Togoder security

npm package security report

@noble/curves npm package: is it safe?

No malicious code found.

No issues Version 1.9.7 Files reviewed 78 Size 1.0 MB Scanned

Summary

Togoder Security scanned the npm package @noble/curves@1.9.7 on Oct 4, 2026. An AI review of 78 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
1
low

Findings 1

low

intentional_import_guard

NPS-B65BAC756F6F

The root module throws an Error when imported directly, instructing users to import submodules instead. This is a deliberate design choice by the @noble/curves library to prevent importing the root entry point, which would load all curve variants. It is not a malicious pattern; no data exfiltration, credential harvesting, obfuscation, dynamic execution, network activity, filesystem manipulation, or process spawning is present.

esm/index.js:14

Files reviewed

FileVerdictWhat the reviewer saw
_shortw_utils.js safe No malicious patterns detected
abstract/bls.js safe No malicious patterns detected; the code is a standard cryptographic implementation for BLS signatures with no signs of data exfiltration, environment harvesting, dynamic code execution, or other security concerns.
abstract/curve.js safe This is the legitimate noble-curves elliptic curve cryptography library; no malicious patterns, data exfiltration, obfuscation, or backdoors were detected.
abstract/edwards.js safe No malicious patterns detected; this is a legitimate implementation of twisted Edwards curve cryptography from the noble-curves library.
abstract/fft.js safe No malicious patterns detected; the code is a pure mathematical FFT/NTT implementation with no network, filesystem, process, or dynamic execution behavior.
abstract/hash-to-curve.js safe No malicious patterns detected
abstract/modular.js safe No malicious patterns detected; the code is a legitimate cryptographic modular arithmetic utility from the noble-curves library.
abstract/montgomery.js safe This is a legitimate implementation of the Montgomery curve ladder for X25519/X448 cryptography from the noble-curves library with no malicious patterns detected.
abstract/poseidon.js safe No malicious patterns detected; this is a legitimate cryptographic hash implementation with no data exfiltration, credential harvesting, obfuscation, or other red flags.
abstract/tower.js safe No malicious patterns detected
abstract/utils.js safe No malicious patterns detected; this is a deprecated re-export shim forwarding utility functions from a local module.
abstract/weierstrass.js safe No malicious patterns detected; this is the legitimate noble-curves elliptic curve cryptography library implementing standard ECDH/ECDSA with no exfiltration, backdoors, or suspicious behavior.
bls12-381.js safe This is a legitimate BLS12-381 elliptic curve cryptography implementation from the noble-curves library with no malicious patterns detected.
bn254.js safe No malicious patterns detected; this is a legitimate implementation of the bn254 elliptic curve from the noble-curves library.
ed25519.js safe This file is the legitimate open-source noble-curves ed25519 implementation containing only cryptographic curve math and no malicious patterns such as exfiltration, credential harvesting, obfuscation, or process spawning.
ed448.js safe No malicious patterns detected; this is a legitimate cryptographic library implementation for Ed448 and related curves from the noble-curves project.
esm/_shortw_utils.js safe Cleared by Jev triage; no further analysis needed
esm/abstract/bls.js safe No malicious patterns detected in the BLS signature implementation from the noble-curves library.
esm/abstract/curve.js safe No malicious patterns detected; the file implements well-known cryptographic algorithms from the noble-curves library with no network, filesystem, process, or obfuscated code.
esm/abstract/edwards.js safe No malicious patterns detected; the code is a legitimate cryptographic implementation of the Twisted Edwards curve and EdDSA.
esm/abstract/fft.js safe Cleared by Jev triage; no further analysis needed
esm/abstract/hash-to-curve.js safe No malicious patterns detected; the code is a standard cryptographic hash-to-curve implementation.
esm/abstract/modular.js safe No malicious patterns detected; the file is a legitimate cryptographic modular arithmetic utility from the noble-curves library.
