Summary
Togoder Security scanned the npm package @wagmi/connectors@6.2.0 on Oct 4, 2026. An AI review of 18 source files produced 2 medium, 14 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 16
Vulnerable dependency
NPS-97BCC0DADBFF
The JSDoc deprecation notice explicitly states this connector relies on a vulnerable downstream dependency chain (@walletconnect/ethereum-provider@2.21.1 > @reown/appkit@1.8.9 > @reown/appkit-utils@1.8.9 > @walletconnect/logger@2.1.2 > pino@7.11.0). The known vulnerability in pino@7.11.0 is a prototype pollution issue. While not a direct malicious pattern in this file, it represents a real security concern that users must mitigate via package manager overrides.
Known vulnerable dependency (informational)
NPS-02E9DF6ACA0A
The JSDoc for the exported walletConnect function explicitly documents that this connector relies on a downstream dependency chain (@walletconnect/ethereum-provider@2.21.1 > @reown/appkit@1.8.9 > @reown/appkit-utils@1.8.9 > @walletconnect/logger@2.1.2 > pino@7.11.0) containing a known vulnerability. The code itself does not exploit this, but consumers are exposed unless they override pino to a patched version as documented. This is a supply-chain risk rather than a malicious code pattern in this file.
Dynamic Import
NPS-4CFBD1D3327F
The code uses dynamic import() to load @coinbase/wallet-sdk and cbw-sdk. This is a normal pattern for third-party SDK integration and not inherently malicious. The imports are static strings and not computed from external input.
dynamic import with computed specifier
NPS-6FD051469B2C
The code dynamically imports the 'porto' module inside getPortoInstance using await import('porto'). However, the specifier is a static string literal, not computed from external input, and is a legitimate dependency. No obfuscation or exfiltration is present.
Storage manipulation
NPS-57DEE0A2F186
The code reads and writes to config.storage to manage a 'disconnected' shim. This is limited to the application's own storage and does not involve file system or credential harvesting.
Provider interaction and account data handling
NPS-20812EF122E5
The connector requests Ethereum accounts via eth_accounts and maps them to addresses. This is standard behavior for a wallet connector and does not involve exfiltration. However, the code interacts with the Safe Apps SDK and provider, which could potentially be used to access sensitive wallet data if the underlying Safe Apps SDK were malicious. The code itself does not send data externally.
Dynamic import based on runtime environment
NPS-DE27C1E6384B
The code uses dynamic imports (import('@safe-global/safe-apps-provider') and import('@safe-global/safe-apps-sdk')) to load external modules at runtime. While these are legitimate dependencies for the Safe connector, dynamic imports can be a vector for supply chain attacks if the referenced packages are compromised or if the import path were to be manipulated.
Timeout on external call
NPS-E68539E9185A
The getInfo call to the Safe SDK is wrapped with a timeout. While this is good practice, it indicates communication with an external service (the Safe Apps iframe). The data returned includes Safe information, which is expected for this connector but could be a concern if the iframe context is compromised.
Dynamic import
NPS-3A4C72D43912
The code performs a dynamic import('@walletconnect/ethereum-provider') at runtime. This is a legitimate lazy-loading pattern for a wallet connector, not obfuscation, and the import specifier is a static string. No external or computed input controls the module path.
Network interaction via RPC
NPS-D057AA472FC1
The connector builds an rpcMap from configured chains and passes it to EthereumProvider.init, and makes wallet_switchEthereumChain / wallet_addEthereumChain requests. These are expected WalletConnect/EIP-1193 behaviors, not exfiltration, but they do cause network calls to user-configured RPC endpoints.
Event listener manipulation
NPS-BDE618ABA986
provider_?.events.setMaxListeners(Number.POSITIVE_INFINITY) removes Node.js EventEmitter listener limits. This is used to avoid MaxListenersExceededWarning in long-lived wallet sessions, but unbounded listeners can theoretically be abused for memory exhaustion if the provider emits many events. This is a known trade-off in wagmi's implementation, not a backdoor.
Embedded base64 payload (icon)
NPS-AC382E50606B
Contains a large base64-encoded SVG data URI for the connector icon. This is a standard pattern for wagmi connector icons and decodes to a valid SVG logo, not executable code. However, embedded base64 blobs are worth flagging for manual review.
RPC method invocation
NPS-3787E1B65579
Calls provider.request with wallet_connect, wallet_disconnect, wallet_switchEthereumChain, eth_accounts, eth_chainId. These are standard EIP-1193 / EIP-6963 wallet RPC calls expected for a wagmi connector and are not exfiltration.
