# @noble/curves@1.4.2 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:30:03.000Z
- Files reviewed: 63
- Findings: no findings
- Report: https://security.togoder.click/npm/@noble/curves@1.4.2
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @noble/curves@1.4.2 on Oct 4, 2026. An AI review of 63 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `_shortw_utils.js` (safe): No malicious patterns detected
- `abstract/bls.js` (safe): No malicious patterns detected; the code implements BLS signature cryptography with no external calls, obfuscation, or suspicious behavior.
- `abstract/curve.js` (safe): No malicious patterns detected
- `abstract/edwards.js` (safe): No malicious patterns detected; the code is a legitimate implementation of twisted Edwards curve cryptography from the noble-curves library.
- `abstract/hash-to-curve.js` (safe): No malicious patterns detected; the code is a standard cryptographic hash-to-curve implementation based on RFC 9380 with no network, filesystem, process, or dynamic execution activities.
- `abstract/modular.js` (safe): No malicious patterns detected; this is a legitimate cryptographic utility module from noble-curves implementing modular arithmetic and finite field operations.
- `abstract/montgomery.js` (safe): This is a legitimate implementation of the Montgomery curve (X25519/X448) from the noble-curves cryptographic library, with no malicious patterns detected.
- `abstract/poseidon.js` (safe): No malicious patterns detected; the code is a legitimate implementation of the Poseidon hash function with input validation and no external network, filesystem, or process interactions.
- `abstract/utils.js` (safe): No malicious patterns detected; the file is a legitimate collection of cryptographic utility functions from the noble-curves library with no network, filesystem, or code execution behavior.
- `abstract/weierstrass.js` (safe): No malicious patterns detected; this is a legitimate implementation of Weierstrass elliptic curve cryptography from the noble-curves library with no data exfiltration, dynamic code execution, or suspicious behavior.
- `bls12-381.js` (safe): No malicious patterns detected; the code is a legitimate BLS12-381 cryptographic implementation with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `bn254.js` (safe): The code is a legitimate cryptographic curve definition from the noble-curves library with no malicious patterns detected.
- `ed25519.js` (safe): This is a legitimate implementation of the Ed25519 elliptic curve cryptography from the noble-curves library; no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, network requests, or process spawning were detected.
- `ed448.js` (safe): No malicious patterns detected
- `esm/_shortw_utils.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/abstract/bls.js` (safe): No malicious patterns detected; the code is a standard BLS signature implementation with no exfiltration, obfuscation, or dynamic execution.
- `esm/abstract/curve.js` (safe): No malicious patterns detected in this cryptographic curve utility code from the noble-curves library.
- `esm/abstract/edwards.js` (safe): No malicious patterns detected; the code is a legitimate implementation of the Twisted Edwards curve cryptography from the noble-curves library.
- `esm/abstract/hash-to-curve.js` (safe): The code is a clean implementation of RFC 9380 hash-to-curve primitives with no malicious patterns, network calls, filesystem access, or dynamic code execution.
- `esm/abstract/modular.js` (safe): No malicious patterns detected; the code implements standard modular arithmetic and field utilities for cryptographic purposes without any external communication, obfuscation, or system-level operations.
- `esm/abstract/montgomery.js` (safe): No malicious patterns detected
- `esm/abstract/poseidon.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/abstract/utils.js` (safe): No malicious patterns detected
- `esm/abstract/weierstrass.js` (safe): No malicious patterns detected; the file is a legitimate implementation of Weierstrass elliptic curve cryptography from the noble-curves library with no data exfiltration, credential harvesting, obfuscation, or backdoor behavior.
- `esm/bls12-381.js` (safe): No malicious patterns detected; the code is a legitimate implementation of BLS12-381 cryptographic primitives from the noble-curves library.
- `esm/bn254.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/ed25519.js` (safe): No malicious patterns detected
- `esm/ed448.js` (safe): No malicious patterns detected
- `esm/index.js` (safe): The file only throws an intentional error to prevent direct root module import and contains no malicious patterns.
- `esm/jubjub.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/p256.js` (safe): No malicious patterns detected; the code is a standard implementation of the NIST P-256 elliptic curve from the noble-curves library.
- `esm/p384.js` (safe): This is a legitimate implementation of the NIST P-384 elliptic curve from the noble-curves library with no malicious patterns detected.
