Togoder security

npm package security report

@ethereumjs/util@9.1.0 security report

Risky patterns found that deserve a look.

Needs review Version 9.1.0 Files reviewed 63 Size 291.7 KB Scanned

Summary

Togoder Security scanned the npm package @ethereumjs/util@9.1.0 on Oct 4, 2026. An AI review of 63 source files produced 2 medium, 5 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
5
low

Findings 7

medium

Missing response validation / trust of arbitrary provider

NPS-3E0D75A3594E

The code explicitly documents that no parameter or response validation is done, and there is a TODO noting that json.error is not checked. The raw result from an untrusted remote provider is returned directly to the caller. In a wallet or web3 context, a malicious or MITM'd RPC endpoint could return forged data (e.g., fabricated balances, blocks, or transaction results) that gets propagated to downstream consumers.

src/provider.ts:30
medium

SSRF / unrestricted outbound request

NPS-526AE252327A

fetchFromProvider takes an arbitrary URL and performs a POST request to it without any allowlist, scheme validation, or host restriction. If this function is invoked with user-controlled input (or if getProvider resolves a URL from an attacker-influenced provider object), it can be abused for Server-Side Request Forgery against internal services (e.g., cloud metadata endpoints like 169.254.169.254, localhost services, or internal APIs).

src/provider.ts:33
low

suspicious network request

NPS-6DBBEDD84C22

fetchFromProvider performs an outbound HTTP request to an arbitrary URL passed in by the caller. While this is the intended functionality of a JSON-RPC provider helper, the code performs no validation of the URL and passes through the JSON-RPC method and params unvalidated, which could be leveraged for SSRF-like or data-forwarding behavior if the caller's URL is influenced by untrusted input.

dist/esm/provider.js:22
low

no response validation

NPS-14C73CDE97DE

The function consumes and returns json.result without validating the shape or checking for json.error, as noted by the TODO comment. A malicious or compromised RPC endpoint could return crafted responses that propagate to callers, potentially enabling downstream injection or unexpected behavior.

dist/esm/provider.js:41
low

permissive handling of private provider internals

NPS-8676E7D9785A

getProvider accesses the private/internal field _getConnection() on provider objects to extract a connection URL. Relying on an undocumented internal API is fragile and could break or behave unexpectedly across versions of the underlying ethers/Web3 provider library.

dist/esm/provider.js:51
low

Error message reflection of remote content

NPS-32EAA05B68D1

On a non-OK response, the code reads the response body (res.text()) from the remote provider and embeds it directly into a thrown Error string. If this error message is later displayed in a UI or logged, it can facilitate log injection, spoofing, or reflected content issues depending on raw body size/format.

src/provider.ts:44
low

Internal API access via duck-typing

NPS-9B6A4C17ECAB

getProvider accesses the non-public ethers internal method _getConnection() on the provider object. This uses underscored, private API surface which can change between ethers versions and, more importantly, means the resolved URL is taken from an opaque internal call rather than being validated, potentially returning unexpected hosts.

