Summary
Togoder Security scanned the npm package @walletconnect/sign-client@2.21.0 on Oct 4, 2026. An AI review of 2 source files produced 1 medium, 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 3
Deeplink handling
NPS-E10C3433B41C
The code reads and processes deep links via getDeepLink and handleDeeplinkRedirect, which can redirect users to external apps. This is a standard WalletConnect feature but could be abused for phishing if the input is not properly validated.
External network communication
NPS-45B7E72BD9F2
The package makes network connections to a hardcoded WebSocket relay URL 'wss://relay.walletconnect.org' and potentially other external services. This is expected for WalletConnect, but it means data (session metadata, encrypted payloads) is sent externally.
Dynamic code execution
NPS-9C0BD34D3426
The code uses global.Linking.openURL to open URLs dynamically, which could be exploited if an attacker controls the URL. However, this is part of the intended link-mode feature and URLs are constructed from internal data.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/index.cjs.js | medium | This is the official WalletConnect SignClient library. While it performs external network communication and dynamic URL opening as part of its intended functionality, no malicious patterns such as credential harvesting, obfuscation, backdoors, or unauthorized file system access were detected. |
| dist/index.es.js | safe | No malicious patterns detected; this is a legitimate WalletConnect SignClient library with standard cryptographic and relay communication code. |
Affected version ranges
None of the 2 scanned versions of @walletconnect/sign-client are flagged high or critical. The latest scanned version, 2.21.1, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 2.21.0 – 2.21.1 | Needs review | 2 | >=2.21.0 <=2.21.1 | Deeplink handling |
| 2.19.0 – 2.19.1 | Not scanned | 2 | >=2.19.0 <=2.19.1 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of @walletconnect/sign-client
Frequently asked questions
Is @walletconnect/sign-client safe to use?
No confirmed malware was found in @walletconnect/sign-client@2.21.0, but the review flagged 1 medium, 2 low severity findings for risky patterns worth checking before you rely on it.
Does @walletconnect/sign-client contain malware?
No malware was identified in @walletconnect/sign-client@2.21.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @walletconnect/sign-client checked?
Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @walletconnect/sign-client together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @walletconnect/sign-client@2.21.0, cost nothing.