# @adraffy/ens-normalize@1.11.1 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:01:04.000Z
- Files reviewed: 5
- Findings: 3 low severity findings
- Report: https://security.togoder.click/npm/@adraffy/ens-normalize
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @adraffy/ens-normalize@1.11.1 on Oct 4, 2026. An AI review of 5 source files produced 3 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] Obfuscated data blob

Finding ID: `NPS-226D7D95FDFB`

File: `dist/index-xnf.mjs:1`

The file contains a large base64-encoded compressed blob (COMPRESSED) decoded via custom arithmetic decoding. While this is obfuscated data, the code comments and SHA-256 hash indicate it is the legitimate ENS normalization data from adraffy/ens-normalize.js. No dynamic execution (eval/Function) is performed on the decoded data.

### [low] custom base64 decode

Finding ID: `NPS-68F13974FD9F`

File: `dist/index.cjs`

unsafe_atob implements a custom Base64 decoder. The comment explicitly notes it expects well-formed input and references a security issue. No dynamic evaluation or external input is processed; it decodes only the hardcoded constant.

### [low] compressed data blob

Finding ID: `NPS-881266CE687A`

File: `dist/index.cjs:7`

The file contains large base64-encoded compressed data blobs (COMPRESSED and COMPRESSED$1). These are decoded at runtime via a custom arithmetic decoder (unsafe_atob and decode_arithmetic). While the encoded payloads are opaque, the code references the legitimate open-source ens-normalize.js library, includes source URLs and SHA-256 hashes for verification, and the decoded data is used strictly for Unicode normalization tables (NFD/NFC/decomposition/recomposition/emoji data). No dynamic code execution or network activity is associated with these blobs.

## Files reviewed

- `dist/all.js` (safe): No malicious patterns detected; the code is the legitimate ens-normalize.js library implementing Unicode normalization for Ethereum Name Service (ENS) with embedded compressed data blobs that are self-contained and properly documented.
- `dist/index-xnf.cjs` (safe): No malicious patterns detected; the code is a legitimate ENS name normalization library that decodes an embedded Unicode data blob and contains no network, filesystem, process, or dynamic-evaluation activity.
- `dist/index-xnf.mjs` (safe): The file is the legitimate ENS name normalization library (ens-normalize.js) containing an expected compressed Unicode data table; no malicious patterns such as exfiltration, credential harvesting, or remote code execution were detected.
- `dist/index.cjs` (safe): The file is the ens-normalize library's Unicode normalization logic with embedded compressed data tables; it contains no network, credential, process, or code-execution patterns and appears benign.
- `dist/index.mjs` (safe): No malicious patterns detected; the file is a benign ENS name normalization library with base64-encoded Unicode data and no network, filesystem, process, or dynamic execution behavior.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
