Togoder security

npm package security report

@ethereumjs/util@8.1.0 security report

No malicious code found.

No issues Version 8.1.0 Files reviewed 30 Size 122.3 KB Scanned

Summary

Togoder Security scanned the npm package @ethereumjs/util@8.1.0 on Oct 4, 2026. An AI review of 30 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
1
low

Findings 1

low

Network Request

NPS-B367CBC2FF2C

The function fetchFromProvider makes an HTTP POST request to the provided URL. This is expected behavior for an RPC provider helper. No data exfiltration to hardcoded external servers is present; the URL is supplied by the caller.

src/provider.ts:6

Files reviewed

FileVerdictWhat the reviewer saw
dist/account.js safe This is a legitimate Ethereum account utility library (from ethereumjs) with no malicious patterns, no data exfiltration, no credential harvesting, no dynamic code execution, and no suspicious network or filesystem activity.
dist/address.js safe No malicious patterns detected; the code is a standard Ethereum address utility with no network, filesystem, or process activity.
dist/asyncEventEmitter.js safe No malicious patterns detected; the code is a legitimate async EventEmitter implementation with no data exfiltration, credential harvesting, obfuscation, or other red flags.
dist/bytes.js safe No malicious patterns detected
dist/constants.js safe No malicious patterns detected
dist/encoding.js safe No malicious patterns detected; the code is a legitimate Ethereum Patricia Merkle Trie encoding utility with no network, filesystem, process, or dynamic execution behavior.
dist/helpers.js safe No malicious patterns detected
dist/index.js safe No malicious patterns detected; the file contains only standard TypeScript/CommonJS re-export boilerplate for an Ethereum utility library.
dist/internal.js safe No malicious patterns detected; the code contains only standard Ethereum utility functions for hex/ASCII handling with no external network, process, or filesystem operations.
dist/lock.js safe Cleared by Jev triage; no further analysis needed
dist/provider.js safe No malicious patterns detected; the code performs standard JSON-RPC fetch operations and provider URL extraction without exfiltration, obfuscation, or dangerous system calls.
dist/signature.js safe No malicious patterns detected
dist/types.js safe No malicious patterns detected; the code is a straightforward type conversion utility with input validation and no external calls, file access, or dynamic execution.
dist/units.js safe No malicious patterns detected
dist/withdrawal.js safe No malicious patterns detected; the code is a straightforward EIP-4895 withdrawal data representation class with no external calls, dynamic execution, or filesystem access.
src/account.ts safe No malicious patterns detected; the file implements standard Ethereum account utilities without exfiltration, obfuscation, or backdoor behavior.
src/address.ts safe No malicious patterns detected
src/asyncEventEmitter.ts safe No malicious patterns detected; the code is a straightforward TypeScript port of a well-known async event emitter library with no network, filesystem, process, or obfuscation concerns.
src/bytes.ts safe Cleared by Jev triage; no further analysis needed
src/constants.ts safe No malicious patterns detected
src/encoding.ts safe Cleared by Jev triage; no further analysis needed
src/helpers.ts safe Cleared by Jev triage; no further analysis needed
src/index.ts safe No malicious patterns detected
src/internal.ts safe Cleared by Jev triage; no further analysis needed
src/lock.ts safe Cleared by Jev triage; no further analysis needed
Show 5 more files
FileVerdictWhat the reviewer saw
src/provider.ts safe The code is a benign RPC provider helper with no malicious patterns detected.
src/signature.ts safe No malicious patterns detected; the code is a standard Ethereum ECDSA signature utility without exfiltration, obfuscation, or dynamic execution.
src/types.ts safe Cleared by Jev triage; no further analysis needed
src/units.ts safe Cleared by Jev triage; no further analysis needed
src/withdrawal.ts safe No malicious patterns detected; the code is a standard EIP-4895 withdrawal data class with no network, filesystem, process, or dynamic code execution behaviors.

Affected version ranges

None of the 2 scanned versions of @ethereumjs/util are flagged high or critical. The latest scanned version, 10.0.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

8.1.010.0.0
VersionsVerdictCountRangeTop findings
10.0.0 Not scanned 1 10.0.0
9.1.0 Needs review 1 9.1.0 SSRF / unrestricted outbound request; Missing response validation / trust of arbitrary provider
8.1.0 No issues 1 8.1.0

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of @ethereumjs/util

VersionVerdictFilesScanned
9.1.0 Needs review 63 Oct 4, 2026
8.1.0 No issues 30 Oct 4, 2026

Frequently asked questions

Is @ethereumjs/util safe to use?

Our AI source review of @ethereumjs/util@8.1.0 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does @ethereumjs/util contain malware?

No malware was identified in @ethereumjs/util@8.1.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @ethereumjs/util checked?

Togoder Security downloaded the published npm package and had an AI model read its 30 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @ethereumjs/util together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @ethereumjs/util@8.1.0, cost nothing.

Related security reports