# @walletconnect/utils@2.21.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:54:43.000Z
- Files reviewed: 2
- Findings: 1 medium, 8 low severity findings
- Report: https://security.togoder.click/npm/@walletconnect/utils@2.21.1
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @walletconnect/utils@2.21.1 on Oct 4, 2026. An AI review of 2 source files produced 1 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] suspicious network requests

Finding ID: `NPS-A2D016B5D7DD`

File: `dist/index.cjs.js`

The code constructs URLs and opens them via window.open in the openDeeplink function. This is used for deep linking in wallet interactions, which is expected behavior but could be abused to open malicious sites if input is not properly sanitized.

### [low] network request to external service

Finding ID: `NPS-118AAABA2CAA`

File: `dist/index.cjs.js`

The code makes network requests to an external RPC endpoint (https://rpc.walletconnect.org/v1) via fetch in the isValidEip1271Signature function. This is expected behavior for WalletConnect, but it does send data to a third-party server.

### [low] cryptographic operations

Finding ID: `NPS-94A73A2E0D84`

File: `dist/index.cjs.js`

The code performs cryptographic operations including key generation, encryption, decryption, and signature verification. These are expected for a WalletConnect library but could be misused if the package is compromised.

### [low] dynamic code execution

Finding ID: `NPS-505045921413`

File: `dist/index.cjs.js`

The code uses eval-like patterns such as new Function? No, but it does have dynamic code generation through Function constructor? Actually, it uses eval? No, it doesn't. It uses setTimeout, setInterval, and other standard functions. However, it does use `new Function`? No, it doesn't. It uses `Function`? No. The code is not obfuscated but is minified. No dynamic code execution beyond standard JavaScript.

### [low] environment variable access

Finding ID: `NPS-71AFE470FE20`

File: `dist/index.cjs.js`

The code accesses process.env.IS_VITEST to check if running in a test environment. This is a minor environment variable read, not sensitive.

### [low] Network request to external endpoint

Finding ID: `NPS-3845C5CC3D50`

File: `dist/index.es.js`

The code makes fetch requests to a hardcoded external RPC endpoint (https://rpc.walletconnect.org/v1) for EIP-1271 signature verification. This is expected WalletConnect behavior, but the endpoint is external and could be a data collection point.

### [low] Environment/browser data access

Finding ID: `NPS-DE36EC5A74DF`

File: `dist/index.es.js`

The code accesses window metadata, navigator, location, localStorage, and generates device/browser fingerprinting information (OS, browser name, version, host, app ID). This data is appended to WebSocket relay URLs via query parameters (auth, ua, projectId, packageName, bundleId). This is standard WalletConnect relay metadata but constitutes device fingerprinting.

### [low] Dynamic URL construction with external input

Finding ID: `NPS-A210AC518847`

File: `dist/index.es.js`

Various functions construct URLs from external input including metadata URLs, deep links, and relay URLs. The openDeeplink/handleDeeplinkRedirect functions open URLs in new windows with noreferrer noopener, which is safe, but the URL construction uses external input.

### [low] Cryptographic key material handling

Finding ID: `NPS-07DD634A349F`

File: `dist/index.es.js`

The code imports and uses cryptographic primitives including X25519 key exchange, ChaCha20-Poly1305 encryption, SHA-256, and secp256k1/P-256 signature verification. It generates random keys and handles encrypted envelopes. This is expected for a WalletConnect library but the presence of key generation and encryption/decryption functions warrants review.

## Files reviewed

- `dist/index.cjs.js` (medium): The code is a legitimate WalletConnect library with expected cryptographic and network operations, but it includes deep linking and network requests that could pose risks if the package is compromised.
- `dist/index.es.js` (medium): This is a legitimate WalletConnect utilities library (@walletconnect/utils) that handles cryptographic operations, session management, and relay URL construction; no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, wallet draining, or backdoors were detected, though it does perform expected network requests and device fingerprinting for WalletConnect relay functionality.

## Version ranges

None of the 3 scanned versions of @walletconnect/utils are flagged high or critical. The latest scanned version, 2.25.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 2.21.0 – 2.25.0 (`>=2.21.0 <=2.25.0`): medium (suspicious network requests)
- 2.19.0 – 2.19.1 (`>=2.19.0 <=2.19.1`): not scanned

## Scanned versions

- [2.25.0](https://security.togoder.click/npm/@walletconnect/utils@2.25.0): medium, 2026-10-04T21:17:50.000Z
- [2.21.1](https://security.togoder.click/npm/@walletconnect/utils@2.21.1): medium, 2026-10-04T16:54:43.000Z
- [2.21.0](https://security.togoder.click/npm/@walletconnect/utils@2.21.0): medium, 2026-10-04T16:54:43.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
