# @walletconnect/logger@2.1.2 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:20:16.000Z
- Files reviewed: 3
- Findings: 1 medium, 2 low severity findings
- Report: https://security.togoder.click/npm/@walletconnect/logger@2.1.2
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @walletconnect/logger@2.1.2 on Oct 4, 2026. An AI review of 3 source files produced 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Data collection and logging

Finding ID: `NPS-92B8CDB8B698`

File: `dist/index.es.js:1`

The module implements a custom logger that collects logs in memory, including potentially sensitive context data (via `context` field in child loggers). The logs can be downloaded as a Blob. While not inherently malicious, this could facilitate data exfiltration if the library is used in a context where logs contain sensitive information and are automatically downloaded or transmitted.

### [low] File download / browser file generation

Finding ID: `NPS-6EB572356ECD`

File: `dist/index.es.js:1`

The `downloadLogsBlobInBrowser` method creates a Blob from collected log data and programmatically triggers a download in the browser via an anchor element. While this is a common logging utility pattern, it could potentially be abused to exfiltrate sensitive data if the logs contain secrets and the download is triggered without user interaction or consent. The filename includes `walletconnect-logs-` and a timestamp.

### [low] Dynamic code execution / eval-like behavior

Finding ID: `NPS-0790D900945F`

File: `dist/index.es.js:1`

The code uses `JSON.parse(e)` on log messages when they are strings. If log messages contain untrusted input, this could lead to parsing errors or potentially prototype pollution, though it's not direct code execution. It is a minor risk.

## Files reviewed

- `dist/index.es.js` (medium): The code is a legitimate logging utility for WalletConnect, but contains patterns that could be misused for data exfiltration through log collection and browser-based download functionality; no direct malicious behavior was detected.
- `dist/index.cjs.js` (safe): No malicious patterns detected; the code is a legitimate logging utility using pino and safe-json with no exfiltration, obfuscation, or dangerous operations.
- `dist/index.umd.js` (safe): No malicious patterns detected; the code is a legitimate logging library with browser and server support, containing no exfiltration, credential harvesting, obfuscation, or other suspicious behavior.

## Version ranges

None of the 2 scanned versions of @walletconnect/logger are flagged high or critical. The latest scanned version, 3.0.2, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 2.1.2 – 3.0.2 (`>=2.1.2 <=3.0.2`): medium (Data collection and logging)

## Scanned versions

- [3.0.2](https://security.togoder.click/npm/@walletconnect/logger@3.0.2): medium, 2026-10-04T21:17:57.000Z
- [2.1.2](https://security.togoder.click/npm/@walletconnect/logger@2.1.2): medium, 2026-10-04T16:20:16.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
