Skip to content

chore: versioning alignment - #194

Merged
SlavaSereb merged 57 commits into
mainfrom
docs/remove-outdated-github-release-links
Sep 24, 2026
Merged

SlavaSereb merged 57 commits into
mainfrom
docs/remove-outdated-github-release-links

Conversation

@tomer-shoham

Copy link
Copy Markdown
Collaborator

No description provided.

a0ngo and others added 30 commits June 3, 2025 13:06
feat: 💚 added gitlab ci

See merge request fireblocks/key-backup/recovery-utility!1
test: new-version label test

See merge request fireblocks/key-backup/recovery-utility!2
Merge Hidden branch into Main

See merge request fireblocks/key-backup/recovery-utility!12
Feat/btc api key

See merge request fireblocks/key-backup/recovery-utility!14
Fix: missing evm keys

See merge request fireblocks/key-backup/recovery-utility!13
SlavaSereb and others added 11 commits June 1, 2026 08:38
Feat/mobile key share v2

See merge request fireblocks/key-backup/recovery-utility!21
Fix/tron address y coordinate padding

See merge request fireblocks/key-backup/recovery-utility!23
Fix two bugs preventing NCW recovery from working:
- RecoveryForm checked for 'ncwMaster' but recoverKeys returns 'ncwWalletMaster'
- useBaseWorkspace placed ncwMaster at the workspace top-level instead of on
  extendedKeys where all consumers (Layout, /ncw page, wallet derivation) read it

Add EdDSA (MPC_EDDSA_ED25519) support to NCW wallet share derivation:
- BIP-32 hardened child derivation always uses secp256k1 (matches cloud cosigner)
- SHA-512 expansion reduced directly mod the target curve order (ed25519.CURVE.n)
- Export both ECDSA and EdDSA shares per wallet in the derive output JSON
- Fix leading-zero padding in hex-encoded wallet shares
# Conflicts:
#   apps/recovery-relay/package.json
#   apps/recovery-utility/package.json
feat: fix NCW recovery and add EdDSA wallet share derivation

See merge request fireblocks/key-backup/recovery-utility!24
@tomer-shoham
tomer-shoham requested review from SlavaSereb and a lite review from Copilot September 23, 2026 08:49
@tomer-shoham tomer-shoham changed the title Docs/remove outdated GitHub release links chore: versioning alignment Sep 23, 2026
ncwWalletMasters: masterKeys,
keysetThMapping,
maxKeysetId,
} = parseMetadataFile(metadataFile.getData().toString());

@semgrep-code-fireblocks semgrep-code-fireblocks Bot Sep 23, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Risk: Affected versions of adm-zip are vulnerable to Memory Allocation with Excessive Size Value. adm-zip allocates a ZIP entry's output buffer with Buffer.alloc() sized from the uncompressed size declared in the archive's central directory, before validating that value against the data actually present. Reading, testing, or extracting a crafted archive via readFile(), readFileAsync(), readAsText(), readAsTextAsync(), extractEntryTo(), extractAllTo(), extractAllToAsync(), test(), or a per-entry getData()/getDataAsync() therefore commits the attacker-declared allocation before any CRC or size check runs. A 105-byte ZIP with a single stored entry declaring a size of 1,774,399,200 commits roughly 1.8 GB of resident memory — about 16 million times the input size — which can exhaust process memory and deny service, and will OOM-kill the process outright on memory-constrained hosts such as containers or serverless runtimes.

Fix: Upgrade this library to at least version 0.6.1 at recovery/yarn.lock:5131.

Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-83170, GHSA-7q85-xj36-vmfc

🌟 Fixed in commit 6a09be8 🌟

for (const file of zipFiles) {
if (file.entryName.startsWith('MOBILE')) {
const { keyId, playerId, value } = recoverMobileKeyShare(signingKeys, file.getData().toString(), mobilePass);
const { keyId, playerId, value } = recoverMobileKeyShare(signingKeys, file.getData().toString(), mobilePass, onLog);

@semgrep-code-fireblocks semgrep-code-fireblocks Bot Sep 23, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Risk: Affected versions of adm-zip are vulnerable to Memory Allocation with Excessive Size Value. adm-zip allocates a ZIP entry's output buffer with Buffer.alloc() sized from the uncompressed size declared in the archive's central directory, before validating that value against the data actually present. Reading, testing, or extracting a crafted archive via readFile(), readFileAsync(), readAsText(), readAsTextAsync(), extractEntryTo(), extractAllTo(), extractAllToAsync(), test(), or a per-entry getData()/getDataAsync() therefore commits the attacker-declared allocation before any CRC or size check runs. A 105-byte ZIP with a single stored entry declaring a size of 1,774,399,200 commits roughly 1.8 GB of resident memory — about 16 million times the input size — which can exhaust process memory and deny service, and will OOM-kill the process outright on memory-constrained hosts such as containers or serverless runtimes.

Fix: Upgrade this library to at least version 0.6.1 at recovery/yarn.lock:5131.

Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-83170, GHSA-7q85-xj36-vmfc

🌟 Fixed in commit 6a09be8 🌟

ncwWalletMasters: masterKeys,
keysetThMapping,
maxKeysetId,
} = parseMetadataFile(metadataFile.getData().toString());

@semgrep-code-fireblocks semgrep-code-fireblocks Bot Sep 23, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Risk: Affected versions of adm-zip are vulnerable to Memory Allocation with Excessive Size Value / Uncontrolled Resource Consumption. adm-zip allocates a decompression buffer sized directly from the untrusted uncompressed-size field in a ZIP entry header without validating it against the actual compressed data. When reading, testing, or extracting a crafted archive via readFile(), readAsText(), readAsTextAsync(), extractEntryTo(), extractAllTo(), extractAllToAsync(), test(), or a per-entry getData(), a tiny (~120-byte) ZIP declaring a multi-gigabyte uncompressed size forces an enormous Buffer.alloc, exhausting process memory and causing a denial of service.

Fix: Upgrade this library to at least version 0.6.0 at recovery/yarn.lock:5131.

Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42960, GHSA-xcpc-8h2w-3j85, CVE-2026-39244

🧼 Fixed in commit 6a09be8 🧼

for (const file of zipFiles) {
if (file.entryName.startsWith('MOBILE')) {
const { keyId, playerId, value } = recoverMobileKeyShare(signingKeys, file.getData().toString(), mobilePass);
const { keyId, playerId, value } = recoverMobileKeyShare(signingKeys, file.getData().toString(), mobilePass, onLog);

@semgrep-code-fireblocks semgrep-code-fireblocks Bot Sep 23, 2026 •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Risk: Affected versions of adm-zip are vulnerable to Memory Allocation with Excessive Size Value / Uncontrolled Resource Consumption. adm-zip allocates a decompression buffer sized directly from the untrusted uncompressed-size field in a ZIP entry header without validating it against the actual compressed data. When reading, testing, or extracting a crafted archive via readFile(), readAsText(), readAsTextAsync(), extractEntryTo(), extractAllTo(), extractAllToAsync(), test(), or a per-entry getData(), a tiny (~120-byte) ZIP declaring a multi-gigabyte uncompressed size forces an enormous Buffer.alloc, exhausting process memory and causing a denial of service.

Fix: Upgrade this library to at least version 0.6.0 at recovery/yarn.lock:5131.

Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42960, GHSA-xcpc-8h2w-3j85, CVE-2026-39244

🍰 Fixed in commit 6a09be8 🍰

@semgrep-code-fireblocks

Copy link
Copy Markdown

Semgrep found 1 ssc-ac1b2289-93d7-4f3c-99f6-078913291f1b finding:

  • apps/recovery-utility/renderer/pages/setup.tsx

Risk: Affected versions of node-forge are vulnerable to Interpretation Conflict. An attacker can craft malicious ASN.1 data that desynchronizes node-forge's asn1.validate on optional field boundaries, causing subsequent mandatory fields—such as digital signatures or MACs in X.509, PKCS#7, PKCS#12 and related protocols—to be skipped or verified against attacker-controlled bytes, effectively bypassing critical integrity checks.

