Togoder security

npm package security report

@reown/appkit-utils@1.7.8 security report

Risky patterns found that deserve a look.

Needs review Version 1.7.8 Files reviewed 17 Size 26.3 KB Scanned

Summary

Togoder Security scanned the npm package @reown/appkit-utils@1.7.8 on Oct 4, 2026. An AI review of 17 source files produced 1 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
6
low

Findings 7

medium

third-party RPC proxy with projectId

NPS-D14F4D8904DB

The code constructs and uses RPC endpoints hosted at 'rpc.walletconnect.org', injecting the caller's projectId into query parameters. All JSON-RPC traffic for supported chains is routed through this third-party proxy, which can observe request contents, correlate IPs, and potentially log or alter responses. While this appears to be the library's intended design (WalletConnect/Reown), it constitutes centralized third-party data flow that could be a privacy and integrity concern.

dist/esm/src/CaipNetworkUtil.js:18
low

network metadata query parameters

NPS-6FE63AF63DBC

getBlockchainApiRpcUrl builds URLs with 'chainId' and 'projectId' search params, revealing application/project identifiers to the RPC provider on every request. This is not malicious per se but constitutes information disclosure to an external service.

dist/esm/src/CaipNetworkUtil.js:8
low

custom RPC URL override precedence

NPS-C1B92DC8CB5F

extendCaipNetwork/getViemTransport place customRpcUrls (user-supplied) ahead of reown RPC and default RPC URLs in fallback order. This is expected behavior, but combined with the third-party proxy it means user traffic can be silently sent to arbitrary RPC endpoints configured elsewhere in the app, increasing risk if those configurations are attacker-controlled.

dist/esm/src/CaipNetworkUtil.js:130
low

Project ID leakage in URL

NPS-006FFE43F8AA

The detectRpcUrl function appends the provided projectId as a query parameter to an RPC URL. This could leak a project identifier to an external RPC endpoint, but it only happens when the default RPC URL already points to the blockchain API hostname, so it is expected behavior rather than malicious exfiltration.

dist/esm/src/solana/SolanaHelpersUtils.js:6
low

Unsafe hex parsing

NPS-B65E685CB3E7

hexStringToNumber uses parseInt on an externally supplied string without validation. This is a robustness concern (could yield NaN), not a direct security vulnerability, as no dynamic code execution or data exfiltration occurs.

dist/esm/src/solana/SolanaHelpersUtils.js:22
low

Potential undefined access

NPS-8513054B0220

getAddress calls toBase58() without verifying that publicKey exists. This is a correctness/DoS concern rather than a malicious pattern.

dist/esm/src/solana/SolanaHelpersUtils.js:27
low

suspicious_import

NPS-AE04543F2729

Imports UniversalProvider from @walletconnect/universal-provider, a cryptocurrency wallet interaction library. While not inherently malicious, wallet-related libraries in a types utility file can be a vector for wallet drainer or key exfiltration patterns if the package is compromised or if this is a trojanized dependency. No actual malicious behavior is present in this file.

dist/esm/src/solana/SolanaTypesUtil.js:1

Files reviewed

FileVerdictWhat the reviewer saw
dist/esm/src/CaipNetworkUtil.js medium No overtly malicious code (no exfiltration of credentials, no shell/eval/backdoor), but the module routes all supported-chain RPC traffic through a third-party proxy at rpc.walletconnect.org with embedded projectId and permits user-supplied RPC overrides, which warrants caution.
dist/esm/src/solana/SolanaHelpersUtils.js medium No malicious patterns detected; only minor robustness and potential project identifier exposure concerns in RPC URL construction and hex parsing.
dist/esm/src/solana/SolanaTypesUtil.js medium The file only imports a walletconnect provider in a Solana types utility; no malicious patterns are present, but the wallet-related import warrants low-level scrutiny.
dist/esm/exports/ethers.js safe This file is a simple re-export shim that adds no logic; no malicious patterns are present in the provided code.
dist/esm/exports/index.js safe Cleared by Jev triage; no further analysis needed
dist/esm/exports/solana.js safe The file is a simple re-export barrel module with no executable logic or suspicious patterns.
dist/esm/src/ConstantsUtil.js safe No malicious patterns detected; the file only contains static string constants for wallet connector names and EIP standards.
dist/esm/src/ErrorUtil.js safe No malicious patterns detected; the file only defines error constants and a top-level AbortController without any network, filesystem, process, or dynamic code execution activity.
dist/esm/src/HelpersUtil.js safe Cleared by Jev triage; no further analysis needed
dist/esm/src/LoggerUtil.js safe No malicious patterns detected; the code is a benign logger wrapper for WalletConnect that delegates error handling to a caller-provided callback.
dist/esm/src/PresetsUtil.js safe This file contains only static mapping data for wallet connector IDs, network image identifiers, and chain IDs, with no executable code, network calls, file system access, or other malicious patterns.
dist/esm/src/ProviderUtil.js safe No malicious patterns detected
dist/esm/src/TypeUtil.js safe No malicious patterns detected; the file only defines a static enum and contains no executable or suspicious behavior.
dist/esm/src/ethers/EthersHelpersUtil.js safe No malicious patterns detected; the code provides standard Ethereum wallet interaction utilities using provider.request methods without exfiltration, obfuscation, or harmful behavior.
dist/esm/src/ethers/EthersStoreUtil.js safe No malicious patterns detected
dist/esm/src/ethers/EthersTypesUtil.js safe No malicious patterns detected
dist/esm/src/solana/SolanaConstantsUtil.js safe No malicious patterns detected; the file contains only static Solana blockchain constants and configuration.

Frequently asked questions

Is @reown/appkit-utils safe to use?

No confirmed malware was found in @reown/appkit-utils@1.7.8, but the review flagged 1 medium, 6 low severity findings for risky patterns worth checking before you rely on it.

Does @reown/appkit-utils contain malware?

No malware was identified in @reown/appkit-utils@1.7.8 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @reown/appkit-utils checked?

Togoder Security downloaded the published npm package and had an AI model read its 17 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @reown/appkit-utils together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @reown/appkit-utils@1.7.8, cost nothing.

Related security reports