user operation receipt and formats the result; no malicious patterns detected.
- `_cjs/account-abstraction/actions/bundler/prepareUserOperation.js` (safe): No malicious patterns detected; the code is a standard user operation preparation utility for an Ethereum account abstraction library.
- `_cjs/account-abstraction/actions/bundler/sendUserOperation.js` (safe): No malicious patterns detected; the code is a standard ERC-4337 user operation submission utility that constructs and sends RPC requests without any obfuscation, data exfiltration, credential harvesting, or dynamic code execution.
- `_cjs/account-abstraction/actions/bundler/waitForUserOperationReceipt.js` (safe): No malicious patterns detected in the provided waitForUserOperationReceipt utility code.
- `_cjs/account-abstraction/actions/paymaster/getPaymasterData.js` (safe): No malicious patterns detected
- `_cjs/account-abstraction/actions/paymaster/getPaymasterStubData.js` (safe): No malicious patterns detected
- `_cjs/account-abstraction/clients/createBundlerClient.js` (safe): No malicious patterns detected; the code is a straightforward factory for creating a bundler client with standard imports and no suspicious behavior.
- `_cjs/account-abstraction/clients/createPaymasterClient.js` (safe): No malicious patterns detected; the code is a standard client factory for a paymaster client in an account abstraction library.
- `_cjs/account-abstraction/clients/decorators/bundler.js` (safe): No malicious patterns detected; the file only aggregates user operation actions and delegates to trusted internal modules without suspicious behavior.
- `_cjs/account-abstraction/clients/decorators/paymaster.js` (safe): No malicious patterns detected
- `_cjs/account-abstraction/constants/abis.js` (safe): No malicious patterns detected
- `_cjs/account-abstraction/constants/address.js` (safe): No malicious patterns detected
- `_cjs/account-abstraction/errors/bundler.js` (safe): This file only defines error classes for bundler/account-abstraction errors, with no network, filesystem, process, or dynamic code execution behavior.
- `_cjs/account-abstraction/errors/userOperation.js` (safe): No malicious patterns detected; the file contains only error class definitions for user operation handling with no network, filesystem, process, or dynamic execution behavior.
- `_cjs/account-abstraction/index.js` (safe): No malicious patterns detected; the file is a standard module barrel/index file for an account abstraction library, re-exporting symbols via Object.defineProperty with no execution of untrusted code or network/file system access.
- `_cjs/account-abstraction/types/account.js` (safe): No malicious patterns detected in the provided file.
- `_cjs/account-abstraction/types/entryPointVersion.js` (safe): No malicious patterns detected
- `_cjs/account-abstraction/types/rpc.js` (safe): No malicious patterns detected
- `_cjs/account-abstraction/types/userOperation.js` (safe): The file contains only TypeScript compression boilerplate for a type declaration module, with no executable code or malicious patterns.
- `_cjs/account-abstraction/utils/errors/getBundlerError.js` (safe): No malicious patterns detected
- `_cjs/account-abstraction/utils/errors/getUserOperationError.js` (safe): No malicious patterns detected
- `_cjs/account-abstraction/utils/formatters/userOperation.js` (safe): No malicious patterns detected; the code only performs deterministic BigInt conversion for user operation parameters.
- `_cjs/account-abstraction/utils/formatters/userOperationGas.js` (safe): Cleared by Jev triage; no further analysis needed
- `_cjs/account-abstraction/utils/formatters/userOperationReceipt.js` (safe): No malicious patterns detected; the code performs straightforward formatting of user operation receipt data without any exfiltration, obfuscation, or dynamic execution.
- `_cjs/account-abstraction/utils/formatters/userOperationRequest.js` (safe): No malicious patterns detected; the file is a straightforward formatter that hex-encodes numeric fields for a UserOperation RPC request with no network, filesystem, process, or dynamic code execution activity.
- `_cjs/account-abstraction/utils/userOperation/getUserOperationHash.js` (safe): No malicious patterns detected
- `_cjs/account-abstraction/utils/userOperation/toPackedUserOperation.js` (safe): No malicious patterns detected
- `_cjs/accounts/generateMnemonic.js` (safe): No malicious patterns detected
- `_cjs/accounts/generatePrivateKey.js` (safe): No malicious patterns detected; the code uses the reputable @noble/curves library to generate a secp256k1 private key and encodes it to hex.