Fix: Upgrade this library to at least version 1.3.2 at recovery/yarn.lock:11168.

Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-199630, GHSA-5gfm-wpxj-wjgq

Semgrep found 1 ssc-844d5c40-8a97-91b4-2c79-cde2fa831b82 finding:

  • apps/recovery-utility/renderer/pages/setup.tsx

Risk: Affected versions of node-forge are vulnerable to Uncontrolled Recursion. Unbounded recursion in node-forge's ASN.1 DER parser (asn1.fromDer) allows remote attackers to supply specially crafted, deeply nested TLV structures that exhaust the JavaScript call stack and crash the process, resulting in a Denial of Service when parsing untrusted DER inputs.

Fix: Upgrade this library to at least version 1.3.2 at recovery/yarn.lock:11168.

Reference(s): https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-199767, GHSA-554w-wpv2-vw27

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unresolved critical CI, security, build, and wallet/signing issues block approval.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 24 High severity · 9 Medium severity

Open (33)

And 13 more that still need to be addressed.

What changed in this PR

This PR removes outdated GitHub release links while adding multi-keyset recovery, raw signing, expanded wallet/token support, API-key settings, logging, and CI/build automation. Unresolved correctness, security, compatibility, and pipeline issues remain.

Changes:

  • Adds algorithm-aware recovery and account-specific key derivation.
  • Adds raw-signing flows and broader blockchain asset support.
  • Updates logging, RPC/API-key handling, builds, and CI mirroring.
File Reviewed change
test.txt Adds sync marker.
scripts/​build-cross-platform.sh Adds cross-platform build script.
README.md Removes release link.
packages/​wallet-derivation/​wallets/​NCWallet.ts Adds EdDSA NCW derivation.
packages/​wallet-derivation/​wallets/​EdDSAWallet.ts Updates byte handling.
packages/​wallet-derivation/​wallets/​ECDSAWallet.ts Adds message signing.
packages/​wallet-derivation/​wallets/​chains/​XRP.ts Updates XRP reserve configuration.
packages/​wallet-derivation/​wallets/​chains/​Tron.ts Pads public-key coordinates.
packages/​wallet-derivation/​wallets/​chains/​EVM.ts Supports configurable chain IDs.
packages/​wallet-derivation/​wallets/​BaseWallet.ts Selects account keysets.
packages/​wallet-derivation/​types.ts Updates key and share types.
packages/​shared/​schemas/​settingsInput.ts Adds API-key settings.
packages/​shared/​schemas/​relayUrl.ts Adds raw-signing schemas.
packages/​shared/​schemas/​recoverKeysInput.ts Adds JSON passphrases.
packages/​shared/​schemas/​recoverAccountInput.ts Adds keyset mapping inputs.
packages/​shared/​schemas/​extendedKeys.ts Adds keyset schemas.
packages/​shared/​reducers/​rawSignReducer.ts Adds raw-signing state.
packages/​shared/​pages/​keys.tsx Removes shared keys page.
packages/​shared/​pages/​csv.tsx Updates key types.
packages/​shared/​pages/​accounts/​vault/​index.tsx Adds keyset props.
packages/​shared/​lib/​validateAddress.ts Updates validator patching.
packages/​shared/​lib/​relayUrl.ts Routes raw-signing messages.
packages/​shared/​lib/​getLogger.ts Adds daily log folders.
packages/​shared/​index.ts Updates exports.
packages/​shared/​hooks/​useRawSignMessage.ts Implements signing flow.
packages/​shared/​hooks/​useRawSign.ts Adds raw-sign state hook.
packages/​shared/​hooks/​useBaseWorkspace/​types.ts Adds app-specific key types.
