Summary
Togoder Security scanned the npm package @walletconnect/keyvaluestorage@1.1.1 on Oct 4, 2026. An AI review of 4 source files produced 2 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 8
File system manipulation
NPS-0DFC5CEE7A31
The code reads, writes, renames, and checks existence of files/directories using the 'fs' module, including operations on the database file path and migration logic. While these operations appear scoped to the user-configured database path, the migration logic renames files and could potentially interact with files outside the intended package scope if the dbName is crafted maliciously.
File system manipulation and renaming
NPS-DE42236E76B2
The code checks for a file at the path constructed from the provided database name (default 'walletconnect.db'), and if it exists but is not a directory, it renames it by appending '.to_migrate'. It later renames that file to append '.migrated'. This manipulates files on disk outside the package scope and could be used to alter or corrupt user data or files.
Dynamic module loading
NPS-04130C3D56CD
The code uses require('unstorage') and require('unstorage/drivers/fs-lite') dynamically inside a try-catch block. Although the module names are hardcoded, this pattern can be used to load arbitrary modules if the dependency is compromised or if the module resolution is altered.
Code runs at import time
NPS-54C3111109EA
Top-level code executes on import, including the definition of a class that may create file system storage instances and perform migration routines. This behavior is typical for such libraries but warrants caution as it runs automatically when the module is required.
Storage migration / data access
NPS-0BACC1EF9CE7
The code implements a KeyValueStorage abstraction for WalletConnect v2, migrating data from IndexedDB to localStorage and accessing keys matching walletconnect-related prefixes. This is expected behavior for the @walletconnect/keyvaluestorage package and does not constitute malicious data harvesting.
Top-level side effects
NPS-4DF6BE895FB3
The module initializes a KeyValueStorage instance at import time via class instantiation, which triggers storage reads/writes (IndexedDB/localStorage). While this runs on import, it is limited to the package's own storage namespace and WalletConnect-related keys.
Dynamic require usage
NPS-A33C106DD768
The code dynamically requires modules ('unstorage' and 'unstorage/drivers/fs-lite') based on runtime conditions rather than static imports. While this is for optional dependency loading, it could be exploited if the module resolution path can be influenced.
Potential denial of service via busy-wait loop
NPS-6DA19ED4E368
The initialize() method uses a setInterval loop that polls every 20ms until this.initialized is true. If initialization never completes, this creates an infinite loop, potentially causing a denial of service. However, this appears to be an implementation flaw rather than intentional malice.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/index.cjs.js | medium | The code performs file system operations and dynamic module loading but shows no clear malicious intent such as data exfiltration, credential harvesting, or obfuscated payloads. |
| dist/index.umd.js | medium | The package performs expected key-value storage operations but includes file system manipulation (renaming files) outside its scope and uses dynamic require; no clear malicious intent like exfiltration or backdoors was found. |
| dist/index.es.js | safe | No malicious patterns detected; the code is the legitimate @walletconnect/keyvaluestorage package performing local storage abstraction and migration. |
| dist/react-native/index.js | safe | No malicious patterns detected |
Frequently asked questions
Is @walletconnect/keyvaluestorage safe to use?
No confirmed malware was found in @walletconnect/keyvaluestorage@1.1.1, but the review flagged 2 medium, 6 low severity findings for risky patterns worth checking before you rely on it.
Does @walletconnect/keyvaluestorage contain malware?
No malware was identified in @walletconnect/keyvaluestorage@1.1.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @walletconnect/keyvaluestorage checked?
Togoder Security downloaded the published npm package and had an AI model read its 4 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @walletconnect/keyvaluestorage together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @walletconnect/keyvaluestorage@1.1.1, cost nothing.