Vulnerabilities/

MetaMask SDK indirectly exposed via malicious [email protected] dependency

Severity:
Medium

Description

This advisory only applies to developers who use MetaMask SDK in the browser and who, on Sept 8th 2025 between 13:00–15:30 UTC, performed one of the following actions and then deployed their application:

Recommendation

Update the @metamask/sdk-communication-layer package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@metamask/sdk-communication-layer
Anything's wrong? Let us know Last updated on September 15, 2025

This issue is available in SmartScanner Professional

See Pricing