Summary
Togoder Security scanned the npm package @walletconnect/universal-provider@2.21.1 on Oct 4, 2026. An AI review of 2 source files produced 2 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 10
External network request with wallet session data
NPS-4600E82403CE
The getCallStatus and getUserOperationReceipt methods fetch data from externally configured bundler URLs. The bundler URL is constructed from sessionProperties.bundler_url or sessionProperties.bundler_name values that come from the wallet session. This means a malicious or compromised wallet could set an arbitrary bundler_url to exfiltrate user operation data, including the full request parameters, to an attacker-controlled server.
Dynamic URL construction from session properties
NPS-8BDBB63FDA43
The bundler URL is constructed as ${jt}?projectId=${this.client.core.projectId}&chainId=${t}&bundler=${e} where e is sessionProperties.bundler_name. If a malicious wallet sets bundler_name to a crafted value, it could redirect requests (though the base URL is hardcoded to WalletConnect's bundler endpoint). More concerning is the custom bundler_url path which allows arbitrary URLs from session properties.
Network requests
NPS-4477B8210B68
The code makes network requests to walletconnect.org endpoints and custom RPC URLs for blockchain interactions. This is expected functionality for a WalletConnect Universal Provider library and does not appear malicious.
Dynamic code execution
NPS-DD21CE5B5424
No eval, new Function, or similar dynamic code execution patterns detected.
Process spawning
NPS-6CE12B98E07D
No child_process, shell commands, or process spawning detected.
Credential harvesting
NPS-49AE76CC5A9B
No environment variable harvesting or access to sensitive files like .npmrc, .ssh, .aws detected.
Obfuscation
NPS-C85258D490AE
The code is minified but not obfuscated. The structure is consistent with standard bundler output (Rollup) for a legitimate library.
File system manipulation
NPS-C901874766D7
No file system operations outside of package scope detected.
Install-time execution
NPS-FDC828620250
The code is a library module that exports UniversalProvider and default. It does not contain install-time hooks (preinstall/postinstall) as it's a runtime library.
WalletConnect session data persistence and external RPC communication
NPS-9B6057D8DD6C
This is a WalletConnect Universal Provider library that intentionally communicates with external RPC endpoints, relays, and bundlers. It reads projectId from client core and sends it to WalletConnect infrastructure. While this is expected behavior for the library's purpose, it represents significant external communication including session topics, namespaces, and account addresses.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/index.es.js | medium | This is a legitimate WalletConnect Universal Provider library with no obvious malicious code, but it contains design patterns (arbitrary bundler URLs from session properties, external RPC calls) that could be abused if session properties are attacker-controlled. |
| dist/index.cjs.js | safe | The code appears to be a legitimate implementation of the WalletConnect Universal Provider library; no malicious patterns were detected. |
Affected version ranges
None of the 2 scanned versions of @walletconnect/universal-provider are flagged high or critical. The latest scanned version, 2.21.1, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 2.21.0 – 2.21.1 | Needs review | 2 | >=2.21.0 <=2.21.1 | External network request with wallet session data; Dynamic URL construction from session properties |
| 2.19.0 – 2.19.1 | Not scanned | 2 | >=2.19.0 <=2.19.1 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of @walletconnect/universal-provider
Frequently asked questions
Is @walletconnect/universal-provider safe to use?
No confirmed malware was found in @walletconnect/universal-provider@2.21.1, but the review flagged 2 medium, 8 low severity findings for risky patterns worth checking before you rely on it.
Does @walletconnect/universal-provider contain malware?
No malware was identified in @walletconnect/universal-provider@2.21.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @walletconnect/universal-provider checked?
Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @walletconnect/universal-provider together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @walletconnect/universal-provider@2.21.1, cost nothing.