@metamask/sdk-communication-layer

npm Compromised

1

report

Attack type: Malicious version

Reports

Malicious version Versions: >= 0.16.0, <= 0.33.0 212d ago by isitcompromised.com

MetaMask SDK indirectly exposed via malicious debug@4.4.2 dependency ### Who is affected? This advisory only applies to developers who use MetaMask SDK in the browser and who, on Sept 8th 2025 between 13:00–15:30 UTC, performed one of the following actions and then deployed their application: - Installed MetaMask SDK into a project with a lockfile for the first time - Installed MetaMask SDK in a project without a lockfile - Updated a lockfile to pull in `debug@4.4.2` (e.g., via `npm update` or `yarn upgrade`) ### What happened? On Sept 8th, 2025 (13:00–15:30 UTC

View evidence

Have more info?

Submit additional evidence or a new report for this package.

Submit a report