# @exodus/bytes@1.15.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:11:06.000Z
- Files reviewed: 53
- Findings: 4 low severity findings
- Report: https://security.togoder.click/npm/@exodus/bytes
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @exodus/bytes@1.15.1 on Oct 6, 2026. An AI review of 53 source files produced 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] unnecessary buffer access

Finding ID: `NPS-8F77AB56ACB4`

File: `hex.node.js:12`

The code accesses `Buffer.from(arr.buffer, arr.byteOffset, arr.byteLength).hexSlice(...)`, which could potentially expose underlying ArrayBuffer memory beyond the intended view. However, no exfiltration or malicious intent is evident.

### [low] unsafe buffer allocation

Finding ID: `NPS-5C9E89C57E7F`

File: `hex.node.js:33`

Use of `Buffer.allocUnsafe` and `Buffer.allocUnsafeSlow` may expose uninitialized memory if the hex writing fails partway. The code does validate the written count, but the allocated buffer is not zero-filled before writing.

### [low] Top-level code execution

Finding ID: `NPS-0C04F7A0B893`

File: `utf8.node.js`

The module performs top-level initialization including creating TextDecoder instances and checking globalThis.Deno. This code runs on import but is benign and necessary for the module's UTF-8 encoding/decoding functionality.

### [low] Use of Buffer.allocUnsafe

Finding ID: `NPS-55B338565A1E`

File: `utf8.node.js`

Buffer.allocUnsafe is used for performance when encoding large strings. The buffer is fully written with the encoded string before being returned, so there is no exposure of uninitialized memory. This is a standard optimization pattern.

## Files reviewed

- `hex.node.js` (medium): No malicious patterns detected, but minor security-sensitive buffer operations warrant caution.
- `array.js` (safe): Cleared by Jev triage; no further analysis needed
- `assert.js` (safe): Cleared by Jev triage; no further analysis needed
- `base32.js` (safe): Cleared by Jev triage; no further analysis needed
- `base58.js` (safe): No malicious patterns detected; the file is a straightforward, well-implemented Base58 encoder/decoder with no network, process, filesystem, or dynamic-code execution concerns.
- `base58check.js` (safe): No malicious patterns detected; the code is a straightforward Base58Check encoding/decoding utility using SHA-256 hashing with no network, filesystem, or process operations.
- `base58check.node.js` (safe): No malicious patterns detected
- `base64.js` (safe): Cleared by Jev triage; no further analysis needed
- `bech32.js` (safe): The code implements Bech32/Bech32m encoding and decoding with no malicious patterns, network activity, or dynamic execution.
- `bigint.js` (safe): Cleared by Jev triage; no further analysis needed
- `encoding-browser.browser.js` (safe): Cleared by Jev triage; no further analysis needed
- `encoding-browser.js` (safe): Cleared by Jev triage; no further analysis needed
- `encoding-browser.native.js` (safe): Cleared by Jev triage; no further analysis needed
- `encoding-lite.js` (safe): Cleared by Jev triage; no further analysis needed
- `encoding.js` (safe): The code is a simple encoding utility that imports and re-exports text encoding functions, with no evidence of malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or unauthorized system interaction.
- `fallback/_utils.js` (safe): Cleared by Jev triage; no further analysis needed
- `fallback/base32.js` (safe): Cleared by Jev triage; no further analysis needed
- `fallback/base58check.js` (safe): No malicious patterns detected in the Base58Check implementation; it performs standard checksum encoding/decoding with no network, filesystem, process, or dynamic code execution behavior.
- `fallback/base64.js` (safe): Cleared by Jev triage; no further analysis needed
- `fallback/encoding.api.js` (safe): Cleared by Jev triage; no further analysis needed
- `fallback/encoding.js` (safe): Cleared by Jev triage; no further analysis needed
- `fallback/encoding.labels.js` (safe): The file only defines static encoding label mappings and contains no malicious patterns.
- `fallback/encoding.util.js` (safe): Cleared by Jev triage; no further analysis needed
- `fallback/hex.js` (safe): Cleared by Jev triage; no further analysis needed
- `fallback/latin1.js` (safe): Cleared by Jev triage; no further analysis needed
- `fallback/multi-byte.encodings.cjs` (safe): Cleared by Jev triage; no further analysis needed
- `fallback/multi-byte.js` (safe): Cleared by Jev triage; no further analysis needed
- `fallback/multi-byte.table.js` (safe): No malicious patterns detected; the code is a legitimate implementation of multi-byte character encoding tables from the @exodus/bytes library, using base64 decoding and self-referencing data structures for encoding tables without any network, filesystem, or process execution activity.
- `fallback/percent.js` (safe): Cleared by Jev triage; no further analysis needed
- `fallback/platform.browser.js` (safe): No malicious patterns detected; the file contains only standard text encoding/decoding utilities for browser environments.
- `fallback/platform.js` (safe): Cleared by Jev triage; no further analysis needed
- `fallback/platform.native.js` (safe): This file contains only platform detection, text encoding/decoding utilities, and performance optimizations for Hermes/Deno/Node.js environments with no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or network activity.
- `fallback/single-byte.encodings.js` (safe): No malicious patterns detected; the file only contains static encoding lookup tables and map definitions with no network, filesystem, process, or dynamic execution behavior.
- `fallback/single-byte.js` (safe): Cleared by Jev triage; no further analysis needed
- `fallback/utf16.js` (safe): Cleared by Jev triage; no further analysis needed
- `fallback/utf8.auto.browser.js` (safe): Cleared by Jev triage; no further analysis needed
- `fallback/utf8.auto.js` (safe): Cleared by Jev triage; no further analysis needed
- `fallback/utf8.auto.native.js` (safe): Cleared by Jev triage; no further analysis needed
- `fallback/utf8.js` (safe): Cleared by Jev triage; no further analysis needed
- `hex.js` (safe): Cleared by Jev triage; no further analysis needed
- `index.js` (safe): No malicious patterns detected
- `multi-byte.js` (safe): Cleared by Jev triage; no further analysis needed
- `multi-byte.node.js` (safe): Cleared by Jev triage; no further analysis needed
- `single-byte.js` (safe): Cleared by Jev triage; no further analysis needed
- `single-byte.node.js` (safe): Cleared by Jev triage; no further analysis needed
- `utf16.browser.js` (safe): Cleared by Jev triage; no further analysis needed
- `utf16.js` (safe): The file only re-exports from a relative native module with no malicious patterns detected.
- `utf16.native.js` (safe): No malicious patterns detected; the code is a benign UTF-16 encode/decode utility with feature detection for TextDecoder.
- `utf16.node.js` (safe): No malicious patterns detected; the code is a standard UTF-16 encoding/decoding utility with no network, filesystem, process, or dynamic execution behavior.
- `utf8.js` (safe): No malicious patterns detected; the code is a standard UTF-8 encoding/decoding utility with no exfiltration, credential harvesting, obfuscation, or dynamic code execution.
- `utf8.node.js` (safe): The code is a legitimate UTF-8 encoding/decoding utility with no malicious patterns; top-level initialization and use of Buffer.allocUnsafe are benign performance optimizations.
- `whatwg.js` (safe): No malicious patterns detected; the code implements WHATWG percent-encoding logic using only local imports and standard URL encoding operations.
- `wif.js` (safe): No malicious patterns detected; the code implements WIF encoding/decoding with strict validation and no network, filesystem, or dynamic execution behavior.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
