Togoder security

npm package security report

@exodus/bytes npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 1.15.1 Files reviewed 53 Size 172.3 KB Scanned

Summary

Togoder Security scanned the npm package @exodus/bytes@1.15.1 on Oct 6, 2026. An AI review of 53 source files produced 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
4
low

Findings 4

low

unnecessary buffer access

NPS-8F77AB56ACB4

The code accesses Buffer.from(arr.buffer, arr.byteOffset, arr.byteLength).hexSlice(...), which could potentially expose underlying ArrayBuffer memory beyond the intended view. However, no exfiltration or malicious intent is evident.

hex.node.js:12
low

unsafe buffer allocation

NPS-5C9E89C57E7F

Use of Buffer.allocUnsafe and Buffer.allocUnsafeSlow may expose uninitialized memory if the hex writing fails partway. The code does validate the written count, but the allocated buffer is not zero-filled before writing.

hex.node.js:33
low

Top-level code execution

NPS-0C04F7A0B893

The module performs top-level initialization including creating TextDecoder instances and checking globalThis.Deno. This code runs on import but is benign and necessary for the module's UTF-8 encoding/decoding functionality.

utf8.node.js
low

Use of Buffer.allocUnsafe

NPS-55B338565A1E

Buffer.allocUnsafe is used for performance when encoding large strings. The buffer is fully written with the encoded string before being returned, so there is no exposure of uninitialized memory. This is a standard optimization pattern.

utf8.node.js

Files reviewed

FileVerdictWhat the reviewer saw
hex.node.js medium No malicious patterns detected, but minor security-sensitive buffer operations warrant caution.
array.js safe Cleared by Jev triage; no further analysis needed
assert.js safe Cleared by Jev triage; no further analysis needed
base32.js safe Cleared by Jev triage; no further analysis needed
base58.js safe No malicious patterns detected; the file is a straightforward, well-implemented Base58 encoder/decoder with no network, process, filesystem, or dynamic-code execution concerns.
base58check.js safe No malicious patterns detected; the code is a straightforward Base58Check encoding/decoding utility using SHA-256 hashing with no network, filesystem, or process operations.
base58check.node.js safe No malicious patterns detected
base64.js safe Cleared by Jev triage; no further analysis needed
bech32.js safe The code implements Bech32/Bech32m encoding and decoding with no malicious patterns, network activity, or dynamic execution.
bigint.js safe Cleared by Jev triage; no further analysis needed
encoding-browser.browser.js safe Cleared by Jev triage; no further analysis needed
encoding-browser.js safe Cleared by Jev triage; no further analysis needed
encoding-browser.native.js safe Cleared by Jev triage; no further analysis needed
encoding-lite.js safe Cleared by Jev triage; no further analysis needed
encoding.js safe The code is a simple encoding utility that imports and re-exports text encoding functions, with no evidence of malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or unauthorized system interaction.
fallback/_utils.js safe Cleared by Jev triage; no further analysis needed
fallback/base32.js safe Cleared by Jev triage; no further analysis needed
fallback/base58check.js safe No malicious patterns detected in the Base58Check implementation; it performs standard checksum encoding/decoding with no network, filesystem, process, or dynamic code execution behavior.
fallback/base64.js safe Cleared by Jev triage; no further analysis needed
fallback/encoding.api.js safe Cleared by Jev triage; no further analysis needed
fallback/encoding.js safe Cleared by Jev triage; no further analysis needed
fallback/encoding.labels.js safe The file only defines static encoding label mappings and contains no malicious patterns.
fallback/encoding.util.js safe Cleared by Jev triage; no further analysis needed
fallback/hex.js safe Cleared by Jev triage; no further analysis needed
fallback/latin1.js safe Cleared by Jev triage; no further analysis needed
Show 28 more files
FileVerdictWhat the reviewer saw
fallback/multi-byte.encodings.cjs safe Cleared by Jev triage; no further analysis needed
fallback/multi-byte.js safe Cleared by Jev triage; no further analysis needed
fallback/multi-byte.table.js safe No malicious patterns detected; the code is a legitimate implementation of multi-byte character encoding tables from the @exodus/bytes library, using base64 decoding and self-referencing data structures for encoding tables without any network, filesystem, or process execution activity.
fallback/percent.js safe Cleared by Jev triage; no further analysis needed
fallback/platform.browser.js safe No malicious patterns detected; the file contains only standard text encoding/decoding utilities for browser environments.
fallback/platform.js safe Cleared by Jev triage; no further analysis needed
fallback/platform.native.js safe This file contains only platform detection, text encoding/decoding utilities, and performance optimizations for Hermes/Deno/Node.js environments with no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or network activity.
fallback/single-byte.encodings.js safe No malicious patterns detected; the file only contains static encoding lookup tables and map definitions with no network, filesystem, process, or dynamic execution behavior.
fallback/single-byte.js safe Cleared by Jev triage; no further analysis needed
fallback/utf16.js safe Cleared by Jev triage; no further analysis needed
fallback/utf8.auto.browser.js safe Cleared by Jev triage; no further analysis needed
fallback/utf8.auto.js safe Cleared by Jev triage; no further analysis needed
fallback/utf8.auto.native.js safe Cleared by Jev triage; no further analysis needed
fallback/utf8.js safe Cleared by Jev triage; no further analysis needed
hex.js safe Cleared by Jev triage; no further analysis needed
index.js safe No malicious patterns detected
multi-byte.js safe Cleared by Jev triage; no further analysis needed
multi-byte.node.js safe Cleared by Jev triage; no further analysis needed
single-byte.js safe Cleared by Jev triage; no further analysis needed
single-byte.node.js safe Cleared by Jev triage; no further analysis needed
utf16.browser.js safe Cleared by Jev triage; no further analysis needed
utf16.js safe The file only re-exports from a relative native module with no malicious patterns detected.
utf16.native.js safe No malicious patterns detected; the code is a benign UTF-16 encode/decode utility with feature detection for TextDecoder.
utf16.node.js safe No malicious patterns detected; the code is a standard UTF-16 encoding/decoding utility with no network, filesystem, process, or dynamic execution behavior.
utf8.js safe No malicious patterns detected; the code is a standard UTF-8 encoding/decoding utility with no exfiltration, credential harvesting, obfuscation, or dynamic code execution.
utf8.node.js safe The code is a legitimate UTF-8 encoding/decoding utility with no malicious patterns; top-level initialization and use of Buffer.allocUnsafe are benign performance optimizations.
whatwg.js safe No malicious patterns detected; the code implements WHATWG percent-encoding logic using only local imports and standard URL encoding operations.
wif.js safe No malicious patterns detected; the code implements WIF encoding/decoding with strict validation and no network, filesystem, or dynamic execution behavior.

Scanned versions of @exodus/bytes

VersionVerdictFilesScanned
1.15.1 Needs review 53 Oct 6, 2026

Frequently asked questions

Is @exodus/bytes safe to use?

No confirmed malware was found in @exodus/bytes@1.15.1, but the review flagged 4 low severity findings for risky patterns worth checking before you rely on it.

Does @exodus/bytes contain malware?

No malware was identified in @exodus/bytes@1.15.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @exodus/bytes checked?

Togoder Security downloaded the published npm package and had an AI model read its 53 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @exodus/bytes together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @exodus/bytes@1.15.1, cost nothing.

Related security reports