Togoder security

npm package security report

@noble/curves@1.4.2 security report

No malicious code found.

No issues Version 1.4.2 Files reviewed 63 Size 755.6 KB Scanned

Summary

Togoder Security scanned the npm package @noble/curves@1.4.2 on Oct 4, 2026. An AI review of 63 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
0
low

Findings

No findings. The reviewer saw nothing malicious or risky in this version.

Files reviewed

FileVerdictWhat the reviewer saw
_shortw_utils.js safe No malicious patterns detected
abstract/bls.js safe No malicious patterns detected; the code implements BLS signature cryptography with no external calls, obfuscation, or suspicious behavior.
abstract/curve.js safe No malicious patterns detected
abstract/edwards.js safe No malicious patterns detected; the code is a legitimate implementation of twisted Edwards curve cryptography from the noble-curves library.
abstract/hash-to-curve.js safe No malicious patterns detected; the code is a standard cryptographic hash-to-curve implementation based on RFC 9380 with no network, filesystem, process, or dynamic execution activities.
abstract/modular.js safe No malicious patterns detected; this is a legitimate cryptographic utility module from noble-curves implementing modular arithmetic and finite field operations.
abstract/montgomery.js safe This is a legitimate implementation of the Montgomery curve (X25519/X448) from the noble-curves cryptographic library, with no malicious patterns detected.
abstract/poseidon.js safe No malicious patterns detected; the code is a legitimate implementation of the Poseidon hash function with input validation and no external network, filesystem, or process interactions.
abstract/utils.js safe No malicious patterns detected; the file is a legitimate collection of cryptographic utility functions from the noble-curves library with no network, filesystem, or code execution behavior.
abstract/weierstrass.js safe No malicious patterns detected; this is a legitimate implementation of Weierstrass elliptic curve cryptography from the noble-curves library with no data exfiltration, dynamic code execution, or suspicious behavior.
bls12-381.js safe No malicious patterns detected; the code is a legitimate BLS12-381 cryptographic implementation with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
bn254.js safe The code is a legitimate cryptographic curve definition from the noble-curves library with no malicious patterns detected.
ed25519.js safe This is a legitimate implementation of the Ed25519 elliptic curve cryptography from the noble-curves library; no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, network requests, or process spawning were detected.
ed448.js safe No malicious patterns detected
esm/_shortw_utils.js safe Cleared by Jev triage; no further analysis needed
esm/abstract/bls.js safe No malicious patterns detected; the code is a standard BLS signature implementation with no exfiltration, obfuscation, or dynamic execution.
esm/abstract/curve.js safe No malicious patterns detected in this cryptographic curve utility code from the noble-curves library.
esm/abstract/edwards.js safe No malicious patterns detected; the code is a legitimate implementation of the Twisted Edwards curve cryptography from the noble-curves library.
esm/abstract/hash-to-curve.js safe The code is a clean implementation of RFC 9380 hash-to-curve primitives with no malicious patterns, network calls, filesystem access, or dynamic code execution.
esm/abstract/modular.js safe No malicious patterns detected; the code implements standard modular arithmetic and field utilities for cryptographic purposes without any external communication, obfuscation, or system-level operations.
esm/abstract/montgomery.js safe No malicious patterns detected
esm/abstract/poseidon.js safe Cleared by Jev triage; no further analysis needed
esm/abstract/utils.js safe No malicious patterns detected
esm/abstract/weierstrass.js safe No malicious patterns detected; the file is a legitimate implementation of Weierstrass elliptic curve cryptography from the noble-curves library with no data exfiltration, credential harvesting, obfuscation, or backdoor behavior.
esm/bls12-381.js safe No malicious patterns detected; the code is a legitimate implementation of BLS12-381 cryptographic primitives from the noble-curves library.
Show 38 more files
FileVerdictWhat the reviewer saw
esm/bn254.js safe Cleared by Jev triage; no further analysis needed
esm/ed25519.js safe No malicious patterns detected
esm/ed448.js safe No malicious patterns detected
esm/index.js safe The file only throws an intentional error to prevent direct root module import and contains no malicious patterns.
esm/jubjub.js safe Cleared by Jev triage; no further analysis needed
esm/p256.js safe No malicious patterns detected; the code is a standard implementation of the NIST P-256 elliptic curve from the noble-curves library.
esm/p384.js safe This is a legitimate implementation of the NIST P-384 elliptic curve from the noble-curves library with no malicious patterns detected.
