Summary
Togoder Security scanned the npm package @walletconnect/logger@3.0.2 on Oct 4, 2026. An AI review of 3 source files produced 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 3
Browser download trigger
NPS-9801DD6E6252
The code includes a function downloadLogsBlobInBrowser that creates a Blob, an anchor element, and programmatically clicks it to download a file named 'walletconnect-logs-...txt'. While this is a legitimate feature for exporting logs, it could be misused to exfiltrate log data if triggered without user consent. It does not send data to external servers, but it does cause file downloads in the browser.
Global object modification
NPS-F60A5A29107C
The function Le() attempts to define globalThis on Object.prototype using Object.defineProperty with a getter that deletes itself and sets this.globalThis = this. This modifies the global object prototype, which is generally considered bad practice and could potentially interfere with other code or be used for environment detection. However, this appears to be a polyfill for globalThis and not directly malicious.
Dynamic code execution
NPS-4EF5826A15F2
The code uses JSON.parse on log messages in appendToLogs (line: const r=typeof t=='string'?JSON.parse(t).level:t.level). This could execute arbitrary code if the log message is attacker-controlled and contains a malicious payload, but JSON.parse itself does not execute code; it only parses JSON. This is a low risk as it's a standard parsing operation.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/index.es.js | medium | The code is a logging library (Pino-based) with browser log download functionality and a globalThis polyfill; no clear malicious intent, but minor concerns around global prototype modification and potential log data exposure via file download. |
| dist/index.cjs.js | safe | No malicious patterns detected; the code is a bundled logging library (Pino-based) with chunk logging utilities and no exfiltration, credential harvesting, obfuscation, or backdoor behavior. |
| dist/index.umd.js | safe | No malicious patterns detected; the code is a legitimate WalletConnect logger package with pino integration and in-memory log buffering, containing no data exfiltration, credential harvesting, obfuscation, or suspicious network/process activity. |
Affected version ranges
None of the 2 scanned versions of @walletconnect/logger are flagged high or critical. The latest scanned version, 3.0.2, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 2.1.2 โ 3.0.2 | Needs review | 2 | >=2.1.2 <=3.0.2 | Data collection and logging |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of @walletconnect/logger
Frequently asked questions
Is @walletconnect/logger safe to use?
No confirmed malware was found in @walletconnect/logger@3.0.2, but the review flagged 3 low severity findings for risky patterns worth checking before you rely on it.
Does @walletconnect/logger contain malware?
No malware was identified in @walletconnect/logger@3.0.2 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @walletconnect/logger checked?
Togoder Security downloaded the published npm package and had an AI model read its 3 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @walletconnect/logger together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @walletconnect/logger@3.0.2, cost nothing.