Togoder security

npm package security report

@walletconnect/jsonrpc-ws-connection npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 1.0.16 Files reviewed 3 Size 17.7 KB Scanned

Summary

Togoder Security scanned the npm package @walletconnect/jsonrpc-ws-connection@1.0.16 on Oct 4, 2026. An AI review of 3 source files produced 1 high, 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
1
high
0
medium
4
low

Findings 5

high

TLS certificate validation bypass

NPS-6D24FEAA4432

The code sets rejectUnauthorized: false when creating WebSocket connections to non-localhost URLs (ve(e) check only excludes localhost). This disables TLS certificate validation, allowing man-in-the-middle attacks and potential credential/token interception. In a WebSocket RPC connection library handling wallet communications, this is a significant security weakness.

dist/index.umd.js
low

WebSocket fallback to require('ws')

NPS-1F175F87A1EF

The code uses require('ws') as a fallback when native WebSocket is unavailable. This is a standard pattern in isomorphic libraries and not malicious, though it is a dynamic module load.

dist/index.es.js
low

TLS certificate validation bypass potential

NPS-5350DB8148E7

The code constructs WebSocket options with {rejectUnauthorized: !isLocalhostUrl(e)}, disabling TLS certificate validation for localhost URLs. This is intentional behavior for local development/testing, not exfiltration.

dist/index.es.js
low

Dynamic module loading via require

NPS-094AAC302E7C

Uses require('ws') as a fallback when WebSocket is not globally available. While this is a common pattern for Node.js WebSocket libraries, dynamic require of an external module at runtime can be a supply-chain risk vector.

dist/index.umd.js
low

Global scope pollution / UMD wrapper

NPS-C3B15F6097B1

The UMD wrapper attaches the module to globalThis under '@walletconnect/jsonrpc-ws-connection'. This is standard UMD behavior for a public library and not inherently malicious, but it does expose the library globally.

dist/index.umd.js

Files reviewed

FileVerdictWhat the reviewer saw
dist/index.umd.js medium This appears to be a legitimate WalletConnect JSON-RPC WebSocket connection library, but it disables TLS certificate validation (rejectUnauthorized: false) for non-localhost connections, creating a high-severity man-in-the-middle risk.
dist/index.cjs.js safe No malicious patterns detected; the code is a standard WebSocket connection wrapper using WalletConnect utilities with no data exfiltration, credential harvesting, dynamic execution, or process spawning.
dist/index.es.js safe No malicious patterns detected; the code is a legitimate WebSocket connection wrapper from WalletConnect with standard isomorphic WebSocket handling and a localhost-only TLS bypass.

Scanned versions of @walletconnect/jsonrpc-ws-connection

VersionVerdictFilesScanned
1.0.16 Needs review 3 Oct 4, 2026

Frequently asked questions

Is @walletconnect/jsonrpc-ws-connection safe to use?

No confirmed malware was found in @walletconnect/jsonrpc-ws-connection@1.0.16, but the review flagged 1 high, 4 low severity findings for risky patterns worth checking before you rely on it.

Does @walletconnect/jsonrpc-ws-connection contain malware?

No malware was identified in @walletconnect/jsonrpc-ws-connection@1.0.16 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @walletconnect/jsonrpc-ws-connection checked?

Togoder Security downloaded the published npm package and had an AI model read its 3 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @walletconnect/jsonrpc-ws-connection together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @walletconnect/jsonrpc-ws-connection@1.0.16, cost nothing.

Related security reports