# @noble/ciphers@1.2.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:09:33.000Z
- Files reviewed: 42
- Findings: 1 low severity finding
- Report: https://security.togoder.click/npm/@noble/ciphers@1.2.1
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @noble/ciphers@1.2.1 on Oct 4, 2026. An AI review of 42 source files produced 1 low severity finding. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] Import-time side effect

Finding ID: `NPS-466428AD642F`

File: `src/index.ts:24`

The module contains top-level code that throws an Error immediately upon import, which is intentional to prevent direct root module import. While not malicious, it is a deliberate import-time side effect that alters expected module behavior and could break tooling or cause unexpected failures if imported accidentally.

## Files reviewed

- `src/index.ts` (medium): The file is a standard cryptographic library entry point that intentionally throws on import; no malicious patterns were detected, though the deliberate top-level throw is a minor import-time side effect.
- `_arx.js` (safe): No malicious patterns detected
- `_assert.js` (safe): Cleared by Jev triage; no further analysis needed
- `_micro.js` (safe): No malicious patterns detected; the file is a legitimate cryptographic implementation (Salsa20/ChaCha20/Poly1305) from the noble-ciphers library with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `_poly1305.js` (safe): No malicious patterns detected
- `_polyval.js` (safe): No malicious patterns detected; the file is a legitimate cryptographic implementation of GHASH and POLYVAL with no network, filesystem, process, or obfuscation red flags.
- `aes.js` (safe): No malicious patterns detected in this pure JavaScript AES implementation.
- `chacha.js` (safe): This file is a legitimate ChaCha20-Poly1305 cipher implementation from the @noble/ciphers library with no malicious patterns detected.
- `crypto.js` (safe): No malicious patterns detected; the file is a harmless utility that exports the global crypto object if available.
- `cryptoNode.js` (safe): No malicious patterns detected; the code simply provides a WebCrypto alias using Node.js built-in crypto module.
- `esm/_arx.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_assert.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_micro.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_poly1305.js` (safe): The code is a legitimate implementation of the Poly1305 MAC algorithm from the @noble/hashes library, with no malicious patterns detected.
- `esm/_polyval.js` (safe): No malicious patterns detected; the code is a legitimate cryptographic implementation of GHASH/POLYVAL for AES-GCM and AES-SIV with no external calls, obfuscation, credential access, or process spawning.
- `esm/aes.js` (safe): No malicious patterns detected; the file is a standard pure-JS AES implementation with CTR, ECB, CBC, CFB, GCM, SIV, and key-wrap modes, using only local utility imports and no network, process, filesystem, or dynamic code execution.
- `esm/chacha.js` (safe): No malicious patterns detected; the code is a legitimate ChaCha20/XChaCha20 cipher implementation without exfiltration, obfuscation, or dynamic execution.
- `esm/crypto.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/cryptoNode.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/ff1.js` (safe): No malicious patterns detected; the code is a legitimate implementation of the NIST FF1 format-preserving encryption algorithm with no network, filesystem, or process manipulation.
- `esm/index.js` (safe): No malicious patterns detected; the file only throws an error to enforce submodule imports and contains no executable payloads, network access, file system manipulation, or credential harvesting.
- `esm/salsa.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/utils.js` (safe): No malicious patterns detected; the code is a benign collection of cryptographic utility functions for hex/byte conversion, byte alignment, and cipher wrapping.
- `esm/webcrypto.js` (safe): No malicious patterns detected; the code is a legitimate WebCrypto AES wrapper from @noble/ciphers with no exfiltration, credential harvesting, obfuscation, or backdoor behavior.
- `ff1.js` (safe): No malicious patterns detected; the code is a standard implementation of the NIST FF1 format-preserving encryption algorithm.
- `index.js` (safe): No malicious patterns detected
- `salsa.js` (safe): No malicious patterns detected; the code implements the Salsa20/XSalsa20/Poly1305 cryptographic algorithms as expected.
- `src/_arx.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/_assert.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/_micro.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/_poly1305.ts` (safe): No malicious patterns detected; the code is a clean TypeScript implementation of the Poly1305 message authentication code.
- `src/_polyval.ts` (safe): No malicious patterns detected; the code is a standard cryptographic implementation of GHASH/Polyval with no exfiltration, obfuscation, or suspicious behavior.
- `src/aes.ts` (safe): This is a legitimate pure-JS AES implementation with no malicious patterns detected.
- `src/chacha.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/crypto.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/cryptoNode.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/ff1.ts` (safe): This is a legitimate implementation of the NIST SP 800-38G FF1 format-preserving encryption algorithm with no malicious patterns detected.
- `src/salsa.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/utils.ts` (safe): No malicious patterns detected; the code contains standard cryptographic utility functions from the noble-ciphers library with no exfiltration, credential harvesting, obfuscation, or other security concerns.
- `src/webcrypto.ts` (safe): The code is a legitimate WebCrypto-based AES encryption utility with no malicious patterns, network exfiltration, credential harvesting, or dynamic code execution.
- `utils.js` (safe): No malicious patterns detected; the file contains cryptographic utility functions with no network, filesystem, process, or dynamic execution behavior.
- `webcrypto.js` (safe): No malicious patterns detected; this is a legitimate WebCrypto AES encryption utility with secure random number generation and no exfiltration, obfuscation, or process execution.

## Version ranges

None of the 2 scanned versions of @noble/ciphers are flagged high or critical. The latest scanned version, 2.2.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 2.2.0 (`2.2.0`): not scanned
- 1.3.0 (`1.3.0`): clean
- 1.2.1 (`1.2.1`): medium

## Scanned versions

- [1.3.0](https://security.togoder.click/npm/@noble/ciphers@1.3.0): safe, 2026-10-04T16:08:53.000Z
- [1.2.1](https://security.togoder.click/npm/@noble/ciphers@1.2.1): medium, 2026-10-04T16:09:33.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
