Summary
Togoder Security scanned the npm package @walletconnect/utils@2.21.0 on Oct 4, 2026. An AI review of 2 source files produced 1 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 9
suspicious network requests
NPS-A2D016B5D7DD
The code constructs URLs and opens them via window.open in the openDeeplink function. This is used for deep linking in wallet interactions, which is expected behavior but could be abused to open malicious sites if input is not properly sanitized.
network request to external service
NPS-118AAABA2CAA
The code makes network requests to an external RPC endpoint (https://rpc.walletconnect.org/v1) via fetch in the isValidEip1271Signature function. This is expected behavior for WalletConnect, but it does send data to a third-party server.
cryptographic operations
NPS-94A73A2E0D84
The code performs cryptographic operations including key generation, encryption, decryption, and signature verification. These are expected for a WalletConnect library but could be misused if the package is compromised.
dynamic code execution
NPS-505045921413
The code uses eval-like patterns such as new Function? No, but it does have dynamic code generation through Function constructor? Actually, it uses eval? No, it doesn't. It uses setTimeout, setInterval, and other standard functions. However, it does use new Function? No, it doesn't. It uses Function? No. The code is not obfuscated but is minified. No dynamic code execution beyond standard JavaScript.
environment variable access
NPS-71AFE470FE20
The code accesses process.env.IS_VITEST to check if running in a test environment. This is a minor environment variable read, not sensitive.
Network request to external endpoint
NPS-3845C5CC3D50
The code makes fetch requests to a hardcoded external RPC endpoint (https://rpc.walletconnect.org/v1) for EIP-1271 signature verification. This is expected WalletConnect behavior, but the endpoint is external and could be a data collection point.
Environment/browser data access
NPS-DE36EC5A74DF
The code accesses window metadata, navigator, location, localStorage, and generates device/browser fingerprinting information (OS, browser name, version, host, app ID). This data is appended to WebSocket relay URLs via query parameters (auth, ua, projectId, packageName, bundleId). This is standard WalletConnect relay metadata but constitutes device fingerprinting.
Dynamic URL construction with external input
NPS-A210AC518847
Various functions construct URLs from external input including metadata URLs, deep links, and relay URLs. The openDeeplink/handleDeeplinkRedirect functions open URLs in new windows with noreferrer noopener, which is safe, but the URL construction uses external input.
Cryptographic key material handling
NPS-07DD634A349F
The code imports and uses cryptographic primitives including X25519 key exchange, ChaCha20-Poly1305 encryption, SHA-256, and secp256k1/P-256 signature verification. It generates random keys and handles encrypted envelopes. This is expected for a WalletConnect library but the presence of key generation and encryption/decryption functions warrants review.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/index.cjs.js | medium | The code is a legitimate WalletConnect library with expected cryptographic and network operations, but it includes deep linking and network requests that could pose risks if the package is compromised. |
| dist/index.es.js | medium | This is a legitimate WalletConnect utilities library (@walletconnect/utils) that handles cryptographic operations, session management, and relay URL construction; no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, wallet draining, or backdoors were detected, though it does perform expected network requests and device fingerprinting for WalletConnect relay functionality. |
Affected version ranges
None of the 3 scanned versions of @walletconnect/utils are flagged high or critical. The latest scanned version, 2.25.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 2.21.0 – 2.25.0 | Needs review | 3 | >=2.21.0 <=2.25.0 | suspicious network requests |
| 2.19.0 – 2.19.1 | Not scanned | 2 | >=2.19.0 <=2.19.1 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of @walletconnect/utils
Frequently asked questions
Is @walletconnect/utils safe to use?
No confirmed malware was found in @walletconnect/utils@2.21.0, but the review flagged 1 medium, 8 low severity findings for risky patterns worth checking before you rely on it.
Does @walletconnect/utils contain malware?
No malware was identified in @walletconnect/utils@2.21.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @walletconnect/utils checked?
Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @walletconnect/utils together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @walletconnect/utils@2.21.0, cost nothing.