# @walletconnect/keyvaluestorage@1.1.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:20:12.000Z
- Files reviewed: 4
- Findings: 2 medium, 6 low severity findings
- Report: https://security.togoder.click/npm/@walletconnect/keyvaluestorage
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @walletconnect/keyvaluestorage@1.1.1 on Oct 4, 2026. An AI review of 4 source files produced 2 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] File system manipulation

Finding ID: `NPS-0DFC5CEE7A31`

File: `dist/index.cjs.js`

The code reads, writes, renames, and checks existence of files/directories using the 'fs' module, including operations on the database file path and migration logic. While these operations appear scoped to the user-configured database path, the migration logic renames files and could potentially interact with files outside the intended package scope if the dbName is crafted maliciously.

### [medium] File system manipulation and renaming

Finding ID: `NPS-DE42236E76B2`

File: `dist/index.umd.js`

The code checks for a file at the path constructed from the provided database name (default 'walletconnect.db'), and if it exists but is not a directory, it renames it by appending '.to_migrate'. It later renames that file to append '.migrated'. This manipulates files on disk outside the package scope and could be used to alter or corrupt user data or files.

### [low] Dynamic module loading

Finding ID: `NPS-04130C3D56CD`

File: `dist/index.cjs.js`

The code uses require('unstorage') and require('unstorage/drivers/fs-lite') dynamically inside a try-catch block. Although the module names are hardcoded, this pattern can be used to load arbitrary modules if the dependency is compromised or if the module resolution is altered.

### [low] Code runs at import time

Finding ID: `NPS-54C3111109EA`

File: `dist/index.cjs.js`

Top-level code executes on import, including the definition of a class that may create file system storage instances and perform migration routines. This behavior is typical for such libraries but warrants caution as it runs automatically when the module is required.

### [low] Storage migration / data access

Finding ID: `NPS-0BACC1EF9CE7`

File: `dist/index.es.js`

The code implements a KeyValueStorage abstraction for WalletConnect v2, migrating data from IndexedDB to localStorage and accessing keys matching walletconnect-related prefixes. This is expected behavior for the @walletconnect/keyvaluestorage package and does not constitute malicious data harvesting.

### [low] Top-level side effects

Finding ID: `NPS-4DF6BE895FB3`

File: `dist/index.es.js`

The module initializes a KeyValueStorage instance at import time via class instantiation, which triggers storage reads/writes (IndexedDB/localStorage). While this runs on import, it is limited to the package's own storage namespace and WalletConnect-related keys.

### [low] Dynamic require usage

Finding ID: `NPS-A33C106DD768`

File: `dist/index.umd.js`

The code dynamically requires modules ('unstorage' and 'unstorage/drivers/fs-lite') based on runtime conditions rather than static imports. While this is for optional dependency loading, it could be exploited if the module resolution path can be influenced.

### [low] Potential denial of service via busy-wait loop

Finding ID: `NPS-6DA19ED4E368`

File: `dist/index.umd.js`

The initialize() method uses a setInterval loop that polls every 20ms until this.initialized is true. If initialization never completes, this creates an infinite loop, potentially causing a denial of service. However, this appears to be an implementation flaw rather than intentional malice.

## Files reviewed

- `dist/index.cjs.js` (medium): The code performs file system operations and dynamic module loading but shows no clear malicious intent such as data exfiltration, credential harvesting, or obfuscated payloads.
- `dist/index.umd.js` (medium): The package performs expected key-value storage operations but includes file system manipulation (renaming files) outside its scope and uses dynamic require; no clear malicious intent like exfiltration or backdoors was found.
- `dist/index.es.js` (safe): No malicious patterns detected; the code is the legitimate @walletconnect/keyvaluestorage package performing local storage abstraction and migration.
- `dist/react-native/index.js` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
