Togoder security

npm package security report

@walletconnect/utils@2.21.1 security report

Risky patterns found that deserve a look.

Needs review Version 2.21.1 Files reviewed 2 Size 348.3 KB Scanned

Summary

Togoder Security scanned the npm package @walletconnect/utils@2.21.1 on Oct 4, 2026. An AI review of 2 source files produced 1 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
8
low

Findings 9

medium

suspicious network requests

NPS-A2D016B5D7DD

The code constructs URLs and opens them via window.open in the openDeeplink function. This is used for deep linking in wallet interactions, which is expected behavior but could be abused to open malicious sites if input is not properly sanitized.

dist/index.cjs.js
low

network request to external service

NPS-118AAABA2CAA

The code makes network requests to an external RPC endpoint (https://rpc.walletconnect.org/v1) via fetch in the isValidEip1271Signature function. This is expected behavior for WalletConnect, but it does send data to a third-party server.

dist/index.cjs.js
low

cryptographic operations

NPS-94A73A2E0D84

The code performs cryptographic operations including key generation, encryption, decryption, and signature verification. These are expected for a WalletConnect library but could be misused if the package is compromised.

dist/index.cjs.js
low

dynamic code execution

NPS-505045921413

The code uses eval-like patterns such as new Function? No, but it does have dynamic code generation through Function constructor? Actually, it uses eval? No, it doesn't. It uses setTimeout, setInterval, and other standard functions. However, it does use new Function? No, it doesn't. It uses Function? No. The code is not obfuscated but is minified. No dynamic code execution beyond standard JavaScript.

dist/index.cjs.js
low

environment variable access

NPS-71AFE470FE20

The code accesses process.env.IS_VITEST to check if running in a test environment. This is a minor environment variable read, not sensitive.

dist/index.cjs.js
low

Network request to external endpoint

NPS-3845C5CC3D50

The code makes fetch requests to a hardcoded external RPC endpoint (https://rpc.walletconnect.org/v1) for EIP-1271 signature verification. This is expected WalletConnect behavior, but the endpoint is external and could be a data collection point.

dist/index.es.js
low

Environment/browser data access

NPS-DE36EC5A74DF

The code accesses window metadata, navigator, location, localStorage, and generates device/browser fingerprinting information (OS, browser name, version, host, app ID). This data is appended to WebSocket relay URLs via query parameters (auth, ua, projectId, packageName, bundleId). This is standard WalletConnect relay metadata but constitutes device fingerprinting.

dist/index.es.js
low

Dynamic URL construction with external input

NPS-A210AC518847

Various functions construct URLs from external input including metadata URLs, deep links, and relay URLs. The openDeeplink/handleDeeplinkRedirect functions open URLs in new windows with noreferrer noopener, which is safe, but the URL construction uses external input.

dist/index.es.js
low

Cryptographic key material handling

NPS-07DD634A349F

The code imports and uses cryptographic primitives including X25519 key exchange, ChaCha20-Poly1305 encryption, SHA-256, and secp256k1/P-256 signature verification. It generates random keys and handles encrypted envelopes. This is expected for a WalletConnect library but the presence of key generation and encryption/decryption functions warrants review.

dist/index.es.js

Files reviewed

FileVerdictWhat the reviewer saw
dist/index.cjs.js medium The code is a legitimate WalletConnect library with expected cryptographic and network operations, but it includes deep linking and network requests that could pose risks if the package is compromised.
dist/index.es.js medium This is a legitimate WalletConnect utilities library (@walletconnect/utils) that handles cryptographic operations, session management, and relay URL construction; no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, wallet draining, or backdoors were detected, though it does perform expected network requests and device fingerprinting for WalletConnect relay functionality.

Affected version ranges

None of the 3 scanned versions of @walletconnect/utils are flagged high or critical. The latest scanned version, 2.25.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

2.19.02.25.0
VersionsVerdictCountRangeTop findings
2.21.0 – 2.25.0 Needs review 3 >=2.21.0 <=2.25.0 suspicious network requests
2.19.0 – 2.19.1 Not scanned 2 >=2.19.0 <=2.19.1

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of @walletconnect/utils

VersionVerdictFilesScanned
2.25.0 Needs review 2 Oct 4, 2026
2.21.1 Needs review 2 Oct 4, 2026
2.21.0 Needs review 2 Oct 4, 2026

Frequently asked questions

Is @walletconnect/utils safe to use?

No confirmed malware was found in @walletconnect/utils@2.21.1, but the review flagged 1 medium, 8 low severity findings for risky patterns worth checking before you rely on it.

Does @walletconnect/utils contain malware?

No malware was identified in @walletconnect/utils@2.21.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @walletconnect/utils checked?

Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @walletconnect/utils together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @walletconnect/utils@2.21.1, cost nothing.

Related security reports