Togoder security

npm package security report

@wagmi/connectors@6.2.0 security report

Risky patterns found that deserve a look.

Needs review Version 6.2.0 Files reviewed 18 Size 176.6 KB Scanned

Summary

Togoder Security scanned the npm package @wagmi/connectors@6.2.0 on Oct 4, 2026. An AI review of 18 source files produced 2 medium, 14 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
14
low

Findings 16

medium

Vulnerable dependency

NPS-97BCC0DADBFF

The JSDoc deprecation notice explicitly states this connector relies on a vulnerable downstream dependency chain (@walletconnect/ethereum-provider@2.21.1 > @reown/appkit@1.8.9 > @reown/appkit-utils@1.8.9 > @walletconnect/logger@2.1.2 > pino@7.11.0). The known vulnerability in pino@7.11.0 is a prototype pollution issue. While not a direct malicious pattern in this file, it represents a real security concern that users must mitigate via package manager overrides.

dist/esm/walletConnect.js:5
medium

Known vulnerable dependency (informational)

NPS-02E9DF6ACA0A

The JSDoc for the exported walletConnect function explicitly documents that this connector relies on a downstream dependency chain (@walletconnect/ethereum-provider@2.21.1 > @reown/appkit@1.8.9 > @reown/appkit-utils@1.8.9 > @walletconnect/logger@2.1.2 > pino@7.11.0) containing a known vulnerability. The code itself does not exploit this, but consumers are exposed unless they override pino to a patched version as documented. This is a supply-chain risk rather than a malicious code pattern in this file.

src/walletConnect.ts
low

Dynamic Import

NPS-4CFBD1D3327F

The code uses dynamic import() to load @coinbase/wallet-sdk and cbw-sdk. This is a normal pattern for third-party SDK integration and not inherently malicious. The imports are static strings and not computed from external input.

dist/esm/coinbaseWallet.js
low

dynamic import with computed specifier

NPS-6FD051469B2C

The code dynamically imports the 'porto' module inside getPortoInstance using await import('porto'). However, the specifier is a static string literal, not computed from external input, and is a legitimate dependency. No obfuscation or exfiltration is present.

dist/esm/porto.js:153
low

Storage manipulation

NPS-57DEE0A2F186

The code reads and writes to config.storage to manage a 'disconnected' shim. This is limited to the application's own storage and does not involve file system or credential harvesting.

dist/esm/safe.js:30
low

Provider interaction and account data handling

NPS-20812EF122E5

The connector requests Ethereum accounts via eth_accounts and maps them to addresses. This is standard behavior for a wallet connector and does not involve exfiltration. However, the code interacts with the Safe Apps SDK and provider, which could potentially be used to access sensitive wallet data if the underlying Safe Apps SDK were malicious. The code itself does not send data externally.

dist/esm/safe.js:48
low

Dynamic import based on runtime environment

NPS-DE27C1E6384B

The code uses dynamic imports (import('@safe-global/safe-apps-provider') and import('@safe-global/safe-apps-sdk')) to load external modules at runtime. While these are legitimate dependencies for the Safe connector, dynamic imports can be a vector for supply chain attacks if the referenced packages are compromised or if the import path were to be manipulated.

dist/esm/safe.js:63
low

Timeout on external call

NPS-E68539E9185A

The getInfo call to the Safe SDK is wrapped with a timeout. While this is good practice, it indicates communication with an external service (the Safe Apps iframe). The data returned includes Safe information, which is expected for this connector but could be a concern if the iframe context is compromised.

dist/esm/safe.js:71
low

Dynamic import

NPS-3A4C72D43912

The code performs a dynamic import('@walletconnect/ethereum-provider') at runtime. This is a legitimate lazy-loading pattern for a wallet connector, not obfuscation, and the import specifier is a static string. No external or computed input controls the module path.

dist/esm/walletConnect.js:237
low

Network interaction via RPC

NPS-D057AA472FC1

The connector builds an rpcMap from configured chains and passes it to EthereumProvider.init, and makes wallet_switchEthereumChain / wallet_addEthereumChain requests. These are expected WalletConnect/EIP-1193 behaviors, not exfiltration, but they do cause network calls to user-configured RPC endpoints.

dist/esm/walletConnect.js:239
low

Event listener manipulation

NPS-BDE618ABA986

provider_?.events.setMaxListeners(Number.POSITIVE_INFINITY) removes Node.js EventEmitter listener limits. This is used to avoid MaxListenersExceededWarning in long-lived wallet sessions, but unbounded listeners can theoretically be abused for memory exhaustion if the provider emits many events. This is a known trade-off in wagmi's implementation, not a backdoor.

dist/esm/walletConnect.js:258
low

Embedded base64 payload (icon)