packages/​shared/​hooks/​useBaseWorkspace/​reduceDerivations.ts Selects mapped keysets.
packages/​shared/​hooks/​useBaseWorkspace/​index.ts Adds keyset workspace handling.
packages/​shared/​components/​TextField/​index.tsx Fixes controlled values.
packages/​shared/​components/​RelayRxTx/​index.tsx Enables QR URL input.
packages/​shared/​components/​RawSigningForm/​Signature/​index.tsx Displays signatures.
packages/​shared/​components/​RawSigningForm/​index.tsx Adds signing form.
packages/​shared/​components/​Modals/​RecoverAccountModal/​index.tsx Adds keyset mapping UI.
packages/​shared/​components/​Modals/​AddressesModal/​index.tsx Updates address keys.
packages/​shared/​components/​index.ts Exports new components.
packages/​shared/​components/​DerivationPathInput/​index.tsx Adds path input.
packages/​extended-key-recovery/​src/​types.ts Adds keyset metadata types.
packages/​extended-key-recovery/​src/​reconstructKeys.ts Reconstructs keyed results.
packages/​extended-key-recovery/​src/​ncw.ts Updates buffer casts.
packages/​extended-key-recovery/​src/​mobileKey.ts Adds V2 decryption.
packages/​extended-key-recovery/​src/​metadata.ts Parses keyset metadata.
packages/​extended-key-recovery/​src/​decrypt.ts Implements V2 decryption.
packages/​extended-key-recovery/​src/​algorithms.ts Adds algorithm helpers.
packages/​e2e-tests/​utils.ts Updates ZIP writing.
packages/​asset-config/​util.ts Recognizes account explorers.
packages/​asset-config/​types.ts Adds account explorer types.
packages/​asset-config/​index.ts Exports SPL assets.
packages/​asset-config/​data/​globalAssets.ts Adds assets.
packages/​asset-config/​config/​patches.ts Adds explorer and RPC patches.
packages/​asset-config/​assets.ts Registers SPL and token assets.
package.json Adds all-platform build command.
docs/​CODEOWNERS Updates owners.
apps/​recovery-utility/​renderer/​pages/​setup.tsx Updates RSA encryption.
apps/​recovery-utility/​renderer/​pages/​settings.tsx Adjusts settings layout.
apps/​recovery-utility/​renderer/​pages/​raw-signing.tsx Adds utility raw signing.
apps/​recovery-utility/​renderer/​pages/​ncw.tsx Derives both NCW algorithms.
apps/​recovery-utility/​renderer/​pages/​keys.tsx Uses local keys page.
apps/​recovery-utility/​renderer/​pages/​index.tsx Adds keyset lookup.
apps/​recovery-utility/​renderer/​pages/​csv.tsx Uses account keysets.
apps/​recovery-utility/​renderer/​pages/​accounts/​vault/​index.tsx Adds keyset mapping data.
apps/​recovery-utility/​renderer/​pages/​accounts/​vault/​[accountId]/​index.tsx Uses account keys.
apps/​recovery-utility/​renderer/​lib/​wallets/​XLM/​index.ts Handles account creation.
apps/​recovery-utility/​renderer/​lib/​wallets/​SPL/​index.ts Adds SPL signing.
apps/​recovery-utility/​renderer/​lib/​wallets/​index.ts Registers new wallets.
apps/​recovery-utility/​renderer/​lib/​wallets/​FLR/​index.ts Adds Flare wallet.
apps/​recovery-utility/​renderer/​lib/​wallets/​EVM/​index.ts Supports chain IDs.
apps/​recovery-utility/​renderer/​lib/​wallets/​ERC20/​index.ts Caps priority fees.
apps/​recovery-utility/​renderer/​lib/​recoverExtendedKeys.ts Adds recovery logging.
apps/​recovery-utility/​renderer/​context/​Workspace.tsx Uses account keysets.
apps/​recovery-utility/​renderer/​components/​RecoveryForm/​index.tsx Adds passphrase JSON handling.
apps/​recovery-utility/​renderer/​components/​Modals/​WithdrawModal/​SignTransaction/​index.tsx Signs with account keys.
apps/​recovery-utility/​renderer/​components/​Modals/​WithdrawModal/​index.tsx Uses account-specific keys.
