@walletconnect/signer-connection
Signer Connection for WalletConnect Protocol
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:dist/index.umd.js | AI (source-diff): Bundled UMD build output, not true obfuscation; no malicious behavior found. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Stale publisher change, long-standing, part of official WalletConnect org. | ai | |
| source-diff | obfuscated-file:dist/index.cjs | AI (source-diff): Standard rollup minified bundle for WalletConnect SDK; content is readable WalletConnect logic, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/index.js | AI (source-diff): Standard rollup ESM bundle; same pattern as dist/index.cjs, no malicious content. | ai | |
| phantom-deps | phantom-dep:uint8arrays | AI (phantom-deps): uint8arrays is a declared dependency used transitively; phantom-dep heuristic false positive for this package. | ai |
Versions (showing 56 of 56)
| Version | Deps | Published |
|---|---|---|
| 2.23.10 | 7 / 0 | |
| 2.23.9 | 7 / 0 | |
| 2.23.8 | 7 / 0 | |
| 2.23.7 | 7 / 0 | |
| 2.23.6 | 7 / 0 | |
| 2.23.5 | 7 / 0 | |
| 2.23.4 | 7 / 0 | |
| 2.23.3 | 7 / 0 | |
| 2.23.2 | 7 / 0 | |
| 2.23.1 | 7 / 0 | |
| 2.23.0 | 7 / 0 | |
| 2.22.4 | 7 / 0 | |
| 2.22.3 | 7 / 0 | |
| 2.22.2 | 7 / 0 | |
| 2.22.1 | 7 / 0 | |
| 2.22.0 | 7 / 0 | |
| 2.21.10 | 7 / 0 | |
| 2.21.9 | 7 / 0 | |
| 2.21.8 | 7 / 0 | |
| 2.21.7 | 7 / 0 | |
| 2.21.6 | 7 / 0 | |
| 2.21.5 | 7 / 0 | |
| 2.21.4 | 7 / 0 | |
| 2.21.3 | 7 / 0 | |
| 2.21.2 | 7 / 0 | |
| 2.21.1 | 7 / 0 | |
| 2.21.0 | 7 / 0 | |
| 2.20.3 | 7 / 0 | |
| 2.20.2 | 7 / 0 | |
| 2.20.1 | 7 / 0 | |
| 2.20.0 | 7 / 0 | |
| 2.19.4 | 7 / 0 | |
| 2.19.3 | 7 / 0 | |
| 2.19.2 | 7 / 0 | |
| 2.19.1 | 7 / 0 | |
| 2.19.0 | 7 / 0 | |
| 2.18.1 | 7 / 0 | |
| 2.18.0 | 7 / 0 | |
| 2.17.5 | 7 / 0 | |
| 2.17.4 | 7 / 0 | |
| 2.17.3 | 7 / 0 | |
| 2.17.2 | 7 / 0 | |
| 2.17.1 | 7 / 0 | |
| 2.17.0 | 7 / 0 | |
| 2.16.3 | 7 / 0 | |
| 2.16.2 | 7 / 0 | |
| 2.16.1 | 7 / 0 | |
| 2.16.0 | 7 / 0 | |
| 2.15.3 | 7 / 0 | |
| 2.15.2 | 7 / 0 | |
| 2.15.1 | 7 / 0 | |
| 2.15.0 | 7 / 0 | |
| 2.14.0 | 7 / 0 | |
| 2.13.3 | 7 / 0 | |
| 2.13.2 | 7 / 0 | |
| 2.13.1 | 7 / 0 |
v2.20.3
2 findingsThis version was published by a different npm account (reown-npm-org) than the most recent previously approved version (gancho_walletconnect) on 2025-05-20. It has since remained available on npm for 424 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.20.2
2 findingsThis version was published by a different npm account (reown-npm-org) than the most recent previously approved version (gancho_walletconnect) on 2025-05-01. It has since remained available on npm for 443 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.20.1
2 findingsThis version was published by a different npm account (reown-npm-org) than the most recent previously approved version (gancho_walletconnect) on 2025-05-01. It has since remained available on npm for 443 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.20.0
2 findingsThis version was published by a different npm account (reown-npm-org) than the most recent previously approved version (gancho_walletconnect) on 2025-04-15. It has since remained available on npm for 459 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.19.4
2 findingsThis version was published by a different npm account (reown-npm-org) than the most recent previously approved version (gancho_walletconnect) on 2025-04-15. It has since remained available on npm for 459 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.19.3
2 findingsThis version was published by a different npm account (reown-npm-org) than the most recent previously approved version (gancho_walletconnect) on 2025-04-15. It has since remained available on npm for 459 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.19.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.19.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.19.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.18.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.18.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.17.5
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.17.4
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.17.3
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.17.2
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.17.1
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.17.0
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.16.3
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.16.2
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.16.1
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.16.0
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.15.3
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.15.2
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.15.1
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.15.0
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.14.0
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.3
3 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
This version was published by a different npm account (lukaisailovic) than the most recent previously approved version (gancho_walletconnect) on 2024-06-14. It has since remained available on npm for 764 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.2
3 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bkrem) than the most recent previously approved version (gancho_walletconnect) on 2024-06-10, but bkrem is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.13.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.