Summary
Togoder Security scanned the npm package @adraffy/ens-normalize@1.11.1 on Oct 4, 2026. An AI review of 5 source files produced 3 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings 3
Obfuscated data blob
NPS-226D7D95FDFB
The file contains a large base64-encoded compressed blob (COMPRESSED) decoded via custom arithmetic decoding. While this is obfuscated data, the code comments and SHA-256 hash indicate it is the legitimate ENS normalization data from adraffy/ens-normalize.js. No dynamic execution (eval/Function) is performed on the decoded data.
custom base64 decode
NPS-68F13974FD9F
unsafe_atob implements a custom Base64 decoder. The comment explicitly notes it expects well-formed input and references a security issue. No dynamic evaluation or external input is processed; it decodes only the hardcoded constant.
compressed data blob
NPS-881266CE687A
The file contains large base64-encoded compressed data blobs (COMPRESSED and COMPRESSED$1). These are decoded at runtime via a custom arithmetic decoder (unsafe_atob and decode_arithmetic). While the encoded payloads are opaque, the code references the legitimate open-source ens-normalize.js library, includes source URLs and SHA-256 hashes for verification, and the decoded data is used strictly for Unicode normalization tables (NFD/NFC/decomposition/recomposition/emoji data). No dynamic code execution or network activity is associated with these blobs.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/all.js | safe | No malicious patterns detected; the code is the legitimate ens-normalize.js library implementing Unicode normalization for Ethereum Name Service (ENS) with embedded compressed data blobs that are self-contained and properly documented. |
| dist/index-xnf.cjs | safe | No malicious patterns detected; the code is a legitimate ENS name normalization library that decodes an embedded Unicode data blob and contains no network, filesystem, process, or dynamic-evaluation activity. |
| dist/index-xnf.mjs | safe | The file is the legitimate ENS name normalization library (ens-normalize.js) containing an expected compressed Unicode data table; no malicious patterns such as exfiltration, credential harvesting, or remote code execution were detected. |
| dist/index.cjs | safe | The file is the ens-normalize library's Unicode normalization logic with embedded compressed data tables; it contains no network, credential, process, or code-execution patterns and appears benign. |
| dist/index.mjs | safe | No malicious patterns detected; the file is a benign ENS name normalization library with base64-encoded Unicode data and no network, filesystem, process, or dynamic execution behavior. |
Scanned versions of @adraffy/ens-normalize
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 1.11.1 | No issues | 5 | Oct 4, 2026 |
Frequently asked questions
Is @adraffy/ens-normalize safe to use?
Our AI source review of @adraffy/ens-normalize@1.11.1 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does @adraffy/ens-normalize contain malware?
No malware was identified in @adraffy/ens-normalize@1.11.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @adraffy/ens-normalize checked?
Togoder Security downloaded the published npm package and had an AI model read its 5 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @adraffy/ens-normalize together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @adraffy/ens-normalize@1.11.1, cost nothing.