Togoder security

npm package security report

@walletconnect/core@2.21.0 security report

Risky patterns found that deserve a look.

Needs review Version 2.21.0 Files reviewed 2 Size 482.2 KB Scanned

Summary

Togoder Security scanned the npm package @walletconnect/core@2.21.0 on Oct 4, 2026. An AI review of 2 source files produced 3 medium, 7 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
3
medium
7
low

Findings 10

medium

Network requests to external services

NPS-C920F11DCD03

The code makes several HTTP fetch requests to external WalletConnect infrastructure (verify.walletconnect.com, pulse.walletconnect.org, echo.walletconnect.com). These are expected for a WalletConnect SDK but represent telemetry and attestation data being sent externally. The event client sends telemetry to pulse.walletconnect.org including client ID, user agent, and event traces.

dist/index.cjs.js:1
medium

Telemetry and data collection

NPS-8A168A42A627

The EventClient class collects and sends telemetry data (client ID, user agent, app domain, event traces) to https://pulse.walletconnect.org/batch. While this is a known feature of WalletConnect v2.21.0, it represents data exfiltration to an external server.

dist/index.cjs.js:1
medium

Cryptographic key handling

NPS-E470A3477163

The Crypto class generates and stores private keys, seeds, and symmetric keys in a keychain backed by storage. It uses ed25519 key pairs and JWT signing. While this is expected for a wallet SDK, any compromise of this code could lead to key theft. The keychain is stored in the configured storage (default in-memory).

dist/index.cjs.js:1
low

Dynamic iframe creation and postMessage handling

NPS-B59D8C754EE4

The Verify class creates a hidden iframe pointing to verify.walletconnect.com for attestation and listens for window postMessage events. It parses incoming messages and extracts JWT attestations. This could potentially be abused if the verify endpoint were compromised, but the URLs are hardcoded to trusted domains.

dist/index.cjs.js:1
low

Global variable manipulation

NPS-5B1DC525CA69

The Core class sets global variables (globalThis._walletConnectCore_) and injects a downloadLogsBlobInBrowser function onto the window object. This modifies the global environment, which could potentially interfere with other applications but is not inherently malicious.

dist/index.cjs.js:1
low

Network requests to external services

NPS-9437383791A6

The code makes network requests to external URLs including https://verify.walletconnect.com, https://verify.walletconnect.org, https://echo.walletconnect.com, and https://pulse.walletconnect.org/batch. These are part of expected WalletConnect functionality (attestation verification, echo client for push notifications, and telemetry/event collection) but represent external data transmission.

dist/index.es.js
low

Telemetry and event data collection

NPS-7EF0CFBC9586

The EventClient class collects and sends telemetry data (events, traces, errors) to https://pulse.walletconnect.org/batch including client ID, user agent, domain, and other metadata. This is opt-in but enabled by default (telemetryEnabled parameter defaults to true).

dist/index.es.js
low

Dynamic iframe creation and message handling

NPS-3C3361A21DC1

The Verify class creates an iframe pointing to a verify URL and listens for postMessage events to receive attestation JWTs. While this is standard WalletConnect verification flow, it involves dynamic DOM manipulation and cross-origin message handling.

dist/index.es.js
low

Local storage of cryptographic material

NPS-024964CC2B50

Cryptographic keys (symmetric keys, private keys, client seeds) are stored in local storage via KeyChain and Crypto classes. This is expected for a wallet connectivity library but means sensitive material is persisted in browser storage.

dist/index.es.js
low

Global state manipulation

NPS-CC6A37D7DF91

The Core class sets global variables on globalThis (e.g., _walletConnectCore_) and can modify window.downloadLogsBlobInBrowser. This is for singleton pattern implementation but does modify global scope.

dist/index.es.js

Files reviewed

FileVerdictWhat the reviewer saw
dist/index.cjs.js medium This appears to be the legitimate WalletConnect Core SDK (v2.21.0) which makes expected network requests to WalletConnect infrastructure for relay, verify, echo, and telemetry services, with no evidence of malicious backdoors, code execution, or credential harvesting beyond what is normal for this SDK.
dist/index.es.js medium This is the official WalletConnect Core library (v2.21.0) with expected network communications to WalletConnect infrastructure for relay, verification, and telemetry; no malicious patterns, obfuscation, credential harvesting, or backdoors were detected.

Affected version ranges

None of the 3 scanned versions of @walletconnect/core are flagged high or critical. The latest scanned version, 2.25.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

2.19.02.25.0
VersionsVerdictCountRangeTop findings
2.21.0 – 2.25.0 Needs review 3 >=2.21.0 <=2.25.0 Telemetry and data collection; Cryptographic key handling
2.19.0 – 2.19.1 Not scanned 2 >=2.19.0 <=2.19.1

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of @walletconnect/core

VersionVerdictFilesScanned
2.25.0 Needs review 2 Oct 4, 2026
2.21.1 Needs review 2 Oct 4, 2026
2.21.0 Needs review 2 Oct 4, 2026

Frequently asked questions

Is @walletconnect/core safe to use?

No confirmed malware was found in @walletconnect/core@2.21.0, but the review flagged 3 medium, 7 low severity findings for risky patterns worth checking before you rely on it.

Does @walletconnect/core contain malware?

No malware was identified in @walletconnect/core@2.21.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @walletconnect/core checked?

Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @walletconnect/core together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @walletconnect/core@2.21.0, cost nothing.

Related security reports