Togoder security

npm package security report

@walletconnect/universal-provider@2.21.1 security report

Risky patterns found that deserve a look.

Needs review Version 2.21.1 Files reviewed 2 Size 535.5 KB Scanned

Summary

Togoder Security scanned the npm package @walletconnect/universal-provider@2.21.1 on Oct 4, 2026. An AI review of 2 source files produced 2 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
8
low

Findings 10

medium

External network request with wallet session data

NPS-4600E82403CE

The getCallStatus and getUserOperationReceipt methods fetch data from externally configured bundler URLs. The bundler URL is constructed from sessionProperties.bundler_url or sessionProperties.bundler_name values that come from the wallet session. This means a malicious or compromised wallet could set an arbitrary bundler_url to exfiltrate user operation data, including the full request parameters, to an attacker-controlled server.

dist/index.es.js
medium

Dynamic URL construction from session properties

NPS-8BDBB63FDA43

The bundler URL is constructed as ${jt}?projectId=${this.client.core.projectId}&chainId=${t}&bundler=${e} where e is sessionProperties.bundler_name. If a malicious wallet sets bundler_name to a crafted value, it could redirect requests (though the base URL is hardcoded to WalletConnect's bundler endpoint). More concerning is the custom bundler_url path which allows arbitrary URLs from session properties.

dist/index.es.js
low

Network requests

NPS-4477B8210B68

The code makes network requests to walletconnect.org endpoints and custom RPC URLs for blockchain interactions. This is expected functionality for a WalletConnect Universal Provider library and does not appear malicious.

dist/index.cjs.js
low

Dynamic code execution

NPS-DD21CE5B5424

No eval, new Function, or similar dynamic code execution patterns detected.

dist/index.cjs.js
low

Process spawning

NPS-6CE12B98E07D

No child_process, shell commands, or process spawning detected.

dist/index.cjs.js
low

Credential harvesting

NPS-49AE76CC5A9B

No environment variable harvesting or access to sensitive files like .npmrc, .ssh, .aws detected.

dist/index.cjs.js
low

Obfuscation

NPS-C85258D490AE

The code is minified but not obfuscated. The structure is consistent with standard bundler output (Rollup) for a legitimate library.

dist/index.cjs.js
low

File system manipulation

NPS-C901874766D7

No file system operations outside of package scope detected.

dist/index.cjs.js
low

Install-time execution

NPS-FDC828620250

The code is a library module that exports UniversalProvider and default. It does not contain install-time hooks (preinstall/postinstall) as it's a runtime library.

dist/index.cjs.js
low

WalletConnect session data persistence and external RPC communication

NPS-9B6057D8DD6C

This is a WalletConnect Universal Provider library that intentionally communicates with external RPC endpoints, relays, and bundlers. It reads projectId from client core and sends it to WalletConnect infrastructure. While this is expected behavior for the library's purpose, it represents significant external communication including session topics, namespaces, and account addresses.

dist/index.es.js

Files reviewed

FileVerdictWhat the reviewer saw
dist/index.es.js medium This is a legitimate WalletConnect Universal Provider library with no obvious malicious code, but it contains design patterns (arbitrary bundler URLs from session properties, external RPC calls) that could be abused if session properties are attacker-controlled.
dist/index.cjs.js safe The code appears to be a legitimate implementation of the WalletConnect Universal Provider library; no malicious patterns were detected.

Affected version ranges

None of the 2 scanned versions of @walletconnect/universal-provider are flagged high or critical. The latest scanned version, 2.21.1, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

2.19.02.21.1
VersionsVerdictCountRangeTop findings
2.21.0 – 2.21.1 Needs review 2 >=2.21.0 <=2.21.1 External network request with wallet session data; Dynamic URL construction from session properties
2.19.0 – 2.19.1 Not scanned 2 >=2.19.0 <=2.19.1

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of @walletconnect/universal-provider

VersionVerdictFilesScanned
2.21.1 Needs review 2 Oct 4, 2026
2.21.0 Needs review 2 Oct 4, 2026

Frequently asked questions

Is @walletconnect/universal-provider safe to use?

No confirmed malware was found in @walletconnect/universal-provider@2.21.1, but the review flagged 2 medium, 8 low severity findings for risky patterns worth checking before you rely on it.

Does @walletconnect/universal-provider contain malware?

No malware was identified in @walletconnect/universal-provider@2.21.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @walletconnect/universal-provider checked?

Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @walletconnect/universal-provider together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @walletconnect/universal-provider@2.21.1, cost nothing.

Related security reports