- `_cjs/accounts/hdKeyToAccount.js` (safe): No malicious patterns detected; the code is a standard HD key to account conversion utility with no exfiltration, obfuscation, network, or process execution.
- `_cjs/accounts/index.js` (safe): This is a standard module index file that re-exports Ethereum account utilities; it contains no malicious patterns, network calls, dynamic code execution, or credential harvesting.
- `_cjs/accounts/mnemonicToAccount.js` (safe): No malicious patterns detected; the code is a straightforward mnemonic-to-account conversion utility using standard cryptographic libraries with no network, filesystem, process, or obfuscated behavior.
- `_cjs/accounts/privateKeyToAccount.js` (safe): No malicious patterns detected; the code is a standard viem-style utility for creating an Ethereum account from a private key.
- `_cjs/accounts/toAccount.js` (safe): The file contains a straightforward utility function for converting input into an account object, with no malicious patterns such as data exfiltration, dynamic code execution, or environment manipulation.
- `_cjs/accounts/types.js` (safe): No malicious patterns detected
- `_cjs/accounts/utils/parseAccount.js` (safe): No malicious patterns detected
- `_cjs/accounts/utils/privateKeyToAddress.js` (safe): No malicious patterns detected; the code performs standard secp256k1 public key derivation and address computation without exfiltration, obfuscation, or side effects.
- `_cjs/accounts/utils/publicKeyToAddress.js` (safe): No malicious patterns detected; the code performs a standard Ethereum public key to address conversion using keccak256 and checksum formatting.
- `_cjs/accounts/utils/sign.js` (safe): No malicious patterns detected
- `_cjs/accounts/utils/signAuthorization.js` (safe): No malicious patterns detected; the code is a straightforward EIP-7702 authorization signing utility with no external data handling, network calls, or dynamic code execution.
- `_cjs/accounts/utils/signMessage.js` (safe): No malicious patterns detected; the file only implements cryptographic message signing using local utility imports.
- `_cjs/accounts/utils/signTransaction.js` (safe): No malicious patterns detected; the code is a standard cryptographic transaction signing utility with no network, filesystem, or process activity.
- `_cjs/accounts/utils/signTypedData.js` (safe): No malicious patterns detected; the code is a straightforward typed-data signing utility with no exfiltration, obfuscation, network, filesystem, or process-spawning behavior.
- `_cjs/accounts/wordlists.js` (safe): No malicious patterns detected
- `_cjs/actions/ens/getEnsAddress.js` (safe): No malicious patterns detected; the code implements standard ENS address resolution using viem's built-in utilities and contract reads.
- `_cjs/actions/ens/getEnsAvatar.js` (safe): No malicious patterns detected
- `_cjs/actions/ens/getEnsName.js` (safe): No malicious patterns detected
- `_cjs/actions/ens/getEnsResolver.js` (safe): No malicious patterns detected; the code performs standard ENS resolver lookups via contract reads and imports only local utility modules.
- `_cjs/actions/ens/getEnsText.js` (safe): No malicious patterns detected; the code is a standard ENS text record resolver implementation using contract reads and ABI encoding/decoding.
- `_cjs/actions/getContract.js` (safe): No malicious patterns detected; the file is a standard viem-style contract interaction helper with expected dynamic ABI method resolution and no data exfiltration, credential harvesting, obfuscation, or process execution.
- `_cjs/actions/index.js` (safe): No malicious patterns detected; this is a standard Ethereum/viem action re-export index file.
- `_cjs/actions/public/call.js` (safe): The file is a legitimate viem Ethereum RPC call implementation with expected network interactions, no obfuscation, credential harvesting, shell execution, or malicious patterns.
- `_cjs/actions/public/createAccessList.js` (safe): No malicious patterns detected; the code is a standard viem library function for creating Ethereum access lists.
- `_cjs/actions/public/createBlockFilter.js` (safe): No malicious patterns detected; the code performs a standard Ethereum JSON-RPC call to create a block filter with no exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `_cjs/actions/public/createContractEventFilter.js` (safe): No malicious patterns detected; the code is a standard Ethereum contract event filter creation function from the viem library.
