Togoder security

npm package security report

@walletconnect/ethereum-provider npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 2.21.1 Files reviewed 3 Size 39.6 KB Scanned

Summary

Togoder Security scanned the npm package @walletconnect/ethereum-provider@2.21.1 on Oct 4, 2026. An AI review of 3 source files produced 1 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
8
low

Findings 9

medium

Cryptocurrency wallet provider

NPS-22A28D872D99

The package implements an Ethereum JSON-RPC provider that can request signatures (personal_sign, eth_signTypedData, eth_sendTransaction) and accounts. This is legitimate wallet functionality, but such code is inherently sensitive because it handles signing requests on behalf of users; it should be reviewed in the context of its intended use.

dist/index.native.js
low

Dynamic module loading based on external input

NPS-1524F44F4720

The code dynamically requires the '@reown/appkit/core' module at runtime using await Promise.resolve().then(function(){return W(require('@reown/appkit/core'))}). While the module name is fixed, this pattern defers loading and could be used for conditional dependencies. However, the use of a fixed module string reduces the risk of arbitrary code execution from computed inputs.

dist/index.cjs.js
low

Potential information exposure via network requests

NPS-1110D33111DB

The code constructs RPC URLs that include a project ID parameter: https://rpc.walletconnect.org/v1/?chainId=...&projectId=.... The project ID may be sensitive if hardcoded or mishandled, but in this context it is a user-supplied configuration parameter. No evidence of exfiltration to unknown servers.

dist/index.cjs.js
low

Session data persistence

NPS-2CE56D707038

The code uses persistent storage (e.g., this.signer.client.core.storage.setItem) to save the chain ID. While this is standard for session management, it represents a minor privacy consideration as it stores user session state. No credentials or sensitive keys are explicitly stored.

dist/index.cjs.js
low

Dynamic import of external module

NPS-2129B4E31985

The code uses a dynamic import for '@reown/appkit/core' inside the initialize method. This is not inherently malicious but could allow loading arbitrary code if the import path were configurable. Here it is a fixed package name, so risk is low.

dist/index.es.js
low

Network requests to external RPC endpoints

NPS-30CE335E151C

The code constructs RPC URLs pointing to 'https://rpc.walletconnect.org/v1/' and uses them for blockchain interactions. This is expected behavior for a wallet provider but could potentially leak user data (e.g., IP address, project ID) to a third-party service.

dist/index.es.js
low

Dynamic code execution via import()

NPS-140174894E3D

The dynamic import of '@reown/appkit/core' is performed based on configuration flag 'showQrModal'. While not user-controlled directly, it loads code at runtime. No obfuscation or malicious payload detected.

dist/index.es.js
low

Third-party dependency and external RPC endpoint

NPS-FF833C29935B

The module relies on the external WalletConnect service and sends RPC requests to the external endpoint https://rpc.walletconnect.org/v1/, including the user's projectId and chainId. While this is expected behavior for a WalletConnect provider, it means blockchain RPC traffic and metadata are transmitted to a third party.

dist/index.native.js
low

Dynamic import of optional module

NPS-EC0839C35A2E

The code uses Promise.resolve().then(function(){return et}) to dynamically load an internal appkit helper module and also attempts to load @reown/appkit. This is dynamic module loading, though the target is a fixed internal object rather than computed or external input, so it is not a direct security risk.

dist/index.native.js

Files reviewed

FileVerdictWhat the reviewer saw
dist/index.cjs.js medium The code is a legitimate WalletConnect Ethereum provider library with no malicious patterns, but it includes dynamic module loading and network requests typical for wallet connectivity.
dist/index.es.js medium The code is a legitimate WalletConnect Ethereum provider with expected network interactions and dynamic imports, but no clear malicious patterns such as data exfiltration or credential harvesting were found.
dist/index.native.js medium The code appears to be a legitimate WalletConnect/Ethereum provider implementation with no clear malicious patterns, though it depends on external services and handles sensitive wallet signing operations.

Scanned versions of @walletconnect/ethereum-provider

VersionVerdictFilesScanned
2.21.1 Needs review 3 Oct 4, 2026

Frequently asked questions

Is @walletconnect/ethereum-provider safe to use?

No confirmed malware was found in @walletconnect/ethereum-provider@2.21.1, but the review flagged 1 medium, 8 low severity findings for risky patterns worth checking before you rely on it.

Does @walletconnect/ethereum-provider contain malware?

No malware was identified in @walletconnect/ethereum-provider@2.21.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @walletconnect/ethereum-provider checked?

Togoder Security downloaded the published npm package and had an AI model read its 3 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @walletconnect/ethereum-provider together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @walletconnect/ethereum-provider@2.21.1, cost nothing.

Related security reports