src/provider.ts:63

Files reviewed

FileVerdictWhat the reviewer saw
dist/esm/provider.js medium No outright malicious patterns (exfiltration, credential harvesting, code execution, backdoors) were detected, but the module makes unvalidated outbound HTTP requests and returns unvalidated RPC responses, warranting caution.
src/provider.ts medium No overt malicious exfiltration, credential harvesting, or code execution was found, but the module performs unvalidated outbound RPC requests to arbitrary URLs and trusts remote responses, creating SSRF and data-integrity risks for callers.
dist/cjs/account.js safe No malicious patterns detected; this is a standard Ethereum account utility module from @ethereumjs/util with no data exfiltration, code execution, or suspicious behavior.
dist/cjs/address.js safe No malicious patterns detected
dist/cjs/asyncEventEmitter.js safe No malicious patterns detected; the code is a legitimate async EventEmitter implementation with no data exfiltration, credential harvesting, obfuscation, or other red flags.
dist/cjs/blobs.js safe No malicious patterns detected; the code is a legitimate implementation of Ethereum EIP-4844 blob utilities with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
dist/cjs/bytes.js safe No malicious patterns detected; the code is a standard Ethereum byte/hex utility library with no network, file system, process spawning, or dynamic code execution.
dist/cjs/constants.js safe This file only exports standard Ethereum cryptographic constants and BigInt values; no malicious patterns, network activity, or dynamic code execution are present.
dist/cjs/db.js safe No malicious patterns detected
dist/cjs/genesis.js safe No malicious patterns detected; the code is a straightforward, pure initialization function that parses Geth genesis alloc JSON into an in-memory state object without any network, filesystem, process, or dynamic-code activity.
dist/cjs/helpers.js safe No malicious patterns detected
dist/cjs/index.js safe No malicious patterns detected; this is a standard TypeScript-compiled CommonJS index file that re-exports utility modules for an Ethereum library (ethereumjs-util).
dist/cjs/internal.js safe No malicious patterns detected in the provided utility code; it contains only standard string/hex manipulation functions with no network, filesystem, process, or dynamic execution behavior.
dist/cjs/kzg.js safe No malicious patterns detected
dist/cjs/lock.js safe Cleared by Jev triage; no further analysis needed
dist/cjs/mapDB.js safe Cleared by Jev triage; no further analysis needed
dist/cjs/provider.js safe No malicious patterns detected; the code performs straightforward JSON-RPC fetch calls and provider URL extraction without any security concerns.
dist/cjs/requests.js safe No malicious patterns detected; the code is a legitimate Ethereum consensus-layer request serialization library with no network, file system, or process manipulation.
dist/cjs/signature.js safe No malicious patterns detected
dist/cjs/types.js safe Cleared by Jev triage; no further analysis needed
dist/cjs/units.js safe No malicious patterns detected; the code is a simple utility for Gwei-to-wei conversion and BigDecimal formatting with no network, filesystem, process execution, or obfuscation concerns.
dist/cjs/verkle.js safe No malicious patterns detected; the code implements Ethereum Verkle tree utilities using local FFI calls and standard byte manipulation without network, filesystem, or dynamic execution risks.
dist/cjs/withdrawal.js safe No malicious patterns detected
dist/esm/account.js safe No malicious patterns detected; the code implements Ethereum account utilities using standard cryptographic libraries without any suspicious behavior.
dist/esm/address.js safe No malicious patterns detected; this is a legitimate Ethereum address handling class from the ethereumjs ecosystem.
Show 38 more files
FileVerdictWhat the reviewer saw
dist/esm/asyncEventEmitter.js safe No malicious patterns detected
dist/esm/blobs.js safe Cleared by Jev triage; no further analysis needed
dist/esm/bytes.js safe No malicious patterns detected; the code only provides standard byte/hex conversion utilities using trusted ethereum-cryptography imports.
dist/esm/constants.js safe No malicious patterns detected
dist/esm/db.js safe No malicious patterns detected; the file only defines two enums for key and value encodings.
dist/esm/genesis.js safe No malicious patterns detected
dist/esm/helpers.js safe Cleared by Jev triage; no further analysis needed
dist/esm/index.js safe This is a standard barrel export file for an Ethereum-related JavaScript library with no malicious patterns detected.
dist/esm/internal.js safe Cleared by Jev triage; no further analysis needed
dist/esm/kzg.js safe No malicious patterns detected; the function simply calls loadTrustedSetup on a provided KZG library and is marked deprecated.
dist/esm/lock.js safe Cleared by Jev triage; no further analysis needed
dist/esm/mapDB.js safe Cleared by Jev triage; no further analysis needed
dist/esm/requests.js safe No malicious patterns detected; the file contains standard Ethereum consensus-layer request serialization/deserialization logic using well-known cryptography and RLP libraries.
dist/esm/signature.js safe No malicious patterns detected; the file implements standard Ethereum ECDSA signature utilities using well-known cryptography libraries with no network, filesystem, environment, or process access.
dist/esm/types.js safe Cleared by Jev triage; no further analysis needed
dist/esm/units.js safe Cleared by Jev triage; no further analysis needed
dist/esm/verkle.js safe No malicious patterns detected
dist/esm/withdrawal.js safe No malicious patterns detected
src/account.ts safe No malicious patterns detected; the code is a standard Ethereum account utility library with no network, filesystem, process, or obfuscated behavior.
src/address.ts safe No malicious patterns detected
src/asyncEventEmitter.ts safe No malicious patterns detected; the code is a straightforward TypeScript port of a well-known async event emitter library with no network, filesystem, process, or obfuscation concerns.
src/blobs.ts safe No malicious patterns detected; the code implements standard EIP-4844 blob utilities using KZG commitments and hashing.
src/bytes.ts safe No malicious patterns detected; the file contains standard Ethereum byte/hex conversion utilities with no network, filesystem, process, or obfuscated code.
src/constants.ts safe No malicious patterns detected; this file only defines standard Ethereum/EVM constants and imports a well-known cryptography library without any exfiltration, dynamic execution, or suspicious behavior.
src/db.ts safe Cleared by Jev triage; no further analysis needed
src/genesis.ts safe No malicious patterns detected; the file contains pure genesis state parsing logic with no network, filesystem, process, or dynamic code execution behavior.
src/helpers.ts safe Cleared by Jev triage; no further analysis needed
src/index.ts safe No malicious patterns detected; the file only re-exports modules from the same package.
src/internal.ts safe Cleared by Jev triage; no further analysis needed
src/kzg.ts safe No malicious patterns detected
src/lock.ts safe Cleared by Jev triage; no further analysis needed
src/mapDB.ts safe Cleared by Jev triage; no further analysis needed
src/requests.ts safe No malicious patterns detected; the code implements Ethereum consensus-layer request serialization with no network, filesystem, process, or dynamic-code activity.
src/signature.ts safe No malicious patterns detected
src/types.ts safe Cleared by Jev triage; no further analysis needed
src/units.ts safe Cleared by Jev triage; no further analysis needed
src/verkle.ts safe No malicious patterns detected; the file contains only Verkle tree cryptographic helper functions with no network, filesystem, process, or dynamic execution behavior.
src/withdrawal.ts safe No malicious patterns detected; the code is a standard EIP-4895 withdrawal data structure with parsing utilities and no network, filesystem, process, or dynamic execution behavior.

Affected version ranges

None of the 2 scanned versions of @ethereumjs/util are flagged high or critical. The latest scanned version, 10.0.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

8.1.010.0.0
VersionsVerdictCountRangeTop findings
10.0.0 Not scanned 1 10.0.0
9.1.0 Needs review 1 9.1.0 SSRF / unrestricted outbound request; Missing response validation / trust of arbitrary provider
8.1.0 No issues 1 8.1.0

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of @ethereumjs/util

VersionVerdictFilesScanned
9.1.0 Needs review 63 Oct 4, 2026
8.1.0 No issues 30 Oct 4, 2026

Frequently asked questions

Is @ethereumjs/util safe to use?

No confirmed malware was found in @ethereumjs/util@9.1.0, but the review flagged 2 medium, 5 low severity findings for risky patterns worth checking before you rely on it.

Does @ethereumjs/util contain malware?

No malware was identified in @ethereumjs/util@9.1.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @ethereumjs/util checked?

Togoder Security downloaded the published npm package and had an AI model read its 63 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @ethereumjs/util together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @ethereumjs/util@9.1.0, cost nothing.

Related security reports