Dynamic import
NPS-5DCD2582A51A
Uses await import('porto') inside getPortoInstance(). This is a dynamic import with a hardcoded module name, not computed from external input, but still worth noting as a module loading pattern. It references the parent package 'porto' from within '@wagmi/connectors' or similar, which is a legitimate cross-package dependency usage.
Dynamic import of external module
NPS-C96D4BD8C142
await import('@walletconnect/ethereum-provider') is a dynamic import. It is a legitimate lazy-load of a statically-known, hard-coded package name (not computed from user input or remote data), so it is not itself malicious, but it is a dynamic module load that warrants noting for supply-chain review.
Network interaction via RPC providers
NPS-47AF1090EB80
extractRpcUrls and provider.request(...) cause network requests to configured RPC endpoints and to the WalletConnect relay. These are expected for a wallet connector and destinations are derived from developer-supplied chain configuration, not from external input.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/esm/safe.js | medium | The code appears to be a legitimate Safe wallet connector with no clear malicious patterns, but it does use dynamic imports and external SDK interactions that warrant a warning for potential supply chain risks. |
| dist/esm/walletConnect.js | medium | No direct malicious code (exfiltration, credential theft, shell execution, obfuscation, or wallet draining) was found in this file; the main concern is a documented vulnerable transitive dependency (pino@7.11.0) that requires user-side package manager overrides to remediate. |
| src/porto.ts | medium | This is a legitimate wagmi connector implementation for the Porto wallet; no malicious patterns such as exfiltration, credential harvesting, obfuscated execution, or backdoors were detected, though the dynamic import and embedded base64 icon are noted for completeness. |
| src/walletConnect.ts | medium | The connector code is functionally consistent with a legitimate wagmi WalletConnect integration, but it explicitly ships with a documented vulnerable downstream dependency (pino@7.11.0 via @reown/appkit) that consumers must override, warranting a warning. |
| dist/esm/baseAccount.js | safe | No malicious patterns detected; the code is a standard wagmi connector implementation for the Base Account SDK with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| dist/esm/coinbaseWallet.js | safe | The code is a legitimate wagmi connector for Coinbase Wallet with no malicious patterns detected; dynamic imports are used for SDK loading but are not obfuscated or externally controlled. |
| dist/esm/exports/index.js | safe | No malicious patterns detected in the re-export barrel file. |
| dist/esm/gemini.js | safe | No malicious patterns detected |
| dist/esm/metaMask.js | safe | No malicious patterns detected; this is a legitimate MetaMask SDK connector for wagmi with standard wallet interaction logic. |
| dist/esm/porto.js | safe | The code is a legitimate wagmi connector implementation for Porto with no malicious patterns detected. |
| dist/esm/version.js | safe | Cleared by Jev triage; no further analysis needed |
| src/baseAccount.ts | safe | No malicious patterns detected; the code is a legitimate wagmi connector for Base Account with no data exfiltration, credential harvesting, obfuscation, or suspicious network/file/process operations. |
| src/coinbaseWallet.ts | safe | No malicious patterns detected; this is a legitimate wagmi connector for Coinbase Wallet with expected dynamic imports and provider interactions. |
| src/exports/index.ts | safe | This is a standard barrel file re-exporting wallet connector modules from a wagmi-based package, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
| src/gemini.ts | safe | No malicious patterns detected; the code is a standard wagmi connector for the Gemini wallet. |
| src/metaMask.ts | safe | No malicious patterns detected; this is a legitimate wagmi connector for MetaMask SDK with standard wallet interaction code. |
| src/safe.ts | safe | No malicious patterns detected |
| src/version.ts | safe | Cleared by Jev triage; no further analysis needed |
Scanned versions of @wagmi/connectors
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 6.2.0 | Needs review | 18 | Oct 4, 2026 |
Frequently asked questions
Is @wagmi/connectors safe to use?
No confirmed malware was found in @wagmi/connectors@6.2.0, but the review flagged 2 medium, 14 low severity findings for risky patterns worth checking before you rely on it.
Does @wagmi/connectors contain malware?
No malware was identified in @wagmi/connectors@6.2.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @wagmi/connectors checked?
Togoder Security downloaded the published npm package and had an AI model read its 18 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @wagmi/connectors together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @wagmi/connectors@6.2.0, cost nothing.