# @ethereumjs/util@9.1.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T21:27:35.000Z
- Files reviewed: 63
- Findings: 2 medium, 5 low severity findings
- Report: https://security.togoder.click/npm/@ethereumjs/util
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @ethereumjs/util@9.1.0 on Oct 4, 2026. An AI review of 63 source files produced 2 medium, 5 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Missing response validation / trust of arbitrary provider

Finding ID: `NPS-3E0D75A3594E`

File: `src/provider.ts:30`

The code explicitly documents that no parameter or response validation is done, and there is a TODO noting that json.error is not checked. The raw result from an untrusted remote provider is returned directly to the caller. In a wallet or web3 context, a malicious or MITM'd RPC endpoint could return forged data (e.g., fabricated balances, blocks, or transaction results) that gets propagated to downstream consumers.

### [medium] SSRF / unrestricted outbound request

Finding ID: `NPS-526AE252327A`

File: `src/provider.ts:33`

fetchFromProvider takes an arbitrary URL and performs a POST request to it without any allowlist, scheme validation, or host restriction. If this function is invoked with user-controlled input (or if getProvider resolves a URL from an attacker-influenced provider object), it can be abused for Server-Side Request Forgery against internal services (e.g., cloud metadata endpoints like 169.254.169.254, localhost services, or internal APIs).

### [low] suspicious network request

Finding ID: `NPS-6DBBEDD84C22`

File: `dist/esm/provider.js:22`

fetchFromProvider performs an outbound HTTP request to an arbitrary URL passed in by the caller. While this is the intended functionality of a JSON-RPC provider helper, the code performs no validation of the URL and passes through the JSON-RPC method and params unvalidated, which could be leveraged for SSRF-like or data-forwarding behavior if the caller's URL is influenced by untrusted input.

### [low] no response validation

Finding ID: `NPS-14C73CDE97DE`

File: `dist/esm/provider.js:41`

The function consumes and returns json.result without validating the shape or checking for json.error, as noted by the TODO comment. A malicious or compromised RPC endpoint could return crafted responses that propagate to callers, potentially enabling downstream injection or unexpected behavior.

### [low] permissive handling of private provider internals

Finding ID: `NPS-8676E7D9785A`

File: `dist/esm/provider.js:51`

getProvider accesses the private/internal field _getConnection() on provider objects to extract a connection URL. Relying on an undocumented internal API is fragile and could break or behave unexpectedly across versions of the underlying ethers/Web3 provider library.

### [low] Error message reflection of remote content

Finding ID: `NPS-32EAA05B68D1`

File: `src/provider.ts:44`

On a non-OK response, the code reads the response body (res.text()) from the remote provider and embeds it directly into a thrown Error string. If this error message is later displayed in a UI or logged, it can facilitate log injection, spoofing, or reflected content issues depending on raw body size/format.

### [low] Internal API access via duck-typing

Finding ID: `NPS-9B6A4C17ECAB`

File: `src/provider.ts:63`

getProvider accesses the non-public ethers internal method _getConnection() on the provider object. This uses underscored, private API surface which can change between ethers versions and, more importantly, means the resolved URL is taken from an opaque internal call rather than being validated, potentially returning unexpected hosts.

