# @walletconnect/utils@2.25.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T21:17:50.000Z
- Files reviewed: 2
- Findings: 3 low severity findings
- Report: https://security.togoder.click/npm/@walletconnect/utils@2.25.0
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @walletconnect/utils@2.25.0 on Oct 4, 2026. An AI review of 2 source files produced 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] Network request

Finding ID: `NPS-B3A080E103A8`

File: `dist/index.cjs`

The code contains an EIP-1271 signature verification function that makes a POST request to an external RPC endpoint (default `https://rpc.walletconnect.org/v1`) using the global `fetch` API. This is a legitimate network call for blockchain interaction, not data exfiltration, but it does send user-provided signature data to an external server.

### [low] Dynamic code execution

Finding ID: `NPS-820226249DEF`

File: `dist/index.cjs`

The code uses `window.open` with computed URLs for deeplink handling, which could be abused for open redirect if inputs are not properly validated. However, the URLs are constructed from trusted parameters and the function includes checks for same-origin and Telegram-specific handling.

### [low] Cryptographic operations

Finding ID: `NPS-DC0B96EE2FA3`

File: `dist/index.cjs`

The file includes extensive cryptographic utilities (key generation, encryption/decryption, signature verification, hashing) for wallet connectivity. These are expected for a WalletConnect library and do not appear to be malicious, but they handle sensitive key material. No evidence of key exfiltration or address rewriting.

## Files reviewed

- `dist/index.cjs` (medium): This appears to be a legitimate WalletConnect utility library with standard cryptographic and network operations, but it does make external network requests and handles sensitive cryptographic material, warranting caution.
- `dist/index.js` (safe): This is the legitimate WalletConnect Core utility library containing only standard cryptographic helper functions, validation logic, and browser/environment detection; no malicious patterns such as data exfiltration, obfuscated payloads, dynamic code execution, or backdoor installation were detected.

## Version ranges

None of the 3 scanned versions of @walletconnect/utils are flagged high or critical. The latest scanned version, 2.25.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 2.21.0 – 2.25.0 (`>=2.21.0 <=2.25.0`): medium (suspicious network requests)
- 2.19.0 – 2.19.1 (`>=2.19.0 <=2.19.1`): not scanned

## Scanned versions

- [2.25.0](https://security.togoder.click/npm/@walletconnect/utils@2.25.0): medium, 2026-10-04T21:17:50.000Z
- [2.21.1](https://security.togoder.click/npm/@walletconnect/utils@2.21.1): medium, 2026-10-04T16:54:43.000Z
- [2.21.0](https://security.togoder.click/npm/@walletconnect/utils@2.21.0): medium, 2026-10-04T16:54:43.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