NPS-AC382E50606B

Contains a large base64-encoded SVG data URI for the connector icon. This is a standard pattern for wagmi connector icons and decodes to a valid SVG logo, not executable code. However, embedded base64 blobs are worth flagging for manual review.

src/porto.ts
low

RPC method invocation

NPS-3787E1B65579

Calls provider.request with wallet_connect, wallet_disconnect, wallet_switchEthereumChain, eth_accounts, eth_chainId. These are standard EIP-1193 / EIP-6963 wallet RPC calls expected for a wagmi connector and are not exfiltration.

src/porto.ts
low

Dynamic import

NPS-5DCD2582A51A

Uses await import('porto') inside getPortoInstance(). This is a dynamic import with a hardcoded module name, not computed from external input, but still worth noting as a module loading pattern. It references the parent package 'porto' from within '@wagmi/connectors' or similar, which is a legitimate cross-package dependency usage.

src/porto.ts:192
low

Dynamic import of external module

NPS-C96D4BD8C142

await import('@walletconnect/ethereum-provider') is a dynamic import. It is a legitimate lazy-load of a statically-known, hard-coded package name (not computed from user input or remote data), so it is not itself malicious, but it is a dynamic module load that warrants noting for supply-chain review.

src/walletConnect.ts
low

Network interaction via RPC providers

NPS-47AF1090EB80

extractRpcUrls and provider.request(...) cause network requests to configured RPC endpoints and to the WalletConnect relay. These are expected for a wallet connector and destinations are derived from developer-supplied chain configuration, not from external input.

src/walletConnect.ts

Files reviewed

FileVerdictWhat the reviewer saw
dist/esm/safe.js medium The code appears to be a legitimate Safe wallet connector with no clear malicious patterns, but it does use dynamic imports and external SDK interactions that warrant a warning for potential supply chain risks.
dist/esm/walletConnect.js medium No direct malicious code (exfiltration, credential theft, shell execution, obfuscation, or wallet draining) was found in this file; the main concern is a documented vulnerable transitive dependency (pino@7.11.0) that requires user-side package manager overrides to remediate.
src/porto.ts medium This is a legitimate wagmi connector implementation for the Porto wallet; no malicious patterns such as exfiltration, credential harvesting, obfuscated execution, or backdoors were detected, though the dynamic import and embedded base64 icon are noted for completeness.
src/walletConnect.ts medium The connector code is functionally consistent with a legitimate wagmi WalletConnect integration, but it explicitly ships with a documented vulnerable downstream dependency (pino@7.11.0 via @reown/appkit) that consumers must override, warranting a warning.
dist/esm/baseAccount.js safe No malicious patterns detected; the code is a standard wagmi connector implementation for the Base Account SDK with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
dist/esm/coinbaseWallet.js safe The code is a legitimate wagmi connector for Coinbase Wallet with no malicious patterns detected; dynamic imports are used for SDK loading but are not obfuscated or externally controlled.
dist/esm/exports/index.js safe No malicious patterns detected in the re-export barrel file.
dist/esm/gemini.js safe No malicious patterns detected
dist/esm/metaMask.js safe No malicious patterns detected; this is a legitimate MetaMask SDK connector for wagmi with standard wallet interaction logic.
dist/esm/porto.js safe The code is a legitimate wagmi connector implementation for Porto with no malicious patterns detected.
dist/esm/version.js safe Cleared by Jev triage; no further analysis needed
src/baseAccount.ts safe No malicious patterns detected; the code is a legitimate wagmi connector for Base Account with no data exfiltration, credential harvesting, obfuscation, or suspicious network/file/process operations.
src/coinbaseWallet.ts safe No malicious patterns detected; this is a legitimate wagmi connector for Coinbase Wallet with expected dynamic imports and provider interactions.
src/exports/index.ts safe This is a standard barrel file re-exporting wallet connector modules from a wagmi-based package, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
src/gemini.ts safe No malicious patterns detected; the code is a standard wagmi connector for the Gemini wallet.
src/metaMask.ts safe No malicious patterns detected; this is a legitimate wagmi connector for MetaMask SDK with standard wallet interaction code.
src/safe.ts safe No malicious patterns detected
src/version.ts safe Cleared by Jev triage; no further analysis needed

Frequently asked questions

Is @wagmi/connectors safe to use?

No confirmed malware was found in @wagmi/connectors@6.2.0, but the review flagged 2 medium, 14 low severity findings for risky patterns worth checking before you rely on it.

Does @wagmi/connectors contain malware?

No malware was identified in @wagmi/connectors@6.2.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @wagmi/connectors checked?

Togoder Security downloaded the published npm package and had an AI model read its 18 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @wagmi/connectors together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @wagmi/connectors@6.2.0, cost nothing.

Related security reports