Summary
Togoder Security scanned the npm package @walletconnect/ethereum-provider@2.21.1 on Oct 4, 2026. An AI review of 3 source files produced 1 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 9
Cryptocurrency wallet provider
NPS-22A28D872D99
The package implements an Ethereum JSON-RPC provider that can request signatures (personal_sign, eth_signTypedData, eth_sendTransaction) and accounts. This is legitimate wallet functionality, but such code is inherently sensitive because it handles signing requests on behalf of users; it should be reviewed in the context of its intended use.
Dynamic module loading based on external input
NPS-1524F44F4720
The code dynamically requires the '@reown/appkit/core' module at runtime using await Promise.resolve().then(function(){return W(require('@reown/appkit/core'))}). While the module name is fixed, this pattern defers loading and could be used for conditional dependencies. However, the use of a fixed module string reduces the risk of arbitrary code execution from computed inputs.
Potential information exposure via network requests
NPS-1110D33111DB
The code constructs RPC URLs that include a project ID parameter: https://rpc.walletconnect.org/v1/?chainId=...&projectId=.... The project ID may be sensitive if hardcoded or mishandled, but in this context it is a user-supplied configuration parameter. No evidence of exfiltration to unknown servers.
Session data persistence
NPS-2CE56D707038
The code uses persistent storage (e.g., this.signer.client.core.storage.setItem) to save the chain ID. While this is standard for session management, it represents a minor privacy consideration as it stores user session state. No credentials or sensitive keys are explicitly stored.
Dynamic import of external module
NPS-2129B4E31985
The code uses a dynamic import for '@reown/appkit/core' inside the initialize method. This is not inherently malicious but could allow loading arbitrary code if the import path were configurable. Here it is a fixed package name, so risk is low.
Network requests to external RPC endpoints
NPS-30CE335E151C
The code constructs RPC URLs pointing to 'https://rpc.walletconnect.org/v1/' and uses them for blockchain interactions. This is expected behavior for a wallet provider but could potentially leak user data (e.g., IP address, project ID) to a third-party service.
Dynamic code execution via import()
NPS-140174894E3D
The dynamic import of '@reown/appkit/core' is performed based on configuration flag 'showQrModal'. While not user-controlled directly, it loads code at runtime. No obfuscation or malicious payload detected.
Third-party dependency and external RPC endpoint
NPS-FF833C29935B
The module relies on the external WalletConnect service and sends RPC requests to the external endpoint https://rpc.walletconnect.org/v1/, including the user's projectId and chainId. While this is expected behavior for a WalletConnect provider, it means blockchain RPC traffic and metadata are transmitted to a third party.
Dynamic import of optional module
NPS-EC0839C35A2E
The code uses Promise.resolve().then(function(){return et}) to dynamically load an internal appkit helper module and also attempts to load @reown/appkit. This is dynamic module loading, though the target is a fixed internal object rather than computed or external input, so it is not a direct security risk.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/index.cjs.js | medium | The code is a legitimate WalletConnect Ethereum provider library with no malicious patterns, but it includes dynamic module loading and network requests typical for wallet connectivity. |
| dist/index.es.js | medium | The code is a legitimate WalletConnect Ethereum provider with expected network interactions and dynamic imports, but no clear malicious patterns such as data exfiltration or credential harvesting were found. |
| dist/index.native.js | medium | The code appears to be a legitimate WalletConnect/Ethereum provider implementation with no clear malicious patterns, though it depends on external services and handles sensitive wallet signing operations. |
Frequently asked questions
Is @walletconnect/ethereum-provider safe to use?
No confirmed malware was found in @walletconnect/ethereum-provider@2.21.1, but the review flagged 1 medium, 8 low severity findings for risky patterns worth checking before you rely on it.
Does @walletconnect/ethereum-provider contain malware?
No malware was identified in @walletconnect/ethereum-provider@2.21.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @walletconnect/ethereum-provider checked?
Togoder Security downloaded the published npm package and had an AI model read its 3 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @walletconnect/ethereum-provider together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @walletconnect/ethereum-provider@2.21.1, cost nothing.