# @walletconnect/logger@3.0.2 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T21:17:57.000Z
- Files reviewed: 3
- Findings: 3 low severity findings
- Report: https://security.togoder.click/npm/@walletconnect/logger
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @walletconnect/logger@3.0.2 on Oct 4, 2026. An AI review of 3 source files produced 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] Browser download trigger

Finding ID: `NPS-9801DD6E6252`

File: `dist/index.es.js`

The code includes a function `downloadLogsBlobInBrowser` that creates a Blob, an anchor element, and programmatically clicks it to download a file named 'walletconnect-logs-...txt'. While this is a legitimate feature for exporting logs, it could be misused to exfiltrate log data if triggered without user consent. It does not send data to external servers, but it does cause file downloads in the browser.

### [low] Global object modification

Finding ID: `NPS-F60A5A29107C`

File: `dist/index.es.js`

The function `Le()` attempts to define `globalThis` on `Object.prototype` using `Object.defineProperty` with a getter that deletes itself and sets `this.globalThis = this`. This modifies the global object prototype, which is generally considered bad practice and could potentially interfere with other code or be used for environment detection. However, this appears to be a polyfill for `globalThis` and not directly malicious.

### [low] Dynamic code execution

Finding ID: `NPS-4EF5826A15F2`

File: `dist/index.es.js`

The code uses `JSON.parse` on log messages in `appendToLogs` (line: `const r=typeof t=='string'?JSON.parse(t).level:t.level`). This could execute arbitrary code if the log message is attacker-controlled and contains a malicious payload, but `JSON.parse` itself does not execute code; it only parses JSON. This is a low risk as it's a standard parsing operation.

## Files reviewed

- `dist/index.es.js` (medium): The code is a logging library (Pino-based) with browser log download functionality and a globalThis polyfill; no clear malicious intent, but minor concerns around global prototype modification and potential log data exposure via file download.
- `dist/index.cjs.js` (safe): No malicious patterns detected; the code is a bundled logging library (Pino-based) with chunk logging utilities and no exfiltration, credential harvesting, obfuscation, or backdoor behavior.
- `dist/index.umd.js` (safe): No malicious patterns detected; the code is a legitimate WalletConnect logger package with pino integration and in-memory log buffering, containing no data exfiltration, credential harvesting, obfuscation, or suspicious network/process activity.

## Version ranges

None of the 2 scanned versions of @walletconnect/logger are flagged high or critical. The latest scanned version, 3.0.2, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 2.1.2 – 3.0.2 (`>=2.1.2 <=3.0.2`): medium (Data collection and logging)

## Scanned versions

- [3.0.2](https://security.togoder.click/npm/@walletconnect/logger@3.0.2): medium, 2026-10-04T21:17:57.000Z
- [2.1.2](https://security.togoder.click/npm/@walletconnect/logger@2.1.2): medium, 2026-10-04T16:20:16.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
