Summary
Togoder Security scanned the npm package @ethereumjs/util@8.1.0 on Oct 4, 2026. An AI review of 30 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings 1
Network Request
NPS-B367CBC2FF2C
The function fetchFromProvider makes an HTTP POST request to the provided URL. This is expected behavior for an RPC provider helper. No data exfiltration to hardcoded external servers is present; the URL is supplied by the caller.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/account.js | safe | This is a legitimate Ethereum account utility library (from ethereumjs) with no malicious patterns, no data exfiltration, no credential harvesting, no dynamic code execution, and no suspicious network or filesystem activity. |
| dist/address.js | safe | No malicious patterns detected; the code is a standard Ethereum address utility with no network, filesystem, or process activity. |
| dist/asyncEventEmitter.js | safe | No malicious patterns detected; the code is a legitimate async EventEmitter implementation with no data exfiltration, credential harvesting, obfuscation, or other red flags. |
| dist/bytes.js | safe | No malicious patterns detected |
| dist/constants.js | safe | No malicious patterns detected |
| dist/encoding.js | safe | No malicious patterns detected; the code is a legitimate Ethereum Patricia Merkle Trie encoding utility with no network, filesystem, process, or dynamic execution behavior. |
| dist/helpers.js | safe | No malicious patterns detected |
| dist/index.js | safe | No malicious patterns detected; the file contains only standard TypeScript/CommonJS re-export boilerplate for an Ethereum utility library. |
| dist/internal.js | safe | No malicious patterns detected; the code contains only standard Ethereum utility functions for hex/ASCII handling with no external network, process, or filesystem operations. |
| dist/lock.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/provider.js | safe | No malicious patterns detected; the code performs standard JSON-RPC fetch operations and provider URL extraction without exfiltration, obfuscation, or dangerous system calls. |
| dist/signature.js | safe | No malicious patterns detected |
| dist/types.js | safe | No malicious patterns detected; the code is a straightforward type conversion utility with input validation and no external calls, file access, or dynamic execution. |
| dist/units.js | safe | No malicious patterns detected |
| dist/withdrawal.js | safe | No malicious patterns detected; the code is a straightforward EIP-4895 withdrawal data representation class with no external calls, dynamic execution, or filesystem access. |
| src/account.ts | safe | No malicious patterns detected; the file implements standard Ethereum account utilities without exfiltration, obfuscation, or backdoor behavior. |
| src/address.ts | safe | No malicious patterns detected |
| src/asyncEventEmitter.ts | safe | No malicious patterns detected; the code is a straightforward TypeScript port of a well-known async event emitter library with no network, filesystem, process, or obfuscation concerns. |
| src/bytes.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/constants.ts | safe | No malicious patterns detected |
| src/encoding.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/helpers.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/index.ts | safe | No malicious patterns detected |
| src/internal.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/lock.ts | safe | Cleared by Jev triage; no further analysis needed |
Show 5 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| src/provider.ts | safe | The code is a benign RPC provider helper with no malicious patterns detected. |
| src/signature.ts | safe | No malicious patterns detected; the code is a standard Ethereum ECDSA signature utility without exfiltration, obfuscation, or dynamic execution. |
| src/types.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/units.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/withdrawal.ts | safe | No malicious patterns detected; the code is a standard EIP-4895 withdrawal data class with no network, filesystem, process, or dynamic code execution behaviors. |
Affected version ranges
None of the 2 scanned versions of @ethereumjs/util are flagged high or critical. The latest scanned version, 10.0.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 10.0.0 | Not scanned | 1 | 10.0.0 | |
| 9.1.0 | Needs review | 1 | 9.1.0 | SSRF / unrestricted outbound request; Missing response validation / trust of arbitrary provider |
| 8.1.0 | No issues | 1 | 8.1.0 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of @ethereumjs/util
Frequently asked questions
Is @ethereumjs/util safe to use?
Our AI source review of @ethereumjs/util@8.1.0 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does @ethereumjs/util contain malware?
No malware was identified in @ethereumjs/util@8.1.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @ethereumjs/util checked?
Togoder Security downloaded the published npm package and had an AI model read its 30 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @ethereumjs/util together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @ethereumjs/util@8.1.0, cost nothing.