Summary
Togoder Security scanned the npm package @noble/ciphers@1.2.1 on Oct 4, 2026. An AI review of 42 source files produced 1 low severity finding. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 1
Import-time side effect
NPS-466428AD642F
The module contains top-level code that throws an Error immediately upon import, which is intentional to prevent direct root module import. While not malicious, it is a deliberate import-time side effect that alters expected module behavior and could break tooling or cause unexpected failures if imported accidentally.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| src/index.ts | medium | The file is a standard cryptographic library entry point that intentionally throws on import; no malicious patterns were detected, though the deliberate top-level throw is a minor import-time side effect. |
| _arx.js | safe | No malicious patterns detected |
| _assert.js | safe | Cleared by Jev triage; no further analysis needed |
| _micro.js | safe | No malicious patterns detected; the file is a legitimate cryptographic implementation (Salsa20/ChaCha20/Poly1305) from the noble-ciphers library with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| _poly1305.js | safe | No malicious patterns detected |
| _polyval.js | safe | No malicious patterns detected; the file is a legitimate cryptographic implementation of GHASH and POLYVAL with no network, filesystem, process, or obfuscation red flags. |
| aes.js | safe | No malicious patterns detected in this pure JavaScript AES implementation. |
| chacha.js | safe | This file is a legitimate ChaCha20-Poly1305 cipher implementation from the @noble/ciphers library with no malicious patterns detected. |
| crypto.js | safe | No malicious patterns detected; the file is a harmless utility that exports the global crypto object if available. |
| cryptoNode.js | safe | No malicious patterns detected; the code simply provides a WebCrypto alias using Node.js built-in crypto module. |
| esm/_arx.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/_assert.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/_micro.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/_poly1305.js | safe | The code is a legitimate implementation of the Poly1305 MAC algorithm from the @noble/hashes library, with no malicious patterns detected. |
| esm/_polyval.js | safe | No malicious patterns detected; the code is a legitimate cryptographic implementation of GHASH/POLYVAL for AES-GCM and AES-SIV with no external calls, obfuscation, credential access, or process spawning. |
| esm/aes.js | safe | No malicious patterns detected; the file is a standard pure-JS AES implementation with CTR, ECB, CBC, CFB, GCM, SIV, and key-wrap modes, using only local utility imports and no network, process, filesystem, or dynamic code execution. |
| esm/chacha.js | safe | No malicious patterns detected; the code is a legitimate ChaCha20/XChaCha20 cipher implementation without exfiltration, obfuscation, or dynamic execution. |
| esm/crypto.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/cryptoNode.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/ff1.js | safe | No malicious patterns detected; the code is a legitimate implementation of the NIST FF1 format-preserving encryption algorithm with no network, filesystem, or process manipulation. |
| esm/index.js | safe | No malicious patterns detected; the file only throws an error to enforce submodule imports and contains no executable payloads, network access, file system manipulation, or credential harvesting. |
| esm/salsa.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/utils.js | safe | No malicious patterns detected; the code is a benign collection of cryptographic utility functions for hex/byte conversion, byte alignment, and cipher wrapping. |
| esm/webcrypto.js | safe | No malicious patterns detected; the code is a legitimate WebCrypto AES wrapper from @noble/ciphers with no exfiltration, credential harvesting, obfuscation, or backdoor behavior. |
| ff1.js | safe | No malicious patterns detected; the code is a standard implementation of the NIST FF1 format-preserving encryption algorithm. |
Show 17 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| index.js | safe | No malicious patterns detected |
| salsa.js | safe | No malicious patterns detected; the code implements the Salsa20/XSalsa20/Poly1305 cryptographic algorithms as expected. |
| src/_arx.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/_assert.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/_micro.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/_poly1305.ts | safe | No malicious patterns detected; the code is a clean TypeScript implementation of the Poly1305 message authentication code. |
| src/_polyval.ts | safe | No malicious patterns detected; the code is a standard cryptographic implementation of GHASH/Polyval with no exfiltration, obfuscation, or suspicious behavior. |
| src/aes.ts | safe | This is a legitimate pure-JS AES implementation with no malicious patterns detected. |
| src/chacha.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/crypto.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/cryptoNode.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/ff1.ts | safe | This is a legitimate implementation of the NIST SP 800-38G FF1 format-preserving encryption algorithm with no malicious patterns detected. |
| src/salsa.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/utils.ts | safe | No malicious patterns detected; the code contains standard cryptographic utility functions from the noble-ciphers library with no exfiltration, credential harvesting, obfuscation, or other security concerns. |
| src/webcrypto.ts | safe | The code is a legitimate WebCrypto-based AES encryption utility with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution. |
| utils.js | safe | No malicious patterns detected; the file contains cryptographic utility functions with no network, filesystem, process, or dynamic execution behavior. |
| webcrypto.js | safe | No malicious patterns detected; this is a legitimate WebCrypto AES encryption utility with secure random number generation and no exfiltration, obfuscation, or process execution. |
Affected version ranges
None of the 2 scanned versions of @noble/ciphers are flagged high or critical. The latest scanned version, 2.2.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 2.2.0 | Not scanned | 1 | 2.2.0 | |
| 1.3.0 | No issues | 1 | 1.3.0 | |
| 1.2.1 | Needs review | 1 | 1.2.1 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of @noble/ciphers
Frequently asked questions
Is @noble/ciphers safe to use?
No confirmed malware was found in @noble/ciphers@1.2.1, but the review flagged 1 low severity finding for risky patterns worth checking before you rely on it.
Does @noble/ciphers contain malware?
No malware was identified in @noble/ciphers@1.2.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @noble/ciphers checked?
Togoder Security downloaded the published npm package and had an AI model read its 42 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @noble/ciphers together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @noble/ciphers@1.2.1, cost nothing.