esm/abstract/montgomery.js safe No malicious patterns detected; the code is a legitimate implementation of Montgomery curve operations from the noble-curves cryptographic library.
esm/abstract/poseidon.js safe No malicious patterns detected
Show 53 more files
FileVerdictWhat the reviewer saw
esm/abstract/tower.js safe Cleared by Jev triage; no further analysis needed
esm/abstract/utils.js safe Cleared by Jev triage; no further analysis needed
esm/abstract/weierstrass.js safe The code is a standard implementation of elliptic curve cryptography (Weierstrass curves) from the noble-curves library, with no malicious patterns detected.
esm/bls12-381.js safe No malicious patterns detected
esm/bn254.js safe No malicious patterns detected in this bn254 elliptic curve implementation; it is a legitimate cryptographic library module with no data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
esm/ed25519.js safe No malicious patterns detected; this is a legitimate cryptographic library implementation of Ed25519, X25519, and Ristretto255 from noble-curves.
esm/ed448.js safe No malicious patterns detected; the file is a legitimate cryptographic implementation for the Noble Curves library (Ed448, X448, Decaf448).
esm/index.js safe The file is a benign guard that prevents direct import of the package root, with no malicious behavior detected.
esm/jubjub.js safe Cleared by Jev triage; no further analysis needed
esm/misc.js safe No malicious patterns detected
esm/nist.js safe This is a legitimate cryptographic library implementation for NIST P256/P384/P521 curves with no malicious patterns detected.
esm/p256.js safe Cleared by Jev triage; no further analysis needed
esm/p384.js safe Cleared by Jev triage; no further analysis needed
esm/p521.js safe Cleared by Jev triage; no further analysis needed
esm/pasta.js safe Cleared by Jev triage; no further analysis needed
esm/secp256k1.js safe No malicious patterns detected in this secp256k1 elliptic curve implementation from the noble-curves library.
esm/utils.js safe No malicious patterns detected; the file contains only legitimate cryptographic utility functions for the noble-curves library.
index.js safe The file is a harmless guard that prevents direct import of the package root, with no malicious patterns detected
jubjub.js safe No malicious patterns detected; the file is a simple deprecated re-export shim for @noble/curves with no dynamic execution, network, filesystem, or process activity.
misc.js safe No malicious patterns detected in this cryptographic curve implementation from noble-curves.
nist.js safe This is a legitimate implementation of NIST elliptic curves from the noble-curves library with no malicious patterns detected.
p256.js safe No malicious patterns detected in this deprecation shim that only re-exports p256 curve functions from the internal nist module.
p384.js safe This is a simple deprecated re-export shim for the @noble/curves library's P-384 implementation, containing no malicious patterns, network activity, credential harvesting, or dynamic code execution.
p521.js safe No malicious patterns detected; file only re-exports deprecated curve utilities from a local nist module.
pasta.js safe No malicious patterns detected; the file only re-exports deprecated functions from a local module.
secp256k1.js safe No malicious patterns detected; the code is a legitimate implementation of secp256k1 elliptic curve cryptography from the noble-curves library.
src/_shortw_utils.ts safe Cleared by Jev triage; no further analysis needed
src/abstract/bls.ts safe No malicious patterns detected; the file is a legitimate BLS signature implementation with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
src/abstract/curve.ts safe The code is a clean implementation of elliptic curve multiplication algorithms (wNAF, Pippenger) from the noble-curves library with no malicious patterns detected.
src/abstract/edwards.ts safe This is a legitimate cryptographic implementation of Edwards curves from the noble-curves library with no malicious patterns detected.
src/abstract/fft.ts safe No malicious patterns detected; the code is a pure TypeScript implementation of NTT/FFT over finite fields with no network, filesystem, process execution, or obfuscated behavior.
src/abstract/hash-to-curve.ts safe No malicious patterns detected; the file is a legitimate cryptographic hash-to-curve implementation from noble-curves following RFC 9380 with no external communication, credential access, or dynamic code execution.
