# @reown/appkit-utils@1.7.8 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:16:02.000Z
- Files reviewed: 17
- Findings: 1 medium, 6 low severity findings
- Report: https://security.togoder.click/npm/@reown/appkit-utils
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @reown/appkit-utils@1.7.8 on Oct 4, 2026. An AI review of 17 source files produced 1 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] third-party RPC proxy with projectId

Finding ID: `NPS-D14F4D8904DB`

File: `dist/esm/src/CaipNetworkUtil.js:18`

The code constructs and uses RPC endpoints hosted at 'rpc.walletconnect.org', injecting the caller's projectId into query parameters. All JSON-RPC traffic for supported chains is routed through this third-party proxy, which can observe request contents, correlate IPs, and potentially log or alter responses. While this appears to be the library's intended design (WalletConnect/Reown), it constitutes centralized third-party data flow that could be a privacy and integrity concern.

### [low] network metadata query parameters

Finding ID: `NPS-6FE63AF63DBC`

File: `dist/esm/src/CaipNetworkUtil.js:8`

getBlockchainApiRpcUrl builds URLs with 'chainId' and 'projectId' search params, revealing application/project identifiers to the RPC provider on every request. This is not malicious per se but constitutes information disclosure to an external service.

### [low] custom RPC URL override precedence

Finding ID: `NPS-C1B92DC8CB5F`

File: `dist/esm/src/CaipNetworkUtil.js:130`

extendCaipNetwork/getViemTransport place customRpcUrls (user-supplied) ahead of reown RPC and default RPC URLs in fallback order. This is expected behavior, but combined with the third-party proxy it means user traffic can be silently sent to arbitrary RPC endpoints configured elsewhere in the app, increasing risk if those configurations are attacker-controlled.

### [low] Project ID leakage in URL

Finding ID: `NPS-006FFE43F8AA`

File: `dist/esm/src/solana/SolanaHelpersUtils.js:6`

The detectRpcUrl function appends the provided projectId as a query parameter to an RPC URL. This could leak a project identifier to an external RPC endpoint, but it only happens when the default RPC URL already points to the blockchain API hostname, so it is expected behavior rather than malicious exfiltration.

### [low] Unsafe hex parsing

Finding ID: `NPS-B65E685CB3E7`

File: `dist/esm/src/solana/SolanaHelpersUtils.js:22`

hexStringToNumber uses parseInt on an externally supplied string without validation. This is a robustness concern (could yield NaN), not a direct security vulnerability, as no dynamic code execution or data exfiltration occurs.

### [low] Potential undefined access

Finding ID: `NPS-8513054B0220`

File: `dist/esm/src/solana/SolanaHelpersUtils.js:27`

getAddress calls toBase58() without verifying that publicKey exists. This is a correctness/DoS concern rather than a malicious pattern.

### [low] suspicious_import

Finding ID: `NPS-AE04543F2729`

File: `dist/esm/src/solana/SolanaTypesUtil.js:1`

Imports UniversalProvider from @walletconnect/universal-provider, a cryptocurrency wallet interaction library. While not inherently malicious, wallet-related libraries in a types utility file can be a vector for wallet drainer or key exfiltration patterns if the package is compromised or if this is a trojanized dependency. No actual malicious behavior is present in this file.

## Files reviewed

- `dist/esm/src/CaipNetworkUtil.js` (medium): No overtly malicious code (no exfiltration of credentials, no shell/eval/backdoor), but the module routes all supported-chain RPC traffic through a third-party proxy at rpc.walletconnect.org with embedded projectId and permits user-supplied RPC overrides, which warrants caution.
- `dist/esm/src/solana/SolanaHelpersUtils.js` (medium): No malicious patterns detected; only minor robustness and potential project identifier exposure concerns in RPC URL construction and hex parsing.
- `dist/esm/src/solana/SolanaTypesUtil.js` (medium): The file only imports a walletconnect provider in a Solana types utility; no malicious patterns are present, but the wallet-related import warrants low-level scrutiny.
- `dist/esm/exports/ethers.js` (safe): This file is a simple re-export shim that adds no logic; no malicious patterns are present in the provided code.
- `dist/esm/exports/index.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/exports/solana.js` (safe): The file is a simple re-export barrel module with no executable logic or suspicious patterns.
- `dist/esm/src/ConstantsUtil.js` (safe): No malicious patterns detected; the file only contains static string constants for wallet connector names and EIP standards.
- `dist/esm/src/ErrorUtil.js` (safe): No malicious patterns detected; the file only defines error constants and a top-level AbortController without any network, filesystem, process, or dynamic code execution activity.
- `dist/esm/src/HelpersUtil.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/src/LoggerUtil.js` (safe): No malicious patterns detected; the code is a benign logger wrapper for WalletConnect that delegates error handling to a caller-provided callback.
- `dist/esm/src/PresetsUtil.js` (safe): This file contains only static mapping data for wallet connector IDs, network image identifiers, and chain IDs, with no executable code, network calls, file system access, or other malicious patterns.
- `dist/esm/src/ProviderUtil.js` (safe): No malicious patterns detected
- `dist/esm/src/TypeUtil.js` (safe): No malicious patterns detected; the file only defines a static enum and contains no executable or suspicious behavior.
- `dist/esm/src/ethers/EthersHelpersUtil.js` (safe): No malicious patterns detected; the code provides standard Ethereum wallet interaction utilities using provider.request methods without exfiltration, obfuscation, or harmful behavior.
- `dist/esm/src/ethers/EthersStoreUtil.js` (safe): No malicious patterns detected
- `dist/esm/src/ethers/EthersTypesUtil.js` (safe): No malicious patterns detected
- `dist/esm/src/solana/SolanaConstantsUtil.js` (safe): No malicious patterns detected; the file contains only static Solana blockchain constants and configuration.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
