Summary
Togoder Security scanned the npm package @walletconnect/jsonrpc-ws-connection@1.0.16 on Oct 4, 2026. An AI review of 3 source files produced 1 high, 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 5
TLS certificate validation bypass
NPS-6D24FEAA4432
The code sets rejectUnauthorized: false when creating WebSocket connections to non-localhost URLs (ve(e) check only excludes localhost). This disables TLS certificate validation, allowing man-in-the-middle attacks and potential credential/token interception. In a WebSocket RPC connection library handling wallet communications, this is a significant security weakness.
WebSocket fallback to require('ws')
NPS-1F175F87A1EF
The code uses require('ws') as a fallback when native WebSocket is unavailable. This is a standard pattern in isomorphic libraries and not malicious, though it is a dynamic module load.
TLS certificate validation bypass potential
NPS-5350DB8148E7
The code constructs WebSocket options with {rejectUnauthorized: !isLocalhostUrl(e)}, disabling TLS certificate validation for localhost URLs. This is intentional behavior for local development/testing, not exfiltration.
Dynamic module loading via require
NPS-094AAC302E7C
Uses require('ws') as a fallback when WebSocket is not globally available. While this is a common pattern for Node.js WebSocket libraries, dynamic require of an external module at runtime can be a supply-chain risk vector.
Global scope pollution / UMD wrapper
NPS-C3B15F6097B1
The UMD wrapper attaches the module to globalThis under '@walletconnect/jsonrpc-ws-connection'. This is standard UMD behavior for a public library and not inherently malicious, but it does expose the library globally.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/index.umd.js | medium | This appears to be a legitimate WalletConnect JSON-RPC WebSocket connection library, but it disables TLS certificate validation (rejectUnauthorized: false) for non-localhost connections, creating a high-severity man-in-the-middle risk. |
| dist/index.cjs.js | safe | No malicious patterns detected; the code is a standard WebSocket connection wrapper using WalletConnect utilities with no data exfiltration, credential harvesting, dynamic execution, or process spawning. |
| dist/index.es.js | safe | No malicious patterns detected; the code is a legitimate WebSocket connection wrapper from WalletConnect with standard isomorphic WebSocket handling and a localhost-only TLS bypass. |
Frequently asked questions
Is @walletconnect/jsonrpc-ws-connection safe to use?
No confirmed malware was found in @walletconnect/jsonrpc-ws-connection@1.0.16, but the review flagged 1 high, 4 low severity findings for risky patterns worth checking before you rely on it.
Does @walletconnect/jsonrpc-ws-connection contain malware?
No malware was identified in @walletconnect/jsonrpc-ws-connection@1.0.16 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @walletconnect/jsonrpc-ws-connection checked?
Togoder Security downloaded the published npm package and had an AI model read its 3 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @walletconnect/jsonrpc-ws-connection together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @walletconnect/jsonrpc-ws-connection@1.0.16, cost nothing.