- `_cjs/actions/public/createEventFilter.js` (safe): No malicious patterns detected
- `_cjs/actions/public/createPendingTransactionFilter.js` (safe): No malicious patterns detected; the code is a standard Ethereum JSON-RPC client method for creating a pending transaction filter.
- `_cjs/actions/public/estimateContractGas.js` (safe): No malicious patterns detected; the code is a standard library function for estimating contract gas in a blockchain client.
- `_cjs/actions/public/estimateFeesPerGas.js` (safe): No malicious patterns detected; the file contains legitimate Ethereum fee estimation logic using standard viem library imports and no suspicious behavior.
- `_cjs/actions/public/estimateGas.js` (safe): No malicious patterns detected; the code is a standard viem library function for estimating gas via eth_estimateGas RPC calls.
- `_cjs/actions/public/estimateMaxPriorityFeePerGas.js` (safe): No malicious patterns detected; the code appears to be a legitimate library function for estimating Ethereum transaction fees.
- `_cjs/actions/public/getBalance.js` (safe): No malicious patterns detected; the file is a straightforward Ethereum JSON-RPC getBalance helper with no network exfiltration, credential access, obfuscation, or process execution.
- `_cjs/actions/public/getBlobBaseFee.js` (safe): No malicious patterns detected
- `_cjs/actions/public/getBlock.js` (safe): No malicious patterns detected
- `_cjs/actions/public/getBlockNumber.js` (safe): No malicious patterns detected; the code is a straightforward Ethereum JSON-RPC wrapper that caches block numbers with no exfiltration, credential access, obfuscation, or process spawning.
- `_cjs/actions/public/getBlockTransactionCount.js` (safe): No malicious patterns detected
- `_cjs/actions/public/getChainId.js` (safe): No malicious patterns detected; the file contains a standard Ethereum JSON-RPC call to retrieve the chain ID.
- `_cjs/actions/public/getCode.js` (safe): No malicious patterns detected
- `_cjs/actions/public/getContractEvents.js` (safe): No malicious patterns detected; the code is a standard Ethereum contract event retrieval utility with no exfiltration, obfuscation, or dynamic execution.
- `_cjs/actions/public/getEip712Domain.js` (safe): No malicious patterns detected
- `_cjs/actions/public/getFeeHistory.js` (safe): No malicious patterns detected
- `_cjs/actions/public/getFilterChanges.js` (safe): No malicious patterns detected; the code performs legitimate Ethereum JSON-RPC filter change retrieval and log parsing.
- `_cjs/actions/public/getFilterLogs.js` (safe): No malicious patterns detected; the code is a straightforward Ethereum filter logs retrieval and parsing utility.
- `_cjs/actions/public/getGasPrice.js` (safe): No malicious patterns detected
- `_cjs/actions/public/getLogs.js` (safe): No malicious patterns detected
- `_cjs/actions/public/getProof.js` (safe): No malicious patterns detected; the code is a standard Ethereum JSON-RPC getProof implementation with no exfiltration, obfuscation, or suspicious behavior.
- `_cjs/actions/public/getStorageAt.js` (safe): No malicious patterns detected; the file is a straightforward viem library wrapper that calls eth_getStorageAt via the provided client.
- `_cjs/actions/public/getTransaction.js` (safe): No malicious patterns detected; the code is a legitimate Ethereum JSON-RPC utility for fetching transaction data.
- `_cjs/actions/public/getTransactionConfirmations.js` (safe): No malicious patterns detected; the code is a benign utility for calculating transaction confirmations using standard Ethereum client actions.
- `_cjs/actions/public/getTransactionCount.js` (safe): No malicious patterns detected
- `_cjs/actions/public/getTransactionReceipt.js` (safe): No malicious patterns detected; the code is a standard Ethereum JSON-RPC method wrapper for fetching transaction receipts.
- `_cjs/actions/public/multicall.js` (safe): No malicious patterns detected; the code is a standard multicall implementation for Ethereum smart contract interactions.
