# @wagmi/connectors@6.2.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:18:28.000Z
- Files reviewed: 18
- Findings: 2 medium, 14 low severity findings
- Report: https://security.togoder.click/npm/@wagmi/connectors
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @wagmi/connectors@6.2.0 on Oct 4, 2026. An AI review of 18 source files produced 2 medium, 14 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Vulnerable dependency

Finding ID: `NPS-97BCC0DADBFF`

File: `dist/esm/walletConnect.js:5`

The JSDoc deprecation notice explicitly states this connector relies on a vulnerable downstream dependency chain (`@walletconnect/ethereum-provider@2.21.1` > `@reown/appkit@1.8.9` > `@reown/appkit-utils@1.8.9` > `@walletconnect/logger@2.1.2` > `pino@7.11.0`). The known vulnerability in pino@7.11.0 is a prototype pollution issue. While not a direct malicious pattern in this file, it represents a real security concern that users must mitigate via package manager overrides.

### [medium] Known vulnerable dependency (informational)

Finding ID: `NPS-02E9DF6ACA0A`

File: `src/walletConnect.ts`

The JSDoc for the exported `walletConnect` function explicitly documents that this connector relies on a downstream dependency chain (`@walletconnect/ethereum-provider@2.21.1` > `@reown/appkit@1.8.9` > `@reown/appkit-utils@1.8.9` > `@walletconnect/logger@2.1.2` > `pino@7.11.0`) containing a known vulnerability. The code itself does not exploit this, but consumers are exposed unless they override `pino` to a patched version as documented. This is a supply-chain risk rather than a malicious code pattern in this file.

### [low] Dynamic Import

Finding ID: `NPS-4CFBD1D3327F`

File: `dist/esm/coinbaseWallet.js`

The code uses dynamic import() to load @coinbase/wallet-sdk and cbw-sdk. This is a normal pattern for third-party SDK integration and not inherently malicious. The imports are static strings and not computed from external input.

### [low] dynamic import with computed specifier

Finding ID: `NPS-6FD051469B2C`

File: `dist/esm/porto.js:153`

The code dynamically imports the 'porto' module inside getPortoInstance using `await import('porto')`. However, the specifier is a static string literal, not computed from external input, and is a legitimate dependency. No obfuscation or exfiltration is present.

### [low] Storage manipulation

Finding ID: `NPS-57DEE0A2F186`

File: `dist/esm/safe.js:30`

The code reads and writes to `config.storage` to manage a 'disconnected' shim. This is limited to the application's own storage and does not involve file system or credential harvesting.

### [low] Provider interaction and account data handling

Finding ID: `NPS-20812EF122E5`

File: `dist/esm/safe.js:48`

The connector requests Ethereum accounts via `eth_accounts` and maps them to addresses. This is standard behavior for a wallet connector and does not involve exfiltration. However, the code interacts with the Safe Apps SDK and provider, which could potentially be used to access sensitive wallet data if the underlying Safe Apps SDK were malicious. The code itself does not send data externally.

### [low] Dynamic import based on runtime environment

Finding ID: `NPS-DE27C1E6384B`

File: `dist/esm/safe.js:63`

The code uses dynamic imports (`import('@safe-global/safe-apps-provider')` and `import('@safe-global/safe-apps-sdk')`) to load external modules at runtime. While these are legitimate dependencies for the Safe connector, dynamic imports can be a vector for supply chain attacks if the referenced packages are compromised or if the import path were to be manipulated.

### [low] Timeout on external call

Finding ID: `NPS-E68539E9185A`

File: `dist/esm/safe.js:71`

The `getInfo` call to the Safe SDK is wrapped with a timeout. While this is good practice, it indicates communication with an external service (the Safe Apps iframe). The data returned includes Safe information, which is expected for this connector but could be a concern if the iframe context is compromised.

### [low] Dynamic import

Finding ID: `NPS-3A4C72D43912`

File: `dist/esm/walletConnect.js:237`

The code performs a dynamic `import('@walletconnect/ethereum-provider')` at runtime. This is a legitimate lazy-loading pattern for a wallet connector, not obfuscation, and the import specifier is a static string. No external or computed input controls the module path.

### [low] Network interaction via RPC

Finding ID: `NPS-D057AA472FC1`

File: `dist/esm/walletConnect.js:239`

The connector builds an rpcMap from configured chains and passes it to EthereumProvider.init, and makes wallet_switchEthereumChain / wallet_addEthereumChain requests. These are expected WalletConnect/EIP-1193 behaviors, not exfiltration, but they do cause network calls to user-configured RPC endpoints.

### [low] Event listener manipulation

Finding ID: `NPS-BDE618ABA986`

File: `dist/esm/walletConnect.js:258`

`provider_?.events.setMaxListeners(Number.POSITIVE_INFINITY)` removes Node.js EventEmitter listener limits. This is used to avoid MaxListenersExceededWarning in long-lived wallet sessions, but unbounded listeners can theoretically be abused for memory exhaustion if the provider emits many events. This is a known trade-off in wagmi's implementation, not a backdoor.