## Files reviewed

- `dist/esm/provider.js` (medium): No outright malicious patterns (exfiltration, credential harvesting, code execution, backdoors) were detected, but the module makes unvalidated outbound HTTP requests and returns unvalidated RPC responses, warranting caution.
- `src/provider.ts` (medium): No overt malicious exfiltration, credential harvesting, or code execution was found, but the module performs unvalidated outbound RPC requests to arbitrary URLs and trusts remote responses, creating SSRF and data-integrity risks for callers.
- `dist/cjs/account.js` (safe): No malicious patterns detected; this is a standard Ethereum account utility module from @ethereumjs/util with no data exfiltration, code execution, or suspicious behavior.
- `dist/cjs/address.js` (safe): No malicious patterns detected
- `dist/cjs/asyncEventEmitter.js` (safe): No malicious patterns detected; the code is a legitimate async EventEmitter implementation with no data exfiltration, credential harvesting, obfuscation, or other red flags.
- `dist/cjs/blobs.js` (safe): No malicious patterns detected; the code is a legitimate implementation of Ethereum EIP-4844 blob utilities with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `dist/cjs/bytes.js` (safe): No malicious patterns detected; the code is a standard Ethereum byte/hex utility library with no network, file system, process spawning, or dynamic code execution.
- `dist/cjs/constants.js` (safe): This file only exports standard Ethereum cryptographic constants and BigInt values; no malicious patterns, network activity, or dynamic code execution are present.
- `dist/cjs/db.js` (safe): No malicious patterns detected
- `dist/cjs/genesis.js` (safe): No malicious patterns detected; the code is a straightforward, pure initialization function that parses Geth genesis alloc JSON into an in-memory state object without any network, filesystem, process, or dynamic-code activity.
- `dist/cjs/helpers.js` (safe): No malicious patterns detected
- `dist/cjs/index.js` (safe): No malicious patterns detected; this is a standard TypeScript-compiled CommonJS index file that re-exports utility modules for an Ethereum library (ethereumjs-util).
- `dist/cjs/internal.js` (safe): No malicious patterns detected in the provided utility code; it contains only standard string/hex manipulation functions with no network, filesystem, process, or dynamic execution behavior.
- `dist/cjs/kzg.js` (safe): No malicious patterns detected
- `dist/cjs/lock.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/cjs/mapDB.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/cjs/provider.js` (safe): No malicious patterns detected; the code performs straightforward JSON-RPC fetch calls and provider URL extraction without any security concerns.
- `dist/cjs/requests.js` (safe): No malicious patterns detected; the code is a legitimate Ethereum consensus-layer request serialization library with no network, file system, or process manipulation.
- `dist/cjs/signature.js` (safe): No malicious patterns detected
- `dist/cjs/types.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/cjs/units.js` (safe): No malicious patterns detected; the code is a simple utility for Gwei-to-wei conversion and BigDecimal formatting with no network, filesystem, process execution, or obfuscation concerns.
- `dist/cjs/verkle.js` (safe): No malicious patterns detected; the code implements Ethereum Verkle tree utilities using local FFI calls and standard byte manipulation without network, filesystem, or dynamic execution risks.
- `dist/cjs/withdrawal.js` (safe): No malicious patterns detected
- `dist/esm/account.js` (safe): No malicious patterns detected; the code implements Ethereum account utilities using standard cryptographic libraries without any suspicious behavior.
- `dist/esm/address.js` (safe): No malicious patterns detected; this is a legitimate Ethereum address handling class from the ethereumjs ecosystem.
- `dist/esm/asyncEventEmitter.js` (safe): No malicious patterns detected
- `dist/esm/blobs.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/bytes.js` (safe): No malicious patterns detected; the code only provides standard byte/hex conversion utilities using trusted ethereum-cryptography imports.
- `dist/esm/constants.js` (safe): No malicious patterns detected
- `dist/esm/db.js` (safe): No malicious patterns detected; the file only defines two enums for key and value encodings.
- `dist/esm/genesis.js` (safe): No malicious patterns detected
- `dist/esm/helpers.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/index.js` (safe): This is a standard barrel export file for an Ethereum-related JavaScript library with no malicious patterns detected.
- `dist/esm/internal.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/kzg.js` (safe): No malicious patterns detected; the function simply calls loadTrustedSetup on a provided KZG library and is marked deprecated.
- `dist/esm/lock.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/mapDB.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/requests.js` (safe): No malicious patterns detected; the file contains standard Ethereum consensus-layer request serialization/deserialization logic using well-known cryptography and RLP libraries.
- `dist/esm/signature.js` (safe): No malicious patterns detected; the file implements standard Ethereum ECDSA signature utilities using well-known cryptography libraries with no network, filesystem, environment, or process access.
- `dist/esm/types.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/units.js` (safe): Cleared by Jev triage; no further analysis needed
- `dist/esm/verkle.js` (safe): No malicious patterns detected
- `dist/esm/withdrawal.js` (safe): No malicious patterns detected
- `src/account.ts` (safe): No malicious patterns detected; the code is a standard Ethereum account utility library with no network, filesystem, process, or obfuscated behavior.
- `src/address.ts` (safe): No malicious patterns detected
- `src/asyncEventEmitter.ts` (safe): No malicious patterns detected; the code is a straightforward TypeScript port of a well-known async event emitter library with no network, filesystem, process, or obfuscation concerns.
- `src/blobs.ts` (safe): No malicious patterns detected; the code implements standard EIP-4844 blob utilities using KZG commitments and hashing.
- `src/bytes.ts` (safe): No malicious patterns detected; the file contains standard Ethereum byte/hex conversion utilities with no network, filesystem, process, or obfuscated code.
- `src/constants.ts` (safe): No malicious patterns detected; this file only defines standard Ethereum/EVM constants and imports a well-known cryptography library without any exfiltration, dynamic execution, or suspicious behavior.
- `src/db.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/genesis.ts` (safe): No malicious patterns detected; the file contains pure genesis state parsing logic with no network, filesystem, process, or dynamic code execution behavior.
- `src/helpers.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/index.ts` (safe): No malicious patterns detected; the file only re-exports modules from the same package.
- `src/internal.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/kzg.ts` (safe): No malicious patterns detected
- `src/lock.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/mapDB.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/requests.ts` (safe): No malicious patterns detected; the code implements Ethereum consensus-layer request serialization with no network, filesystem, process, or dynamic-code activity.
- `src/signature.ts` (safe): No malicious patterns detected
- `src/types.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/units.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/verkle.ts` (safe): No malicious patterns detected; the file contains only Verkle tree cryptographic helper functions with no network, filesystem, process, or dynamic execution behavior.
- `src/withdrawal.ts` (safe): No malicious patterns detected; the code is a standard EIP-4895 withdrawal data structure with parsing utilities and no network, filesystem, process, or dynamic execution behavior.

## Version ranges

None of the 2 scanned versions of @ethereumjs/util are flagged high or critical. The latest scanned version, 10.0.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 10.0.0 (`10.0.0`): not scanned
- 9.1.0 (`9.1.0`): medium (SSRF / unrestricted outbound request +1 more)
- 8.1.0 (`8.1.0`): clean

## Scanned versions

- [9.1.0](https://security.togoder.click/npm/@ethereumjs/util@9.1.0): medium, 2026-10-04T21:27:35.000Z
- [8.1.0](https://security.togoder.click/npm/@ethereumjs/util@8.1.0): safe, 2026-10-04T16:06:25.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