- `_cjs/actions/public/readContract.js` (safe): No malicious patterns detected; the file is a standard viem readContract utility with no exfiltration, obfuscation, dynamic execution, or suspicious I/O.
- `_cjs/actions/public/simulateBlocks.js` (safe): No malicious patterns detected; this is a legitimate viem-style RPC simulation module with no data exfiltration, credential harvesting, obfuscation, or process execution.
- `_cjs/actions/public/simulateCalls.js` (safe): No malicious patterns detected; the code is a standard Ethereum simulation utility using inline deployless call bytecode for balance queries and does not exfiltrate data, execute arbitrary code, or spawn processes.
- `_cjs/actions/public/simulateContract.js` (safe): No malicious patterns detected; the code is a standard Ethereum contract simulation utility with no external data transmission, credential access, dynamic code execution, or other suspicious behavior.
- `_cjs/actions/public/uninstallFilter.js` (safe): No malicious patterns detected; the file is a simple, legitimate Ethereum JSON-RPC helper for uninstalling a filter.
- `_cjs/actions/public/verifyHash.js` (safe): No malicious patterns detected; the code implements a legitimate Ethereum signature verification utility without data exfiltration, credential harvesting, obfuscation, mining, backdoors, or suspicious network/file/process activity.
- `_cjs/actions/public/verifyMessage.js` (safe): No malicious patterns detected; the file is a straightforward Ethers-style message verification wrapper that hashes input and delegates to verifyHash without any exfiltration, obfuscation, process spawning, or install-time execution.
- `_cjs/actions/public/verifyTypedData.js` (safe): No malicious patterns detected; the code is a straightforward typed-data verification utility with only static module imports and no network, filesystem, process, or dynamic-execution behavior.
- `_cjs/actions/public/waitForTransactionReceipt.js` (safe): The code is a legitimate Ethereum transaction receipt waiting utility that uses standard blockchain interaction patterns without any malicious behavior.
- `_cjs/actions/public/watchBlockNumber.js` (safe): No malicious patterns detected; the code is a standard blockchain block number watcher from the viem library with no data exfiltration, credential harvesting, obfuscation, or other security concerns.
- `_cjs/actions/public/watchBlocks.js` (safe): No malicious patterns detected; the code is a standard blockchain block watcher utility with no exfiltration, credential harvesting, obfuscation, or network abuse.
- `_cjs/actions/public/watchContractEvent.js` (safe): No malicious patterns detected; the code is a standard viem library utility for watching contract events with no exfiltration, credential harvesting, obfuscation, or other red flags.
- `_cjs/actions/public/watchEvent.js` (safe): No malicious patterns detected; the code is a legitimate event watcher for blockchain logs with no data exfiltration, credential harvesting, dynamic code execution, or other security concerns.
- `_cjs/actions/public/watchPendingTransactions.js` (safe): No malicious patterns detected; this is a legitimate viem library utility for watching pending blockchain transactions.
- `_cjs/actions/siwe/verifySiweMessage.js` (safe): No malicious patterns detected; the code performs standard SIWE message verification using local utility functions without any exfiltration, obfuscation, or suspicious behavior.
- `_cjs/actions/wallet/addChain.js` (safe): No malicious patterns detected; the code is a straightforward wrapper for the EIP-3085 wallet_addEthereumChain RPC call.
- `_cjs/actions/wallet/deployContract.js` (safe): No malicious patterns detected
- `_cjs/actions/wallet/getAddresses.js` (safe): No malicious patterns detected
- `_cjs/actions/wallet/getPermissions.js` (safe): No malicious patterns detected; the file is a straightforward wrapper for the wallet_getPermissions RPC method with no suspicious behavior.
- `_cjs/actions/wallet/prepareTransactionRequest.js` (safe): No malicious patterns detected; the code is a legitimate Ethereum transaction preparation module with no data exfiltration, credential harvesting, or backdoor behavior.
- `_cjs/actions/wallet/requestAddresses.js` (safe): No malicious patterns detected; the code simply requests Ethereum addresses from a client and normalizes them.
- `_cjs/actions/wallet/requestPermissions.js` (safe): No malicious patterns detected; code is a straightforward wrapper for a wallet permission request RPC call.
