Summary
Togoder Security scanned the npm package @walletconnect/core@2.21.1 on Oct 4, 2026. An AI review of 2 source files produced 3 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 9
Telemetry and data collection
NPS-F366F00C8AF5
The package includes an EventClient (EventClient class) that sends telemetry events to https://pulse.walletconnect.org/batch and registers device tokens to https://echo.walletconnect.com. This includes client ID, user agent, app domain, and other metadata. While this appears to be legitimate WalletConnect infrastructure, it represents data exfiltration to external servers.
File system/storage manipulation
NPS-7F5D71FC67E3
The package uses keyvaluestorage to persist data including private keys, sym keys, and session data. It stores sensitive cryptographic material. While this is expected for a wallet connection library, improper storage could lead to credential theft. Storage is scoped to the application's storage (localStorage/IndexedDB).
Telemetry and network requests at runtime
NPS-917C34F2599A
The EventClient class (Bi/EventClient) sends POST requests containing the client_id, user_agent, project ID, domain, and event traces to https://pulse.walletconnect.org/batch. It also registers device tokens with https://echo.walletconnect.com/${projectId}/clients. While this is documented WalletConnect telemetry for the official SDK, it is still outbound data transmission to third-party servers that runs on import/initialization.
Network requests to external servers
NPS-B001B020D6B1
Multiple external network requests are made to WalletConnect-controlled domains: relay.walletconnect.org (WebSocket), verify.walletconnect.com, verify.walletconnect.org, echo.walletconnect.com, and pulse.walletconnect.org. These are expected for a WalletConnect library but represent potential data exfiltration vectors if the domains were compromised or if the package were malicious.
Dynamic code execution via crypto operations
NPS-92595D0C0A5A
The code uses crypto.subtle.digest and other cryptographic operations. It also uses JWT signing and verification with Ed25519. These are standard for WalletConnect but could theoretically be abused. No eval, new Function, or similar dynamic code execution was found.
Global object manipulation
NPS-D6C52A9BB08C
The code sets global variables on globalThis (e.g., _walletConnectCore_<prefix>) and may override window.downloadLogsBlobInBrowser. This could lead to namespace pollution or unexpected global state, but is not inherently malicious.
Attestation iframe / postMessage handler
NPS-F8927FCEE8FC
The Verify class creates an iframe pointing to https://verify.walletconnect.com/v3/attestation and listens for message events, parsing JWT attestations. This is part of the official WalletConnect Verify feature, but the mechanism (iframe + postMessage + JWT parsing) could be a vector if the endpoint were compromised or MITM'd.
Dynamic module / globalThis manipulation
NPS-25E8EA22001D
The Core class stores and retrieves a global singleton via globalThis['_walletConnectCore_...'] and reads process.env.DISABLE_GLOBAL_CORE. This is not obfuscation but does interact with the global environment and process environment variables (read-only).
Cryptographic key material handling in memory
NPS-0A3F947ED7D0
The Crypto class generates and stores private keys, symmetric keys, and client seeds in a KeyChain (default in-memory / keyvaluestorage). This is expected for a wallet-connect library, but the library does handle sensitive key material that could be targeted by malicious actors if the package were compromised.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/index.cjs.js | medium | The package is the legitimate WalletConnect Core library and performs expected networking, cryptographic operations, and telemetry to WalletConnect-controlled servers; no malicious patterns such as credential harvesting, obfuscated payloads, shell execution, or wallet draining were detected, but its telemetry and key storage practices warrant caution. |
| dist/index.es.js | medium | This is the legitimate @walletconnect/core package; it contains expected telemetry, attestation, and key-management code, but no evidence of malicious exfiltration, credential harvesting, obfuscation, or backdoor behavior beyond the SDK's documented network calls. |
Affected version ranges
None of the 3 scanned versions of @walletconnect/core are flagged high or critical. The latest scanned version, 2.25.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 2.21.0 – 2.25.0 | Needs review | 3 | >=2.21.0 <=2.25.0 | Telemetry and data collection; Cryptographic key handling |
| 2.19.0 – 2.19.1 | Not scanned | 2 | >=2.19.0 <=2.19.1 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of @walletconnect/core
Frequently asked questions
Is @walletconnect/core safe to use?
No confirmed malware was found in @walletconnect/core@2.21.1, but the review flagged 3 medium, 6 low severity findings for risky patterns worth checking before you rely on it.
Does @walletconnect/core contain malware?
No malware was identified in @walletconnect/core@2.21.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @walletconnect/core checked?
Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @walletconnect/core together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @walletconnect/core@2.21.1, cost nothing.