Togoder security

npm package security report

@walletconnect/keyvaluestorage@1.1.1 security report

Risky patterns found that deserve a look.

Needs review Version 1.1.1 Files reviewed 4 Size 13.0 KB Scanned

Summary

Togoder Security scanned the npm package @walletconnect/keyvaluestorage@1.1.1 on Oct 4, 2026. An AI review of 4 source files produced 2 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
6
low

Findings 8

medium

File system manipulation

NPS-0DFC5CEE7A31

The code reads, writes, renames, and checks existence of files/directories using the 'fs' module, including operations on the database file path and migration logic. While these operations appear scoped to the user-configured database path, the migration logic renames files and could potentially interact with files outside the intended package scope if the dbName is crafted maliciously.

dist/index.cjs.js
medium

File system manipulation and renaming

NPS-DE42236E76B2

The code checks for a file at the path constructed from the provided database name (default 'walletconnect.db'), and if it exists but is not a directory, it renames it by appending '.to_migrate'. It later renames that file to append '.migrated'. This manipulates files on disk outside the package scope and could be used to alter or corrupt user data or files.

dist/index.umd.js
low

Dynamic module loading

NPS-04130C3D56CD

The code uses require('unstorage') and require('unstorage/drivers/fs-lite') dynamically inside a try-catch block. Although the module names are hardcoded, this pattern can be used to load arbitrary modules if the dependency is compromised or if the module resolution is altered.

dist/index.cjs.js
low

Code runs at import time

NPS-54C3111109EA

Top-level code executes on import, including the definition of a class that may create file system storage instances and perform migration routines. This behavior is typical for such libraries but warrants caution as it runs automatically when the module is required.

dist/index.cjs.js
low

Storage migration / data access

NPS-0BACC1EF9CE7

The code implements a KeyValueStorage abstraction for WalletConnect v2, migrating data from IndexedDB to localStorage and accessing keys matching walletconnect-related prefixes. This is expected behavior for the @walletconnect/keyvaluestorage package and does not constitute malicious data harvesting.

dist/index.es.js
low

Top-level side effects

NPS-4DF6BE895FB3

The module initializes a KeyValueStorage instance at import time via class instantiation, which triggers storage reads/writes (IndexedDB/localStorage). While this runs on import, it is limited to the package's own storage namespace and WalletConnect-related keys.

dist/index.es.js
low

Dynamic require usage

NPS-A33C106DD768

The code dynamically requires modules ('unstorage' and 'unstorage/drivers/fs-lite') based on runtime conditions rather than static imports. While this is for optional dependency loading, it could be exploited if the module resolution path can be influenced.

dist/index.umd.js
low

Potential denial of service via busy-wait loop

NPS-6DA19ED4E368

The initialize() method uses a setInterval loop that polls every 20ms until this.initialized is true. If initialization never completes, this creates an infinite loop, potentially causing a denial of service. However, this appears to be an implementation flaw rather than intentional malice.

dist/index.umd.js

Files reviewed

FileVerdictWhat the reviewer saw
dist/index.cjs.js medium The code performs file system operations and dynamic module loading but shows no clear malicious intent such as data exfiltration, credential harvesting, or obfuscated payloads.
dist/index.umd.js medium The package performs expected key-value storage operations but includes file system manipulation (renaming files) outside its scope and uses dynamic require; no clear malicious intent like exfiltration or backdoors was found.
dist/index.es.js safe No malicious patterns detected; the code is the legitimate @walletconnect/keyvaluestorage package performing local storage abstraction and migration.
dist/react-native/index.js safe No malicious patterns detected

Frequently asked questions

Is @walletconnect/keyvaluestorage safe to use?

No confirmed malware was found in @walletconnect/keyvaluestorage@1.1.1, but the review flagged 2 medium, 6 low severity findings for risky patterns worth checking before you rely on it.

Does @walletconnect/keyvaluestorage contain malware?

No malware was identified in @walletconnect/keyvaluestorage@1.1.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @walletconnect/keyvaluestorage checked?

Togoder Security downloaded the published npm package and had an AI model read its 4 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @walletconnect/keyvaluestorage together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @walletconnect/keyvaluestorage@1.1.1, cost nothing.

Related security reports