- `_cjs/actions/wallet/sendRawTransaction.js` (safe): The code is a simple wrapper for sending raw Ethereum transactions via a client request, with no malicious patterns such as exfiltration, credential harvesting, obfuscation, or dynamic code execution.
- `_cjs/actions/wallet/sendTransaction.js` (safe): No malicious patterns detected; the code is a standard Ethereum transaction sending utility from viem library with no data exfiltration, credential harvesting, obfuscation, or unauthorized system access.
- `_cjs/actions/wallet/signMessage.js` (safe): No malicious patterns detected; the code is a standard wallet signMessage action that delegates signing and makes a single RPC request without data exfiltration, obfuscation, or process execution.
- `_cjs/actions/wallet/signTransaction.js` (safe): No malicious patterns detected
- `_cjs/actions/wallet/signTypedData.js` (safe): No malicious patterns detected; the code is a standard Ethereum EIP-712 typed data signing utility with no network exfiltration, credential harvesting, obfuscation, or filesystem/process manipulation.
- `_cjs/actions/wallet/switchChain.js` (safe): No malicious patterns detected
- `_cjs/actions/wallet/watchAsset.js` (safe): No malicious patterns detected
- `_cjs/actions/wallet/writeContract.js` (safe): No malicious patterns detected
- `_cjs/celo/chainConfig.js` (safe): No malicious patterns detected; the file only re-exports chain configuration objects from relative modules.
- `_cjs/celo/fees.js` (safe): No malicious patterns detected
- `_cjs/celo/formatters.js` (safe): No malicious patterns detected; the code is a standard blockchain transaction/block formatter with no network, filesystem, process, or obfuscation activity.
- `_cjs/celo/index.js` (safe): No malicious patterns detected; this is a simple barrel index file re-exporting chainConfig, parseTransaction, and serializeTransaction with no runtime side effects or suspicious behavior.
- `_cjs/celo/parsers.js` (safe): No malicious patterns detected; the file contains standard Celo transaction parsing logic without exfiltration, code execution, or lifecycle hooks.
- `_cjs/celo/serializers.js` (safe): No malicious patterns detected; the code implements CIP-42/64 transaction serialization and validation with no data exfiltration, credential harvesting, dynamic execution, or other suspicious behavior.
- `_cjs/celo/types.js` (safe): No malicious patterns detected
- `_cjs/celo/utils.js` (safe): No malicious patterns detected; the code contains only simple utility functions for value checks and transaction type detection with no network, filesystem, or process activity.
- `_cjs/chains/definitions/0g.js` (safe): No malicious patterns detected; the file only defines a blockchain network configuration using a standard defineChain utility.
- `_cjs/chains/definitions/5ireChain.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/abey.js` (safe): No malicious patterns detected; the file only defines a blockchain network configuration using a local utility import.
- `_cjs/chains/definitions/abstract.js` (safe): This file is a standard chain definition for the Abstract blockchain network, containing only static configuration data and no malicious patterns.
- `_cjs/chains/definitions/abstractTestnet.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/acala.js` (safe): No malicious patterns detected; the file is a standard chain definition module with static configuration data only.
- `_cjs/chains/definitions/acria.js` (safe): No malicious patterns detected; the file only defines chain metadata (id, name, RPC URL, explorer) with no suspicious behavior.
- `_cjs/chains/definitions/adf.js` (safe): No malicious patterns detected; the file only defines a blockchain chain configuration with static metadata and no executable or network-triggering code.
- `_cjs/chains/definitions/aioz.js` (safe): No malicious patterns detected; the file is a standard chain definition for AIOZ Network with no obfuscation, network requests, or system access.
- `_cjs/chains/definitions/alephZero.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/alephZeroTestnet.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/alienX.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/alienXHalTestnet.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/ancient8.js` (safe): No malicious patterns detected; the file is a standard chain configuration definition with no executable or exfiltration behavior.
- `_cjs/chains/definitions/ancient8Sepolia.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/anvil.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/apeChain.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/apexTestnet.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/arbitrum.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/arbitrumGoerli.js` (safe): No malicious patterns detected; the file is a standard chain definition for Arbitrum Goerli with no dynamic execution, network calls, or credential harvesting.