apps/​recovery-utility/​renderer/​components/​Modals/​RawSigningModal/​index.tsx Adds QR signing.
apps/​recovery-utility/​renderer/​components/​Layout/​index.tsx Adds raw-sign navigation.
apps/​recovery-utility/​README.md Removes release links.
apps/​recovery-utility/​package.json Adds build target.
apps/​recovery-utility/​main/​ipc/​getLogs.ts Changes log paths.
apps/​recovery-utility/​main/​background.ts Updates log resets.
apps/​recovery-utility/​electron-builder.json Adds architecture targets.
apps/​recovery-relay/​pages/​settings.tsx Adds API-key editing.
apps/​recovery-relay/​pages/​raw-signing.tsx Adds relay raw signing.
apps/​recovery-relay/​package.json Adds SPL dependency.
apps/​recovery-relay/​lib/​wallets/​XRP/​index.ts Calculates dynamic reserves.
apps/​recovery-relay/​lib/​wallets/​XLM/​index.ts Detects new destinations.
apps/​recovery-relay/​lib/​wallets/​SPL/​unsupported_solana_assets.ts Adds unsupported asset metadata.
apps/​recovery-relay/​lib/​wallets/​SPL/​index.ts Adds SPL relay support.
apps/​recovery-relay/​lib/​wallets/​index.ts Registers relay wallets.
apps/​recovery-relay/​lib/​wallets/​EVM/​FLR.ts Adds Flare relay support.
apps/​recovery-relay/​lib/​wallets/​ERC20/​index.ts Validates token decimals.
apps/​recovery-relay/​lib/​wallets/​ConnectedWallet.ts Extends broadcast signature.
apps/​recovery-relay/​lib/​wallets/​BTCBased/​ZEC.ts Adds API-key support.
apps/​recovery-relay/​lib/​wallets/​BTCBased/​LTC.ts Adds API-key support.
apps/​recovery-relay/​lib/​wallets/​BTCBased/​DOGE.ts Adds API-key support.
apps/​recovery-relay/​lib/​wallets/​BTCBased/​DASH.ts Adds API-key support.
apps/​recovery-relay/​lib/​wallets/​BTCBased/​BTCRelayWalletUtils.ts Adds API-key requests.
apps/​recovery-relay/​lib/​wallets/​BTCBased/​BTCRelayWallet.ts Propagates API keys.
apps/​recovery-relay/​lib/​wallets/​BTCBased/​BTC.ts Updates BTC relay handling.
apps/​recovery-relay/​lib/​defaultRPCs.ts Adds RPC and API-key metadata.
apps/​recovery-relay/​context/​Workspace.tsx Integrates keyset workspace.
apps/​recovery-relay/​context/​Settings.tsx Persists settings.
apps/​recovery-relay/​components/​WithdrawModal/​index.tsx Uses API-key RPC data.
apps/​recovery-relay/​components/​WithdrawModal/​CreateTransaction/​index.tsx Adds API-key setup.
apps/​recovery-relay/​components/​RawSigningModal/​index.tsx Displays signed QR results.
apps/​recovery-relay/​components/​Layout/​index.tsx Adds raw-sign navigation.
.gitlab-ci.yml Adds version, build, and mirror pipeline.
.gitignore Ignores Claude files.
.changeset/​wild-timers-think.md Documents keyset derivation.
.changeset/​violet-ducks-joke.md Documents multi-keyset recovery.
.changeset/​tender-turtles-destroy.md Documents keys-page relocation.
.changeset/​orange-bobcats-taste.md Documents test updates.
.changeset/​old-drinks-camp.md Documents workspace typing.
.changeset/​giant-cups-explode.md Documents keyset mapping.
.changeset/​eleven-cheetahs-rest.md Documents account key selection.
.changeset/​dry-paws-thank.md Documents keyset display.
.changeset/​blue-gorillas-rush.md Documents key type updates.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .gitlab-ci.yml Outdated
description: "Checkpoint from which to start mirroring to github from main branch"
value: ""
EXECUTABLES_DIR: "apps/recovery-utility/dist"
GITHUB_REPO: "https://oauth2:${GITHUB_TOKEN}@github.com/fireblocks/mirror-test.git"
Comment thread .gitlab-ci.yml Outdated