src/abstract/modular.ts safe No malicious patterns detected; the code is a legitimate cryptographic utility library for modular arithmetic and finite fields.
src/abstract/montgomery.ts safe No malicious patterns detected; the code is a standard implementation of X25519/X448 Montgomery curve cryptography from the noble-curves library.
src/abstract/poseidon.ts safe No malicious patterns detected; the code is a legitimate Poseidon hash implementation with only mathematical operations and validation logic.
src/abstract/tower.ts safe Cleared by Jev triage; no further analysis needed
src/abstract/utils.ts safe This is a deprecated re-export module that simply aliases utility functions from a sibling module without any malicious patterns.
src/abstract/weierstrass.ts safe No malicious patterns detected
src/bls12-381.ts safe No malicious patterns detected; the file is a legitimate BLS12-381 cryptographic curve implementation with no data exfiltration, credential harvesting, obfuscation, dynamic execution, or suspicious network/process activity.
src/bn254.ts safe No malicious patterns detected in this cryptographic curve implementation for bn254.
src/ed25519.ts safe This is the legitimate noble-curves ed25519 implementation containing only cryptographic primitives, mathematical operations, and no malicious patterns.
src/ed448.ts safe No malicious patterns detected; the code is a legitimate cryptographic implementation of Ed448/Decaf448 from the noble-curves library with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior.
src/index.ts safe No malicious patterns detected; the file only throws an informative error directing users to import submodules.
src/jubjub.ts safe Cleared by Jev triage; no further analysis needed
src/misc.ts safe Cleared by Jev triage; no further analysis needed
src/nist.ts safe No malicious patterns detected; the file contains standard NIST elliptic curve definitions and RFC 9380 hashing logic from the noble-curves library.
src/p256.ts safe No malicious patterns detected
src/p384.ts safe No malicious patterns detected; this is a thin deprecated re-export wrapper for the noble-curves p384 implementation.
src/p521.ts safe No malicious patterns detected; this is a benign re-export module for the noble-curves p521 implementation.
src/pasta.ts safe Cleared by Jev triage; no further analysis needed
src/secp256k1.ts safe No malicious patterns detected; this is a legitimate, standard implementation of secp256k1 cryptography from the noble-curves library with no data exfiltration, obfuscation, dynamic execution, or suspicious behavior.
src/utils.ts safe No malicious patterns detected; this is a legitimate cryptographic utility module from the noble-curves library with standard byte/number/hex conversion and validation functions.
utils.js safe No malicious patterns detected; this is a legitimate cryptographic utility library (noble-curves) performing standard byte/number conversions, validation, and HMAC-DRBG operations without any exfiltration, dynamic code execution, or process spawning.

Affected version ranges

None of the 5 scanned versions of @noble/curves are flagged high or critical. The latest scanned version, 1.9.7, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

1.2.01.9.7
VersionsVerdictCountRangeTop findings
1.9.1 – 1.9.7 No issues 2 >=1.9.1 <=1.9.7
1.8.2 – 1.9.0 Not scanned 2 >=1.8.2 <=1.9.0
1.4.2 – 1.8.1 No issues 3 >=1.4.2 <=1.8.1
1.2.0 Not scanned 1 1.2.0

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of @noble/curves

VersionVerdictFilesScanned
1.9.7 No issues 78 Oct 4, 2026
1.9.1 No issues 75 Oct 4, 2026
1.8.1 No issues 66 Oct 4, 2026
1.8.0 No issues 66 Oct 4, 2026
1.4.2 No issues 63 Oct 4, 2026

Frequently asked questions

Is @noble/curves safe to use?

Our AI source review of @noble/curves@1.9.7 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does @noble/curves contain malware?

No malware was identified in @noble/curves@1.9.7 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @noble/curves checked?

Togoder Security downloaded the published npm package and had an AI model read its 78 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @noble/curves together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @noble/curves@1.9.7, cost nothing.

Related security reports