- `esm/p521.js` (safe): No malicious patterns detected; this is a standard cryptographic implementation of NIST P-521 elliptic curve in the noble-curves library with no network, file system, process execution, or dynamic code loading behavior.
- `esm/pasta.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/secp256k1.js` (safe): No malicious patterns detected; this is the standard noble-curves secp256k1 implementation with no exfiltration, credential harvesting, obfuscation, or dynamic execution.
- `index.js` (safe): The module immediately throws an error instructing users to import submodules, with no malicious patterns, network activity, credential access, or dynamic execution.
- `jubjub.js` (safe): No malicious patterns detected
- `p256.js` (safe): No malicious patterns detected
- `p384.js` (safe): No malicious patterns detected; this is a legitimate NIST P-384 elliptic curve implementation from the noble-curves library.
- `p521.js` (safe): No malicious patterns detected; the file is a legitimate cryptographic implementation of NIST P-521 curve from the noble-curves library.
- `pasta.js` (safe): No malicious patterns detected
- `secp256k1.js` (safe): No malicious patterns detected; the code implements legitimate secp256k1 elliptic curve cryptography from the noble-curves library.
- `src/_shortw_utils.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/abstract/bls.ts` (safe): No malicious patterns detected; the code is a legitimate BLS signature cryptographic library implementation.
- `src/abstract/curve.ts` (safe): No malicious patterns detected; the code implements elliptic curve arithmetic utilities with no network, filesystem, process, or obfuscated behavior.
- `src/abstract/edwards.ts` (safe): No malicious patterns detected
- `src/abstract/hash-to-curve.ts` (safe): No malicious patterns detected; the code is a legitimate cryptographic hash-to-curve implementation from the noble-curves library with no exfiltration, credential harvesting, obfuscation, or other red flags.
- `src/abstract/modular.ts` (safe): No malicious patterns detected
- `src/abstract/montgomery.ts` (safe): No malicious patterns detected
- `src/abstract/poseidon.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/abstract/utils.ts` (safe): No malicious patterns detected; the code is a collection of cryptographic utility functions from the noble-curves library with standard validation and HMAC-DRBG implementation.
- `src/abstract/weierstrass.ts` (safe): No malicious patterns detected; the code is a legitimate cryptographic library implementation for elliptic curve operations.
- `src/bls12-381.ts` (safe): No malicious patterns detected; the file is a standard cryptographic implementation of BLS12-381 (noble-curves) with no exfiltration, credential harvesting, obfuscation, dynamic execution, or suspicious network/process activity.
- `src/bn254.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/ed25519.ts` (safe): No malicious patterns detected; the code is a legitimate cryptographic library implementation for Ed25519, X25519, and Ristretto255 curves.
- `src/ed448.ts` (safe): No malicious patterns detected; this is a legitimate cryptographic implementation of Ed448, X448, and Decaf448 from the well-known noble-curves library.
- `src/index.ts` (safe): No malicious patterns detected
- `src/jubjub.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/p256.ts` (safe): No malicious patterns detected; this is a standard cryptographic implementation of NIST P-256 curve operations.
- `src/p384.ts` (safe): No malicious patterns detected; the file is a legitimate implementation of the NIST P-384 elliptic curve from the noble-curves library.
- `src/p521.ts` (safe): No malicious patterns detected; this is a legitimate cryptographic implementation of the NIST P-521 elliptic curve from the noble-curves library.
- `src/pasta.ts` (safe): No malicious patterns detected; the file defines standard elliptic curve parameters for Pallas and Vesta using the noble-curves library.
- `src/secp256k1.ts` (safe): No malicious patterns detected; the code is a legitimate implementation of secp256k1 elliptic curve cryptography from the noble-curves library.

## Version ranges

None of the 5 scanned versions of @noble/curves are flagged high or critical. The latest scanned version, 1.9.7, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 1.9.1 – 1.9.7 (`>=1.9.1 <=1.9.7`): clean
- 1.8.2 – 1.9.0 (`>=1.8.2 <=1.9.0`): not scanned
- 1.4.2 – 1.8.1 (`>=1.4.2 <=1.8.1`): clean
- 1.2.0 (`1.2.0`): not scanned

## Scanned versions

- [1.9.7](https://security.togoder.click/npm/@noble/curves@1.9.7): safe, 2026-10-04T16:28:06.000Z
- [1.9.1](https://security.togoder.click/npm/@noble/curves@1.9.1): safe, 2026-10-04T16:09:03.000Z
- [1.8.1](https://security.togoder.click/npm/@noble/curves@1.8.1): safe, 2026-10-04T16:09:43.000Z
- [1.8.0](https://security.togoder.click/npm/@noble/curves@1.8.0): safe, 2026-10-04T16:20:25.000Z
- [1.4.2](https://security.togoder.click/npm/@noble/curves@1.4.2): safe, 2026-10-04T16:30:03.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