build_linux:
stage: build
needs: [version_packages]
Comment thread .gitlab-ci.yml Outdated
sync_to_github:
stage: sync
image: alpine:latest
needs: [build_linux]
Comment thread .gitlab-ci.yml Outdated
Comment on lines +144 to +146
if [[ "$TAGS" != *"${EXCLUDE_TAG}"* ]]; then
echo $COMMIT >> selected_commits.txt;
fi;
Comment thread .gitlab-ci.yml Outdated

- |
while read COMMIT; do
git cherry-pick $COMMIT || echo "Cherry-pick failed or already applied: $COMMIT";
Comment on lines +73 to +78
mobilePassphrase:
formData.passphraseJson !== null
? formData.passphraseJson.passphrase
: formData.autoGeneratedPass
? formData.agpRsaPassphrase
: formData.passphrase,
Comment on lines +108 to +110
if (!xpub || !fpub) {
return undefined;
}

if (ecdsa) {
(extendedKeys as Record<number, RecoveredKey>)[Number(entry[0])].ecdsaMinAccount =
!newAccountId || newAccountId < 0 ? accounts.size : newAccountId;
Comment on lines +82 to +86
selectedWallet.path = {
...selectedWallet.path,
changeIndex: inputChangeIndex,
addressIndex: inputAdressIndex,
};
public isValidAddress(address: string, networkProtocol: string | undefined, assetId: string): boolean {
try {
this.patchValidator();
// this.patchValidator();
@socket-security

socket-security Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​next@​13.5.6 ⏵ 13.5.1144 -18259499 +4970
Updatednpm/​@​types/​bech32@​1.1.4 ⏵ 1.1.865 -310039 +450 -28100
Updatednpm/​eslint-config-turbo@​1.11.3 ⏵ 1.13.4100100629870
Updatednpm/​eslint-config-next@​13.5.6 ⏵ 13.5.11991006598100
Updatednpm/​turbo@​1.11.3 ⏵ 1.13.49998669770
Updatednpm/​ethers@​6.10.0 ⏵ 6.17.068 -310010081100
Updatednpm/​@​types/​uuid@​8.3.4 ⏵ 9.0.81001006980100
Updatednpm/​node-forge@​1.3.1 ⏵ 1.4.0100 +1100 +611008570
Updatednpm/​eslint-config-prettier@​8.10.0 ⏵ 8.10.21001007283100
Updatednpm/​@​types/​multicoin-address-validator@​0.5.2 ⏵ 0.5.399 +110072 +179100
Updatednpm/​@​types/​python-struct@​1.0.4 ⏵ 1.0.573 +310072 +385 +9100
Updatednpm/​@​babel/​preset-typescript@​7.23.2 ⏵ 7.29.7100 +11007289 -6100
Updatednpm/​nextron@​8.12.0 ⏵ 8.24.073 -110010082 -8100
Updatednpm/​@​types/​papaparse@​5.3.14 ⏵ 5.5.2100 +11007482100
Updatednpm/​@​babel/​plugin-transform-runtime@​7.23.2 ⏵ 7.29.7991007494100
Updatednpm/​@​tanstack/​react-query-devtools@​4.36.1 ⏵ 4.44.0991007597100
Updatednpm/​@​types/​adm-zip@​0.5.5 ⏵ 0.5.8100 +110075 +181100
Updatednpm/​@​types/​node-forge@​1.3.11 ⏵ 1.3.14100 +110076 +180100
Updatednpm/​@​types/​jest@​29.5.11 ⏵ 29.5.141001007680100
Updatednpm/​@​babel/​preset-env@​7.23.2 ⏵ 7.29.797 +110076 +196100
Updatednpm/​@​types/​inquirer@​9.0.7 ⏵ 9.0.101001007786100
Updatednpm/​adm-zip@​0.5.10 ⏵ 0.5.18100 +137898 +787 +6100
Updatednpm/​@​hashgraph/​sdk@​2.40.0 ⏵ 2.81.078 +310091 +292 -2100
Updatednpm/​bitcore-lib-doge@​10.0.21 ⏵ 10.10.583 +110078 +288 -2100
Updatednpm/​@​mui/​styles@​5.15.6 ⏵ 5.18.095 +11007887 +37100
Updatednpm/​@​babel/​runtime-corejs3@​7.23.2 ⏵ 7.29.7100 +1100 +27996 +1100
Updatednpm/​@​types/​react@​18.2.48 ⏵ 18.3.31100 +11007993 -2100
Updatednpm/​@​types/​jsrsasign@​10.5.12 ⏵ 10.5.15100 +11007980100
Updatednpm/​@​babel/​runtime@​7.27.6 ⏵ 7.29.71001007993100
Updatednpm/​playwright-core@​1.41.1 ⏵ 1.63.0100 +3510079 +399 +180 -19
Updatednpm/​electron-builder-notarize@​1.5.1 ⏵ 1.5.286 -610095 +180 +4100
Updatednpm/​qrcode.react@​3.1.0 ⏵ 3.2.0100 +110099 +180100
See 49 more rows in the dashboard

