# @walletconnect/universal-provider@2.21.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:54:44.000Z
- Files reviewed: 2
- Findings: 2 medium, 8 low severity findings
- Report: https://security.togoder.click/npm/@walletconnect/universal-provider
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @walletconnect/universal-provider@2.21.1 on Oct 4, 2026. An AI review of 2 source files produced 2 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] External network request with wallet session data

Finding ID: `NPS-4600E82403CE`

File: `dist/index.es.js`

The `getCallStatus` and `getUserOperationReceipt` methods fetch data from externally configured bundler URLs. The bundler URL is constructed from `sessionProperties.bundler_url` or `sessionProperties.bundler_name` values that come from the wallet session. This means a malicious or compromised wallet could set an arbitrary `bundler_url` to exfiltrate user operation data, including the full request parameters, to an attacker-controlled server.

### [medium] Dynamic URL construction from session properties

Finding ID: `NPS-8BDBB63FDA43`

File: `dist/index.es.js`

The bundler URL is constructed as `${jt}?projectId=${this.client.core.projectId}&chainId=${t}&bundler=${e}` where `e` is `sessionProperties.bundler_name`. If a malicious wallet sets `bundler_name` to a crafted value, it could redirect requests (though the base URL is hardcoded to WalletConnect's bundler endpoint). More concerning is the custom `bundler_url` path which allows arbitrary URLs from session properties.

### [low] Network requests

Finding ID: `NPS-4477B8210B68`

File: `dist/index.cjs.js`

The code makes network requests to walletconnect.org endpoints and custom RPC URLs for blockchain interactions. This is expected functionality for a WalletConnect Universal Provider library and does not appear malicious.

### [low] Dynamic code execution

Finding ID: `NPS-DD21CE5B5424`

File: `dist/index.cjs.js`

No eval, new Function, or similar dynamic code execution patterns detected.

### [low] Process spawning

Finding ID: `NPS-6CE12B98E07D`

File: `dist/index.cjs.js`

No child_process, shell commands, or process spawning detected.

### [low] Credential harvesting

Finding ID: `NPS-49AE76CC5A9B`

File: `dist/index.cjs.js`

No environment variable harvesting or access to sensitive files like .npmrc, .ssh, .aws detected.

### [low] Obfuscation

Finding ID: `NPS-C85258D490AE`

File: `dist/index.cjs.js`

The code is minified but not obfuscated. The structure is consistent with standard bundler output (Rollup) for a legitimate library.

### [low] File system manipulation

Finding ID: `NPS-C901874766D7`

File: `dist/index.cjs.js`

No file system operations outside of package scope detected.

### [low] Install-time execution

Finding ID: `NPS-FDC828620250`

File: `dist/index.cjs.js`

The code is a library module that exports UniversalProvider and default. It does not contain install-time hooks (preinstall/postinstall) as it's a runtime library.

### [low] WalletConnect session data persistence and external RPC communication

Finding ID: `NPS-9B6057D8DD6C`

File: `dist/index.es.js`

This is a WalletConnect Universal Provider library that intentionally communicates with external RPC endpoints, relays, and bundlers. It reads `projectId` from client core and sends it to WalletConnect infrastructure. While this is expected behavior for the library's purpose, it represents significant external communication including session topics, namespaces, and account addresses.

## Files reviewed

- `dist/index.es.js` (medium): This is a legitimate WalletConnect Universal Provider library with no obvious malicious code, but it contains design patterns (arbitrary bundler URLs from session properties, external RPC calls) that could be abused if session properties are attacker-controlled.
- `dist/index.cjs.js` (safe): The code appears to be a legitimate implementation of the WalletConnect Universal Provider library; no malicious patterns were detected.

## Version ranges

None of the 2 scanned versions of @walletconnect/universal-provider are flagged high or critical. The latest scanned version, 2.21.1, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 2.21.0 – 2.21.1 (`>=2.21.0 <=2.21.1`): medium (External network request with wallet session data +1 more)
- 2.19.0 – 2.19.1 (`>=2.19.0 <=2.19.1`): not scanned

## Scanned versions

- [2.21.1](https://security.togoder.click/npm/@walletconnect/universal-provider@2.21.1): medium, 2026-10-04T16:54:44.000Z
- [2.21.0](https://security.togoder.click/npm/@walletconnect/universal-provider@2.21.0): medium, 2026-10-04T16:54:41.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
