Summary
Togoder Security scanned the npm package @walletconnect/core@2.21.0 on Oct 4, 2026. An AI review of 2 source files produced 3 medium, 7 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 10
Network requests to external services
NPS-C920F11DCD03
The code makes several HTTP fetch requests to external WalletConnect infrastructure (verify.walletconnect.com, pulse.walletconnect.org, echo.walletconnect.com). These are expected for a WalletConnect SDK but represent telemetry and attestation data being sent externally. The event client sends telemetry to pulse.walletconnect.org including client ID, user agent, and event traces.
Telemetry and data collection
NPS-8A168A42A627
The EventClient class collects and sends telemetry data (client ID, user agent, app domain, event traces) to https://pulse.walletconnect.org/batch. While this is a known feature of WalletConnect v2.21.0, it represents data exfiltration to an external server.
Cryptographic key handling
NPS-E470A3477163
The Crypto class generates and stores private keys, seeds, and symmetric keys in a keychain backed by storage. It uses ed25519 key pairs and JWT signing. While this is expected for a wallet SDK, any compromise of this code could lead to key theft. The keychain is stored in the configured storage (default in-memory).
Dynamic iframe creation and postMessage handling
NPS-B59D8C754EE4
The Verify class creates a hidden iframe pointing to verify.walletconnect.com for attestation and listens for window postMessage events. It parses incoming messages and extracts JWT attestations. This could potentially be abused if the verify endpoint were compromised, but the URLs are hardcoded to trusted domains.
Global variable manipulation
NPS-5B1DC525CA69
The Core class sets global variables (globalThis._walletConnectCore_) and injects a downloadLogsBlobInBrowser function onto the window object. This modifies the global environment, which could potentially interfere with other applications but is not inherently malicious.
Network requests to external services
NPS-9437383791A6
The code makes network requests to external URLs including https://verify.walletconnect.com, https://verify.walletconnect.org, https://echo.walletconnect.com, and https://pulse.walletconnect.org/batch. These are part of expected WalletConnect functionality (attestation verification, echo client for push notifications, and telemetry/event collection) but represent external data transmission.
Telemetry and event data collection
NPS-7EF0CFBC9586
The EventClient class collects and sends telemetry data (events, traces, errors) to https://pulse.walletconnect.org/batch including client ID, user agent, domain, and other metadata. This is opt-in but enabled by default (telemetryEnabled parameter defaults to true).
Dynamic iframe creation and message handling
NPS-3C3361A21DC1
The Verify class creates an iframe pointing to a verify URL and listens for postMessage events to receive attestation JWTs. While this is standard WalletConnect verification flow, it involves dynamic DOM manipulation and cross-origin message handling.
Local storage of cryptographic material
NPS-024964CC2B50
Cryptographic keys (symmetric keys, private keys, client seeds) are stored in local storage via KeyChain and Crypto classes. This is expected for a wallet connectivity library but means sensitive material is persisted in browser storage.
Global state manipulation
NPS-CC6A37D7DF91
The Core class sets global variables on globalThis (e.g., _walletConnectCore_) and can modify window.downloadLogsBlobInBrowser. This is for singleton pattern implementation but does modify global scope.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/index.cjs.js | medium | This appears to be the legitimate WalletConnect Core SDK (v2.21.0) which makes expected network requests to WalletConnect infrastructure for relay, verify, echo, and telemetry services, with no evidence of malicious backdoors, code execution, or credential harvesting beyond what is normal for this SDK. |
| dist/index.es.js | medium | This is the official WalletConnect Core library (v2.21.0) with expected network communications to WalletConnect infrastructure for relay, verification, and telemetry; no malicious patterns, obfuscation, credential harvesting, or backdoors were detected. |
Affected version ranges
None of the 3 scanned versions of @walletconnect/core are flagged high or critical. The latest scanned version, 2.25.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 2.21.0 – 2.25.0 | Needs review | 3 | >=2.21.0 <=2.25.0 | Telemetry and data collection; Cryptographic key handling |
| 2.19.0 – 2.19.1 | Not scanned | 2 | >=2.19.0 <=2.19.1 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of @walletconnect/core
Frequently asked questions
Is @walletconnect/core safe to use?
No confirmed malware was found in @walletconnect/core@2.21.0, but the review flagged 3 medium, 7 low severity findings for risky patterns worth checking before you rely on it.
Does @walletconnect/core contain malware?
No malware was identified in @walletconnect/core@2.21.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @walletconnect/core checked?
Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @walletconnect/core together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @walletconnect/core@2.21.0, cost nothing.