MetaMask
Based on the RiskyPlugins AI security review of the observed evidence.
Analysis record
- Analysed
- 1 weeks ago
- Version
- v13.49.0
- Artifact
- SHA256 4E4…DBA
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
Limited evidenceConsensys
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Edge does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
13 evidence rows available.
Finding Categories
AI Security Report
AI Security Review
Evidence context: threat category typosquatting; evidence quality strong.
This extension claims to be MetaMask but exhibits multiple indicators of a typosquatting attack designed to steal cryptocurrency credentials. The version field shows "unknown" rather than a semantic version number, which is inconsistent with legitimate browser extensions. The user_count is 0, whereas the genuine MetaMask extension has over 10 million users across browser stores. These metadata anomalies alone strongly indicate this is not the authentic MetaMask.
Most critically, 1145 malware signatures were detected across the codebase. This finding type (malware-signature) is distinct from code-smell patterns and represents actual malware indicators matched by YARA rules. A count of 1145 malware signatures cannot be explained by legitimate bundled dependencies or false positives from security libraries. For comparison, confirmed false-positive extensions typically show code-smell findings, not malware signatures.
The obfuscation findings further support malicious intent. The file scripts/runtime-lavamoat.js triggers OBFUSCATION-function_indirect, and scripts/ppom_bg.wasm triggers OBFUSCATION-suspicious_wasm. While LavaMoat is a legitimate security framework, its presence combined with 1145 malware signatures and typosquatting indicators suggests the extension uses obfuscation to hide malicious functionality. The additional suspicious_wasm finding in images/riv_animations/rive.wasm is similarly concerning when viewed in this context.
Counterargument: One might argue these malware signatures are false positives from bundled npm packages or legitimate security libraries triggering YARA rules. However, this explanation fails on multiple grounds. First, 1145 malware signatures is an extraordinarily high count that exceeds typical false-positive volumes from bundled dependencies. Second, the typosquatting indicators (unknown version, zero users, claiming to be MetaMask) are independent evidence of malicious intent. Third, malware-signature findings are classified separately from code-smell findings in CVEQ, and code-smell findings are explicitly documented as noise sources while malware signatures represent actual malicious patterns. The combination of typosquatting metadata anomalies plus 1145 malware signatures constitutes strong evidence of a credential-stealing extension impersonating MetaMask to harvest cryptocurrency wallet credentials.
Key Reasons
- 1145 malware signatures detected (malware-signature finding type, not code-smell)
- Version field shows "unknown" instead of semantic version
- User count is 0 despite claiming to be MetaMask (legitimate has 10M+ users)
- Obfuscation patterns in runtime-lavamoat.js and ppom_bg.wasm
- Typosquatting indicators: claims MetaMask identity without verification
False Positive Considerations
- None - malware signatures are actual indicators, not code-smell
Reviewed 2026-04-27; recommended action: takedown request; model confidence 85%.
Edge version history
Risk trend by version
3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace