Summary
Togoder Security scanned the npm package @exodus/bytes@1.15.1 on Oct 6, 2026. An AI review of 53 source files produced 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 4
unnecessary buffer access
NPS-8F77AB56ACB4
The code accesses Buffer.from(arr.buffer, arr.byteOffset, arr.byteLength).hexSlice(...), which could potentially expose underlying ArrayBuffer memory beyond the intended view. However, no exfiltration or malicious intent is evident.
unsafe buffer allocation
NPS-5C9E89C57E7F
Use of Buffer.allocUnsafe and Buffer.allocUnsafeSlow may expose uninitialized memory if the hex writing fails partway. The code does validate the written count, but the allocated buffer is not zero-filled before writing.
Top-level code execution
NPS-0C04F7A0B893
The module performs top-level initialization including creating TextDecoder instances and checking globalThis.Deno. This code runs on import but is benign and necessary for the module's UTF-8 encoding/decoding functionality.
Use of Buffer.allocUnsafe
NPS-55B338565A1E
Buffer.allocUnsafe is used for performance when encoding large strings. The buffer is fully written with the encoded string before being returned, so there is no exposure of uninitialized memory. This is a standard optimization pattern.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| hex.node.js | medium | No malicious patterns detected, but minor security-sensitive buffer operations warrant caution. |
| array.js | safe | Cleared by Jev triage; no further analysis needed |
| assert.js | safe | Cleared by Jev triage; no further analysis needed |
| base32.js | safe | Cleared by Jev triage; no further analysis needed |
| base58.js | safe | No malicious patterns detected; the file is a straightforward, well-implemented Base58 encoder/decoder with no network, process, filesystem, or dynamic-code execution concerns. |
| base58check.js | safe | No malicious patterns detected; the code is a straightforward Base58Check encoding/decoding utility using SHA-256 hashing with no network, filesystem, or process operations. |
| base58check.node.js | safe | No malicious patterns detected |
| base64.js | safe | Cleared by Jev triage; no further analysis needed |
| bech32.js | safe | The code implements Bech32/Bech32m encoding and decoding with no malicious patterns, network activity, or dynamic execution. |
| bigint.js | safe | Cleared by Jev triage; no further analysis needed |
| encoding-browser.browser.js | safe | Cleared by Jev triage; no further analysis needed |
| encoding-browser.js | safe | Cleared by Jev triage; no further analysis needed |
| encoding-browser.native.js | safe | Cleared by Jev triage; no further analysis needed |
| encoding-lite.js | safe | Cleared by Jev triage; no further analysis needed |
| encoding.js | safe | The code is a simple encoding utility that imports and re-exports text encoding functions, with no evidence of malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or unauthorized system interaction. |
| fallback/_utils.js | safe | Cleared by Jev triage; no further analysis needed |
| fallback/base32.js | safe | Cleared by Jev triage; no further analysis needed |
| fallback/base58check.js | safe | No malicious patterns detected in the Base58Check implementation; it performs standard checksum encoding/decoding with no network, filesystem, process, or dynamic code execution behavior. |
| fallback/base64.js | safe | Cleared by Jev triage; no further analysis needed |
| fallback/encoding.api.js | safe | Cleared by Jev triage; no further analysis needed |
| fallback/encoding.js | safe | Cleared by Jev triage; no further analysis needed |
| fallback/encoding.labels.js | safe | The file only defines static encoding label mappings and contains no malicious patterns. |
| fallback/encoding.util.js | safe | Cleared by Jev triage; no further analysis needed |
| fallback/hex.js | safe | Cleared by Jev triage; no further analysis needed |
| fallback/latin1.js | safe | Cleared by Jev triage; no further analysis needed |
Show 28 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| fallback/multi-byte.encodings.cjs | safe | Cleared by Jev triage; no further analysis needed |
| fallback/multi-byte.js | safe | Cleared by Jev triage; no further analysis needed |
| fallback/multi-byte.table.js | safe | No malicious patterns detected; the code is a legitimate implementation of multi-byte character encoding tables from the @exodus/bytes library, using base64 decoding and self-referencing data structures for encoding tables without any network, filesystem, or process execution activity. |
| fallback/percent.js | safe | Cleared by Jev triage; no further analysis needed |
| fallback/platform.browser.js | safe | No malicious patterns detected; the file contains only standard text encoding/decoding utilities for browser environments. |
| fallback/platform.js | safe | Cleared by Jev triage; no further analysis needed |
| fallback/platform.native.js | safe | This file contains only platform detection, text encoding/decoding utilities, and performance optimizations for Hermes/Deno/Node.js environments with no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or network activity. |
| fallback/single-byte.encodings.js | safe | No malicious patterns detected; the file only contains static encoding lookup tables and map definitions with no network, filesystem, process, or dynamic execution behavior. |
| fallback/single-byte.js | safe | Cleared by Jev triage; no further analysis needed |
| fallback/utf16.js | safe | Cleared by Jev triage; no further analysis needed |
| fallback/utf8.auto.browser.js | safe | Cleared by Jev triage; no further analysis needed |
| fallback/utf8.auto.js | safe | Cleared by Jev triage; no further analysis needed |
| fallback/utf8.auto.native.js | safe | Cleared by Jev triage; no further analysis needed |
| fallback/utf8.js | safe | Cleared by Jev triage; no further analysis needed |
| hex.js | safe | Cleared by Jev triage; no further analysis needed |
| index.js | safe | No malicious patterns detected |
| multi-byte.js | safe | Cleared by Jev triage; no further analysis needed |
| multi-byte.node.js | safe | Cleared by Jev triage; no further analysis needed |
| single-byte.js | safe | Cleared by Jev triage; no further analysis needed |
| single-byte.node.js | safe | Cleared by Jev triage; no further analysis needed |
| utf16.browser.js | safe | Cleared by Jev triage; no further analysis needed |
| utf16.js | safe | The file only re-exports from a relative native module with no malicious patterns detected. |
| utf16.native.js | safe | No malicious patterns detected; the code is a benign UTF-16 encode/decode utility with feature detection for TextDecoder. |
| utf16.node.js | safe | No malicious patterns detected; the code is a standard UTF-16 encoding/decoding utility with no network, filesystem, process, or dynamic execution behavior. |
| utf8.js | safe | No malicious patterns detected; the code is a standard UTF-8 encoding/decoding utility with no exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
| utf8.node.js | safe | The code is a legitimate UTF-8 encoding/decoding utility with no malicious patterns; top-level initialization and use of Buffer.allocUnsafe are benign performance optimizations. |
| whatwg.js | safe | No malicious patterns detected; the code implements WHATWG percent-encoding logic using only local imports and standard URL encoding operations. |
| wif.js | safe | No malicious patterns detected; the code implements WIF encoding/decoding with strict validation and no network, filesystem, or dynamic execution behavior. |
Frequently asked questions
Is @exodus/bytes safe to use?
No confirmed malware was found in @exodus/bytes@1.15.1, but the review flagged 4 low severity findings for risky patterns worth checking before you rely on it.
Does @exodus/bytes contain malware?
No malware was identified in @exodus/bytes@1.15.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @exodus/bytes checked?
Togoder Security downloaded the published npm package and had an AI model read its 53 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @exodus/bytes together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @exodus/bytes@1.15.1, cost nothing.