- `_cjs/chains/definitions/arbitrumNova.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/arbitrumSepolia.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/areonNetwork.js` (safe): No malicious patterns detected in the chain definition file; it only contains standard blockchain network configuration.
- `_cjs/chains/definitions/areonNetworkTestnet.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/artelaTestnet.js` (safe): No malicious patterns detected; the file is a standard chain definition configuration for Artela Testnet.
- `_cjs/chains/definitions/arthera.js` (safe): This file is a standard chain definition for the Arthera network and contains no malicious patterns or security concerns.
- `_cjs/chains/definitions/artheraTestnet.js` (safe): No malicious patterns detected; the file is a simple, static chain definition for the Arthera Testnet.
- `_cjs/chains/definitions/assetChain.js` (safe): The file contains only a static chain definition with hardcoded RPC and explorer URLs and no malicious patterns or dynamic behavior.
- `_cjs/chains/definitions/assetChainTestnet.js` (safe): No malicious patterns detected; the file only defines a blockchain chain configuration with static URLs and contract addresses.
- `_cjs/chains/definitions/astar.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/astarZkEVM.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/astarZkyoto.js` (safe): This file only defines a blockchain chain configuration object with a static RPC URL and multicall contract address, and contains no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
- `_cjs/chains/definitions/atletaOlympia.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/aurora.js` (safe): No malicious patterns detected; the file is a standard chain definition for Aurora with no network, filesystem, process, or obfuscated code.
- `_cjs/chains/definitions/auroraTestnet.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/auroria.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/avalanche.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/avalancheFuji.js` (safe): This file only defines a static blockchain chain configuration for Avalanche Fuji testnet with no malicious patterns or suspicious behavior.
- `_cjs/chains/definitions/b3.js` (safe): No malicious patterns detected; the file is a static chain definition with no network, filesystem, or code-execution behavior beyond a declarative RPC URL.
- `_cjs/chains/definitions/b3Sepolia.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/bahamut.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/base.js` (safe): No malicious patterns detected; the file is a standard chain configuration definition for Base using the viem library.
- `_cjs/chains/definitions/baseGoerli.js` (safe): This file is a standard blockchain chain definition configuration for Base Goerli (a testnet), containing only static RPC URLs, contract addresses, and chain metadata with no malicious patterns.
- `_cjs/chains/definitions/baseSepolia.js` (safe): No malicious patterns detected; the file only defines a static chain configuration for Base Sepolia with fixed contract addresses and RPC endpoints.
- `_cjs/chains/definitions/beam.js` (safe): No malicious patterns detected; the file only defines a blockchain chain configuration object with static RPC URLs, explorer URL, and multicall contract address.
- `_cjs/chains/definitions/beamTestnet.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/bearNetworkChainMainnet.js` (safe): No malicious patterns detected
- `_cjs/chains/definitions/bearNetworkChainTestnet.js` (safe): No malicious patterns detected; the file only defines a blockchain testnet configuration with standard RPC and explorer URLs.
- `_cjs/chains/definitions/berachain.js` (safe): This file is a static chain definition for Berachain with no executable, network, or credential-harvesting logic; no malicious patterns detected.
- `_cjs/chains/definitions/berachainTestnet.js` (safe): No malicious patterns detected; the file only defines a static blockchain network configuration object with no external calls, dynamic code, or process execution.
- `_cjs/chains/definitions/berachainTestnetbArtio.js` (safe): No malicious patterns detected; this is a standard chain definition file for a testnet.

## Version ranges

None of the 2 scanned versions of viem are flagged high or critical. The latest scanned version, 2.47.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 2.47.0 (`2.47.0`): not scanned
- 2.23.2 – 2.41.2 (`>=2.23.2 <=2.41.2`): medium (Resource exhaustion / unbounded recursion +4 more)

## Scanned versions

- [2.41.2](https://security.togoder.click/npm/viem@2.41.2): medium, 2026-10-04T16:54:47.000Z
- [2.23.2](https://security.togoder.click/npm/viem@2.23.2): medium, 2026-10-04T16:54:42.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