View full report

@socket-security

socket-security Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm @polkadot/keyring is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: apps/recovery-utility/package.json → npm/@substrate/txwrapper-polkadot@6.0.1 → npm/@polkadot/api@10.9.1 → npm/@polkadot/types@10.9.1 → npm/@polkadot/keyring@12.6.2

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@polkadot/keyring@12.6.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Protestware or unwanted behavior: npm es5-ext

Note: The script attempts to run a local post-install script, which could potentially contain malicious code. The error handling suggests that it is designed to fail silently, which is a common tactic in malicious scripts.

From: apps/recovery-utility/package.json → npm/@substrate/txwrapper-polkadot@6.0.1 → npm/es5-ext@0.10.64

ℹ Read more on: This package | This alert | What is protestware?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Consider that consuming this package may come along with functionality unrelated to its primary purpose.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/es5-ext@0.10.64. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm eslint-plugin-react-hooks is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: apps/recovery-relay/package.json → npm/eslint-config-next@13.5.11 → npm/eslint-plugin-react-hooks@5.0.0-canary-7118f5dd7-20230705

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/eslint-plugin-react-hooks@5.0.0-canary-7118f5dd7-20230705. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm eslint-plugin-react is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: packages/eslint-config-custom/package.json → npm/eslint-plugin-react@7.37.5

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/eslint-plugin-react@7.37.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm fast-xml-parser is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: apps/recovery-utility/package.json → npm/@hashgraph/sdk@2.81.0 → npm/@tanstack/react-query@4.44.0 → npm/fast-xml-parser@4.5.7

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/fast-xml-parser@4.5.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm protobufjs is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: apps/recovery-utility/package.json → npm/cosmjs-types@0.8.0 → npm/@cosmjs/stargate@0.32.4 → npm/@terra-money/terra.js@3.1.10 → npm/protobufjs@6.11.6

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/protobufjs@6.11.6. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm ts-api-utils is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: packages/eslint-config-custom/package.json → npm/eslint-config-airbnb-typescript@17.1.0 → npm/eslint-config-next@13.5.11 → npm/ts-api-utils@1.4.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/ts-api-utils@1.4.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm validator is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: apps/recovery-utility/package.json → npm/tronweb@5.3.5 → npm/validator@13.15.26

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/validator@13.15.26. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm yargs is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: packages/extended-key-recovery/package.json → npm/@hashgraph/sdk@2.81.0 → npm/@tanstack/react-query@4.44.0 → npm/concurrently@8.2.2 → npm/@commitlint/cli@17.8.1 → npm/jest@29.7.0 → npm/electron-builder@23.6.0 → npm/yargs@17.7.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/yargs@17.7.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@SlavaSereb
SlavaSereb merged commit a2a9527 into main Sep 24, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants