Summary
Togoder Security scanned the npm package @reown/appkit-utils@1.7.8 on Oct 4, 2026. An AI review of 17 source files produced 1 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 7
third-party RPC proxy with projectId
NPS-D14F4D8904DB
The code constructs and uses RPC endpoints hosted at 'rpc.walletconnect.org', injecting the caller's projectId into query parameters. All JSON-RPC traffic for supported chains is routed through this third-party proxy, which can observe request contents, correlate IPs, and potentially log or alter responses. While this appears to be the library's intended design (WalletConnect/Reown), it constitutes centralized third-party data flow that could be a privacy and integrity concern.
network metadata query parameters
NPS-6FE63AF63DBC
getBlockchainApiRpcUrl builds URLs with 'chainId' and 'projectId' search params, revealing application/project identifiers to the RPC provider on every request. This is not malicious per se but constitutes information disclosure to an external service.
custom RPC URL override precedence
NPS-C1B92DC8CB5F
extendCaipNetwork/getViemTransport place customRpcUrls (user-supplied) ahead of reown RPC and default RPC URLs in fallback order. This is expected behavior, but combined with the third-party proxy it means user traffic can be silently sent to arbitrary RPC endpoints configured elsewhere in the app, increasing risk if those configurations are attacker-controlled.
Project ID leakage in URL
NPS-006FFE43F8AA
The detectRpcUrl function appends the provided projectId as a query parameter to an RPC URL. This could leak a project identifier to an external RPC endpoint, but it only happens when the default RPC URL already points to the blockchain API hostname, so it is expected behavior rather than malicious exfiltration.
Unsafe hex parsing
NPS-B65E685CB3E7
hexStringToNumber uses parseInt on an externally supplied string without validation. This is a robustness concern (could yield NaN), not a direct security vulnerability, as no dynamic code execution or data exfiltration occurs.
Potential undefined access
NPS-8513054B0220
getAddress calls toBase58() without verifying that publicKey exists. This is a correctness/DoS concern rather than a malicious pattern.
suspicious_import
NPS-AE04543F2729
Imports UniversalProvider from @walletconnect/universal-provider, a cryptocurrency wallet interaction library. While not inherently malicious, wallet-related libraries in a types utility file can be a vector for wallet drainer or key exfiltration patterns if the package is compromised or if this is a trojanized dependency. No actual malicious behavior is present in this file.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/esm/src/CaipNetworkUtil.js | medium | No overtly malicious code (no exfiltration of credentials, no shell/eval/backdoor), but the module routes all supported-chain RPC traffic through a third-party proxy at rpc.walletconnect.org with embedded projectId and permits user-supplied RPC overrides, which warrants caution. |
| dist/esm/src/solana/SolanaHelpersUtils.js | medium | No malicious patterns detected; only minor robustness and potential project identifier exposure concerns in RPC URL construction and hex parsing. |
| dist/esm/src/solana/SolanaTypesUtil.js | medium | The file only imports a walletconnect provider in a Solana types utility; no malicious patterns are present, but the wallet-related import warrants low-level scrutiny. |
| dist/esm/exports/ethers.js | safe | This file is a simple re-export shim that adds no logic; no malicious patterns are present in the provided code. |
| dist/esm/exports/index.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/exports/solana.js | safe | The file is a simple re-export barrel module with no executable logic or suspicious patterns. |
| dist/esm/src/ConstantsUtil.js | safe | No malicious patterns detected; the file only contains static string constants for wallet connector names and EIP standards. |
| dist/esm/src/ErrorUtil.js | safe | No malicious patterns detected; the file only defines error constants and a top-level AbortController without any network, filesystem, process, or dynamic code execution activity. |
| dist/esm/src/HelpersUtil.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/esm/src/LoggerUtil.js | safe | No malicious patterns detected; the code is a benign logger wrapper for WalletConnect that delegates error handling to a caller-provided callback. |
| dist/esm/src/PresetsUtil.js | safe | This file contains only static mapping data for wallet connector IDs, network image identifiers, and chain IDs, with no executable code, network calls, file system access, or other malicious patterns. |
| dist/esm/src/ProviderUtil.js | safe | No malicious patterns detected |
| dist/esm/src/TypeUtil.js | safe | No malicious patterns detected; the file only defines a static enum and contains no executable or suspicious behavior. |
| dist/esm/src/ethers/EthersHelpersUtil.js | safe | No malicious patterns detected; the code provides standard Ethereum wallet interaction utilities using provider.request methods without exfiltration, obfuscation, or harmful behavior. |
| dist/esm/src/ethers/EthersStoreUtil.js | safe | No malicious patterns detected |
| dist/esm/src/ethers/EthersTypesUtil.js | safe | No malicious patterns detected |
| dist/esm/src/solana/SolanaConstantsUtil.js | safe | No malicious patterns detected; the file contains only static Solana blockchain constants and configuration. |
Scanned versions of @reown/appkit-utils
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 1.7.8 | Needs review | 17 | Oct 4, 2026 |
Frequently asked questions
Is @reown/appkit-utils safe to use?
No confirmed malware was found in @reown/appkit-utils@1.7.8, but the review flagged 1 medium, 6 low severity findings for risky patterns worth checking before you rely on it.
Does @reown/appkit-utils contain malware?
No malware was identified in @reown/appkit-utils@1.7.8 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @reown/appkit-utils checked?
Togoder Security downloaded the published npm package and had an AI model read its 17 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @reown/appkit-utils together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @reown/appkit-utils@1.7.8, cost nothing.