# @walletconnect/jsonrpc-ws-connection@1.0.16 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:20:07.000Z
- Files reviewed: 3
- Findings: 1 high, 4 low severity findings
- Report: https://security.togoder.click/npm/@walletconnect/jsonrpc-ws-connection
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @walletconnect/jsonrpc-ws-connection@1.0.16 on Oct 4, 2026. An AI review of 3 source files produced 1 high, 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [high] TLS certificate validation bypass

Finding ID: `NPS-6D24FEAA4432`

File: `dist/index.umd.js`

The code sets rejectUnauthorized: false when creating WebSocket connections to non-localhost URLs (ve(e) check only excludes localhost). This disables TLS certificate validation, allowing man-in-the-middle attacks and potential credential/token interception. In a WebSocket RPC connection library handling wallet communications, this is a significant security weakness.

### [low] WebSocket fallback to require('ws')

Finding ID: `NPS-1F175F87A1EF`

File: `dist/index.es.js`

The code uses require('ws') as a fallback when native WebSocket is unavailable. This is a standard pattern in isomorphic libraries and not malicious, though it is a dynamic module load.

### [low] TLS certificate validation bypass potential

Finding ID: `NPS-5350DB8148E7`

File: `dist/index.es.js`

The code constructs WebSocket options with {rejectUnauthorized: !isLocalhostUrl(e)}, disabling TLS certificate validation for localhost URLs. This is intentional behavior for local development/testing, not exfiltration.

### [low] Dynamic module loading via require

Finding ID: `NPS-094AAC302E7C`

File: `dist/index.umd.js`

Uses require('ws') as a fallback when WebSocket is not globally available. While this is a common pattern for Node.js WebSocket libraries, dynamic require of an external module at runtime can be a supply-chain risk vector.

### [low] Global scope pollution / UMD wrapper

Finding ID: `NPS-C3B15F6097B1`

File: `dist/index.umd.js`

The UMD wrapper attaches the module to globalThis under '@walletconnect/jsonrpc-ws-connection'. This is standard UMD behavior for a public library and not inherently malicious, but it does expose the library globally.

## Files reviewed

- `dist/index.umd.js` (medium): This appears to be a legitimate WalletConnect JSON-RPC WebSocket connection library, but it disables TLS certificate validation (rejectUnauthorized: false) for non-localhost connections, creating a high-severity man-in-the-middle risk.
- `dist/index.cjs.js` (safe): No malicious patterns detected; the code is a standard WebSocket connection wrapper using WalletConnect utilities with no data exfiltration, credential harvesting, dynamic execution, or process spawning.
- `dist/index.es.js` (safe): No malicious patterns detected; the code is a legitimate WebSocket connection wrapper from WalletConnect with standard isomorphic WebSocket handling and a localhost-only TLS bypass.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
