Description
This advisory only applies to developers who use MetaMask SDK in the browser and who, on Sept 8th 2025 between 13:00–15:30 UTC, performed one of the following actions and then deployed their application:
- Installed MetaMask SDK into a project with a lockfile for the first time
- Installed MetaMask SDK in a project without a lockfile
- Updated a lo
Recommendation
Update the @metamask/sdk-react package to the latest compatible version. Followings are version details:
- Affected version(s): >= 0.16.0, <= 0.33.0
- Patched version(s): 0.33.1
References
Could your website be exposed too?
SmartScanner can check your website for MetaMask SDK indirectly exposed via malicious [email protected] dependency - @metamask/sdk-react and gives you actionable findings to investigate.
Start a free scanRelated Issues
- MetaMask SDK indirectly exposed via malicious [email protected] dependency - Vulnerability
- MetaMask SDK indirectly exposed via malicious [email protected] dependency - @metamask/sdk - Vulnerability
- Paperclip: Stored XSS via javascript: URLs in MarkdownBody — urlTransform override disables react-markdown sanitization - Vulnerability
- Malicious Package in react-datepicker-plus - Vulnerability