esm/p521.js safe No malicious patterns detected; this is a standard cryptographic implementation of NIST P-521 elliptic curve in the noble-curves library with no network, file system, process execution, or dynamic code loading behavior.
esm/pasta.js safe Cleared by Jev triage; no further analysis needed
esm/secp256k1.js safe No malicious patterns detected; this is the standard noble-curves secp256k1 implementation with no exfiltration, credential harvesting, obfuscation, or dynamic execution.
index.js safe The module immediately throws an error instructing users to import submodules, with no malicious patterns, network activity, credential access, or dynamic execution.
jubjub.js safe No malicious patterns detected
p256.js safe No malicious patterns detected
p384.js safe No malicious patterns detected; this is a legitimate NIST P-384 elliptic curve implementation from the noble-curves library.
p521.js safe No malicious patterns detected; the file is a legitimate cryptographic implementation of NIST P-521 curve from the noble-curves library.
pasta.js safe No malicious patterns detected
secp256k1.js safe No malicious patterns detected; the code implements legitimate secp256k1 elliptic curve cryptography from the noble-curves library.
src/_shortw_utils.ts safe Cleared by Jev triage; no further analysis needed
src/abstract/bls.ts safe No malicious patterns detected; the code is a legitimate BLS signature cryptographic library implementation.
src/abstract/curve.ts safe No malicious patterns detected; the code implements elliptic curve arithmetic utilities with no network, filesystem, process, or obfuscated behavior.
src/abstract/edwards.ts safe No malicious patterns detected
src/abstract/hash-to-curve.ts safe No malicious patterns detected; the code is a legitimate cryptographic hash-to-curve implementation from the noble-curves library with no exfiltration, credential harvesting, obfuscation, or other red flags.
src/abstract/modular.ts safe No malicious patterns detected
src/abstract/montgomery.ts safe No malicious patterns detected
src/abstract/poseidon.ts safe Cleared by Jev triage; no further analysis needed
src/abstract/utils.ts safe No malicious patterns detected; the code is a collection of cryptographic utility functions from the noble-curves library with standard validation and HMAC-DRBG implementation.
src/abstract/weierstrass.ts safe No malicious patterns detected; the code is a legitimate cryptographic library implementation for elliptic curve operations.
src/bls12-381.ts safe No malicious patterns detected; the file is a standard cryptographic implementation of BLS12-381 (noble-curves) with no exfiltration, credential harvesting, obfuscation, dynamic execution, or suspicious network/process activity.
src/bn254.ts safe Cleared by Jev triage; no further analysis needed
src/ed25519.ts safe No malicious patterns detected; the code is a legitimate cryptographic library implementation for Ed25519, X25519, and Ristretto255 curves.
src/ed448.ts safe No malicious patterns detected; this is a legitimate cryptographic implementation of Ed448, X448, and Decaf448 from the well-known noble-curves library.
src/index.ts safe No malicious patterns detected
src/jubjub.ts safe Cleared by Jev triage; no further analysis needed
src/p256.ts safe No malicious patterns detected; this is a standard cryptographic implementation of NIST P-256 curve operations.
src/p384.ts safe No malicious patterns detected; the file is a legitimate implementation of the NIST P-384 elliptic curve from the noble-curves library.
src/p521.ts safe No malicious patterns detected; this is a legitimate cryptographic implementation of the NIST P-521 elliptic curve from the noble-curves library.
src/pasta.ts safe No malicious patterns detected; the file defines standard elliptic curve parameters for Pallas and Vesta using the noble-curves library.
src/secp256k1.ts safe No malicious patterns detected; the code is a legitimate implementation of secp256k1 elliptic curve cryptography from the noble-curves library.

Affected version ranges

None of the 5 scanned versions of @noble/curves are flagged high or critical. The latest scanned version, 1.9.7, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

1.2.01.9.7
VersionsVerdictCountRangeTop findings
1.9.1 – 1.9.7 No issues 2 >=1.9.1 <=1.9.7
1.8.2 – 1.9.0 Not scanned 2 >=1.8.2 <=1.9.0
1.4.2 – 1.8.1 No issues 3 >=1.4.2 <=1.8.1
1.2.0 Not scanned 1 1.2.0

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of @noble/curves

VersionVerdictFilesScanned
1.9.7 No issues 78 Oct 4, 2026
1.9.1 No issues 75 Oct 4, 2026
1.8.1 No issues 66 Oct 4, 2026
1.8.0 No issues 66 Oct 4, 2026
1.4.2 No issues 63 Oct 4, 2026

Frequently asked questions

Is @noble/curves safe to use?

Our AI source review of @noble/curves@1.4.2 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does @noble/curves contain malware?

No malware was identified in @noble/curves@1.4.2 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @noble/curves checked?

Togoder Security downloaded the published npm package and had an AI model read its 63 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @noble/curves together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @noble/curves@1.4.2, cost nothing.

Related security reports