Togoder security

npm package security report

@walletconnect/sign-client npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 2.21.1 Files reviewed 2 Size 528.3 KB Scanned

Summary

Togoder Security scanned the npm package @walletconnect/sign-client@2.21.1 on Oct 4, 2026. An AI review of 2 source files produced 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
2
low

Findings 3

medium

Deeplink handling

NPS-E10C3433B41C

The code reads and processes deep links via getDeepLink and handleDeeplinkRedirect, which can redirect users to external apps. This is a standard WalletConnect feature but could be abused for phishing if the input is not properly validated.

dist/index.cjs.js
low

External network communication

NPS-45B7E72BD9F2

The package makes network connections to a hardcoded WebSocket relay URL 'wss://relay.walletconnect.org' and potentially other external services. This is expected for WalletConnect, but it means data (session metadata, encrypted payloads) is sent externally.

dist/index.cjs.js
low

Dynamic code execution

NPS-9C0BD34D3426

The code uses global.Linking.openURL to open URLs dynamically, which could be exploited if an attacker controls the URL. However, this is part of the intended link-mode feature and URLs are constructed from internal data.

dist/index.cjs.js

Files reviewed

FileVerdictWhat the reviewer saw
dist/index.cjs.js medium This is the official WalletConnect SignClient library. While it performs external network communication and dynamic URL opening as part of its intended functionality, no malicious patterns such as credential harvesting, obfuscation, backdoors, or unauthorized file system access were detected.
dist/index.es.js safe No malicious patterns detected; this is a legitimate WalletConnect SignClient library with standard cryptographic and relay communication code.

Affected version ranges

None of the 2 scanned versions of @walletconnect/sign-client are flagged high or critical. The latest scanned version, 2.21.1, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

2.19.02.21.1
VersionsVerdictCountRangeTop findings
2.21.0 – 2.21.1 Needs review 2 >=2.21.0 <=2.21.1 Deeplink handling
2.19.0 – 2.19.1 Not scanned 2 >=2.19.0 <=2.19.1

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of @walletconnect/sign-client

VersionVerdictFilesScanned
2.21.1 Needs review 2 Oct 4, 2026
2.21.0 Needs review 2 Oct 4, 2026

Frequently asked questions

Is @walletconnect/sign-client safe to use?

No confirmed malware was found in @walletconnect/sign-client@2.21.1, but the review flagged 1 medium, 2 low severity findings for risky patterns worth checking before you rely on it.

Does @walletconnect/sign-client contain malware?

No malware was identified in @walletconnect/sign-client@2.21.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @walletconnect/sign-client checked?

Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @walletconnect/sign-client together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @walletconnect/sign-client@2.21.1, cost nothing.

Related security reports