### [low] Embedded base64 payload (icon)

Finding ID: `NPS-AC382E50606B`

File: `src/porto.ts`

Contains a large base64-encoded SVG data URI for the connector icon. This is a standard pattern for wagmi connector icons and decodes to a valid SVG logo, not executable code. However, embedded base64 blobs are worth flagging for manual review.

### [low] RPC method invocation

Finding ID: `NPS-3787E1B65579`

File: `src/porto.ts`

Calls provider.request with wallet_connect, wallet_disconnect, wallet_switchEthereumChain, eth_accounts, eth_chainId. These are standard EIP-1193 / EIP-6963 wallet RPC calls expected for a wagmi connector and are not exfiltration.

### [low] Dynamic import

Finding ID: `NPS-5DCD2582A51A`

File: `src/porto.ts:192`

Uses `await import('porto')` inside getPortoInstance(). This is a dynamic import with a hardcoded module name, not computed from external input, but still worth noting as a module loading pattern. It references the parent package 'porto' from within '@wagmi/connectors' or similar, which is a legitimate cross-package dependency usage.

### [low] Dynamic import of external module

Finding ID: `NPS-C96D4BD8C142`

File: `src/walletConnect.ts`

`await import('@walletconnect/ethereum-provider')` is a dynamic import. It is a legitimate lazy-load of a statically-known, hard-coded package name (not computed from user input or remote data), so it is not itself malicious, but it is a dynamic module load that warrants noting for supply-chain review.

### [low] Network interaction via RPC providers

Finding ID: `NPS-47AF1090EB80`

File: `src/walletConnect.ts`

`extractRpcUrls` and `provider.request(...)` cause network requests to configured RPC endpoints and to the WalletConnect relay. These are expected for a wallet connector and destinations are derived from developer-supplied chain configuration, not from external input.

## Files reviewed

- `dist/esm/safe.js` (medium): The code appears to be a legitimate Safe wallet connector with no clear malicious patterns, but it does use dynamic imports and external SDK interactions that warrant a warning for potential supply chain risks.
- `dist/esm/walletConnect.js` (medium): No direct malicious code (exfiltration, credential theft, shell execution, obfuscation, or wallet draining) was found in this file; the main concern is a documented vulnerable transitive dependency (pino@7.11.0) that requires user-side package manager overrides to remediate.
- `src/porto.ts` (medium): This is a legitimate wagmi connector implementation for the Porto wallet; no malicious patterns such as exfiltration, credential harvesting, obfuscated execution, or backdoors were detected, though the dynamic import and embedded base64 icon are noted for completeness.
- `src/walletConnect.ts` (medium): The connector code is functionally consistent with a legitimate wagmi WalletConnect integration, but it explicitly ships with a documented vulnerable downstream dependency (pino@7.11.0 via @reown/appkit) that consumers must override, warranting a warning.
- `dist/esm/baseAccount.js` (safe): No malicious patterns detected; the code is a standard wagmi connector implementation for the Base Account SDK with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `dist/esm/coinbaseWallet.js` (safe): The code is a legitimate wagmi connector for Coinbase Wallet with no malicious patterns detected; dynamic imports are used for SDK loading but are not obfuscated or externally controlled.
- `dist/esm/exports/index.js` (safe): No malicious patterns detected in the re-export barrel file.
- `dist/esm/gemini.js` (safe): No malicious patterns detected
- `dist/esm/metaMask.js` (safe): No malicious patterns detected; this is a legitimate MetaMask SDK connector for wagmi with standard wallet interaction logic.
- `dist/esm/porto.js` (safe): The code is a legitimate wagmi connector implementation for Porto with no malicious patterns detected.
- `dist/esm/version.js` (safe): Cleared by Jev triage; no further analysis needed
- `src/baseAccount.ts` (safe): No malicious patterns detected; the code is a legitimate wagmi connector for Base Account with no data exfiltration, credential harvesting, obfuscation, or suspicious network/file/process operations.
- `src/coinbaseWallet.ts` (safe): No malicious patterns detected; this is a legitimate wagmi connector for Coinbase Wallet with expected dynamic imports and provider interactions.
- `src/exports/index.ts` (safe): This is a standard barrel file re-exporting wallet connector modules from a wagmi-based package, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
- `src/gemini.ts` (safe): No malicious patterns detected; the code is a standard wagmi connector for the Gemini wallet.
- `src/metaMask.ts` (safe): No malicious patterns detected; this is a legitimate wagmi connector for MetaMask SDK with standard wallet interaction code.
- `src/safe.ts` (safe): No malicious patterns detected
- `src/version.ts` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
