Togoder security

npm package security report

@noble/ciphers npm package: is it safe?

No malicious code found.

No issues Version 1.3.0 Files reviewed 42 Size 357.6 KB Scanned

Summary

Togoder Security scanned the npm package @noble/ciphers@1.3.0 on Oct 4, 2026. An AI review of 42 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
1
low

Findings 1

low

Intentional import guard

NPS-C7FEC5C5CACF

The file throws an error when imported directly and exports nothing. This is a deliberate design pattern to prevent importing the root module and force users to import specific submodules. It does not execute any malicious code, access environment variables, perform network requests, or manipulate the filesystem.

esm/index.js:31

Files reviewed

FileVerdictWhat the reviewer saw
_arx.js safe No malicious patterns detected; the code is a legitimate implementation of ARX-based ciphers (Salsa/ChaCha) with no data exfiltration, obfuscation, or other security concerns.
_assert.js safe No malicious patterns detected; the file only re-exports deprecated assertion helpers from an internal utility module.
_micro.js safe No malicious patterns detected; the code is a legitimate implementation of Salsa20, ChaCha20, and Poly1305 ciphers from the noble-ciphers library.
_poly1305.js safe No malicious patterns detected; the code is a standard Poly1305 MAC implementation with no network, filesystem, process, or obfuscation concerns.
_polyval.js safe No malicious patterns detected; the code is a legitimate cryptographic implementation of GHASH/POLYVAL with no suspicious network, filesystem, process, or dynamic execution behavior.
aes.js safe No malicious patterns detected; the file is a legitimate pure-JS AES implementation with only internal crypto operations and no network, filesystem, process, or dynamic-code behavior.
chacha.js safe This is a legitimate implementation of ChaCha20 and XChaCha20-Poly1305 cryptographic algorithms from the @noble/ciphers library, with no malicious patterns detected.
crypto.js safe No malicious patterns detected; the file is a harmless utility that exports the global crypto object if available.
cryptoNode.js safe No malicious patterns detected; the code simply provides a WebCrypto alias using Node.js built-in crypto module.
esm/_arx.js safe Cleared by Jev triage; no further analysis needed
esm/_assert.js safe Cleared by Jev triage; no further analysis needed
esm/_micro.js safe Cleared by Jev triage; no further analysis needed
esm/_poly1305.js safe This is a legitimate implementation of the Poly1305 message authentication code with no malicious patterns detected.
esm/_polyval.js safe No malicious patterns detected; the code is a legitimate cryptographic implementation of GHASH and Polyval from the @noble/hashes library.
esm/aes.js safe This is a legitimate pure JavaScript implementation of AES cryptographic primitives with no malicious patterns, network calls, process spawning, or credential harvesting.
esm/chacha.js safe No malicious patterns detected; the file contains a standard implementation of the ChaCha20 stream cipher and related AEAD constructions.
esm/crypto.js safe Cleared by Jev triage; no further analysis needed
esm/cryptoNode.js safe Cleared by Jev triage; no further analysis needed
esm/ff1.js safe No malicious patterns detected
esm/index.js safe The code is a benign root module guard that throws an error to enforce submodule imports; no malicious patterns were detected.
esm/salsa.js safe This is a legitimate implementation of the Salsa20/XSalsa20 stream cipher and XSalsa20-Poly1305 authenticated encryption with no malicious patterns detected.
esm/utils.js safe No malicious patterns detected; the code is a legitimate utility module from the noble-ciphers library with no network, filesystem, process, or obfuscated behavior.
esm/webcrypto.js safe No malicious patterns detected; the code is a legitimate WebCrypto AES implementation for the @noble/ciphers library.
ff1.js safe The code implements the NIST FF1 format-preserving encryption algorithm with no evidence of malicious behavior, data exfiltration, or other red flags.
index.js safe The file is an intentional entry-point guard that throws an error to prevent root module import; no malicious patterns detected.
Show 17 more files
FileVerdictWhat the reviewer saw
salsa.js safe No malicious patterns detected; the code is a legitimate implementation of the Salsa20 cipher family.
src/_arx.ts safe Cleared by Jev triage; no further analysis needed
src/_assert.ts safe Cleared by Jev triage; no further analysis needed
src/_micro.ts safe Cleared by Jev triage; no further analysis needed
src/_poly1305.ts safe This is a standard, clean-room implementation of the Poly1305 message authentication code based on public domain poly1305-donna, with no malicious patterns detected.
src/_polyval.ts safe No malicious patterns detected; the file is a legitimate cryptographic implementation of GHASH/Polyval with no network, filesystem, process, or obfuscation concerns.
src/aes.ts safe No malicious patterns detected; this is a legitimate AES cryptographic implementation with no network, filesystem, process, or dynamic execution behavior.
src/chacha.ts safe Cleared by Jev triage; no further analysis needed
src/crypto.ts safe Cleared by Jev triage; no further analysis needed
src/cryptoNode.ts safe Cleared by Jev triage; no further analysis needed
src/ff1.ts safe No malicious patterns detected; the code is a legitimate implementation of the NIST SP 800-38G FF1 format-preserving encryption algorithm.
src/index.ts safe The file intentionally throws an error at import time to prevent root module usage; no malicious patterns detected.
src/salsa.ts safe Cleared by Jev triage; no further analysis needed
src/utils.ts safe No malicious patterns detected; the code is a standard cryptographic utilities module with only local byte/hex/cipher helper functions.
src/webcrypto.ts safe The code is a legitimate WebCrypto AES encryption utility with no malicious patterns detected.
utils.js safe No malicious patterns detected; the code is a standard cryptographic utility module with only defensive validation and no exfiltration, obfuscation, or process spawning.
webcrypto.js safe No malicious patterns detected; the code is a legitimate WebCrypto AES implementation from the @noble/ciphers library with no data exfiltration, credential harvesting, obfuscation, or backdoor behavior.

Affected version ranges

None of the 2 scanned versions of @noble/ciphers are flagged high or critical. The latest scanned version, 2.2.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

1.2.12.2.0
VersionsVerdictCountRangeTop findings
2.2.0 Not scanned 1 2.2.0
1.3.0 No issues 1 1.3.0
1.2.1 Needs review 1 1.2.1

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of @noble/ciphers

VersionVerdictFilesScanned
1.3.0 No issues 42 Oct 4, 2026
1.2.1 Needs review 42 Oct 4, 2026

Frequently asked questions

Is @noble/ciphers safe to use?

Our AI source review of @noble/ciphers@1.3.0 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does @noble/ciphers contain malware?

No malware was identified in @noble/ciphers@1.3.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @noble/ciphers checked?

Togoder Security downloaded the published npm package and had an AI model read its 42 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @noble/ciphers together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @noble/ciphers@1.3.0, cost nothing.

Related security reports