# @noble/curves@1.8.0 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:20:25.000Z
- Files reviewed: 66
- Findings: no findings
- Report: https://security.togoder.click/npm/@noble/curves@1.8.0
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @noble/curves@1.8.0 on Oct 4, 2026. An AI review of 66 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `_shortw_utils.js` (safe): No malicious patterns detected; the code is a benign utility module for cryptographic curve operations.
- `abstract/bls.js` (safe): No malicious patterns detected; the code is a legitimate implementation of BLS signatures from the noble-curves library with no data exfiltration, credential harvesting, obfuscation, or suspicious network/process activity.
- `abstract/curve.js` (safe): This is a legitimate elliptic curve cryptography library (noble-curves) implementing wNAF and Pippenger algorithms with no malicious patterns detected.
- `abstract/edwards.js` (safe): No malicious patterns detected; this is a legitimate cryptographic library implementation from noble-curves.
- `abstract/hash-to-curve.js` (safe): No malicious patterns detected; the code is a legitimate implementation of RFC 9380 hash-to-curve primitives for elliptic curve cryptography.
- `abstract/modular.js` (safe): No malicious patterns detected; this is a legitimate cryptographic modular arithmetic utility from the noble-curves library with no data exfiltration, obfuscation, or execution-time side effects.
- `abstract/montgomery.js` (safe): The code is a legitimate implementation of Montgomery curve operations for X25519/X448 from the noble-curves library, with no malicious patterns detected.
- `abstract/poseidon.js` (safe): This file implements the Poseidon cryptographic hash function with only local arithmetic operations, input validation, and no suspicious network, filesystem, or process activity.
- `abstract/tower.js` (safe): No malicious patterns detected; the code is a legitimate cryptographic tower field implementation from the noble-curves library with no network, filesystem, process, or dynamic code execution behavior.
- `abstract/utils.js` (safe): No malicious patterns detected; the file contains standard cryptographic utility functions (hex/byte conversion, HMAC-DRBG, validation helpers) with no network, filesystem, process, or dynamic code execution behavior.
- `abstract/weierstrass.js` (safe): No malicious patterns detected; the code is a standard cryptographic library implementation of short Weierstrass elliptic curves and ECDSA, with no data exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
- `bls12-381.js` (safe): No malicious patterns detected; the code implements BLS12-381 cryptographic curve operations from the well-known noble-curves library without any data exfiltration, obfuscation, credential harvesting, or suspicious behavior.
- `bn254.js` (safe): No malicious patterns detected; the file is a legitimate cryptographic implementation of the bn254 elliptic curve from the noble-curves library.
- `ed25519.js` (safe): No malicious patterns detected; this is a legitimate cryptographic library implementing ed25519, x25519, and ristretto255 from the noble-curves project.
- `ed448.js` (safe): No malicious patterns detected; this is a legitimate cryptographic library implementation of Ed448, X448, and Decaf448 with no data exfiltration, credential harvesting, dynamic code execution, or network/file system abuse.
- `esm/_shortw_utils.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/abstract/bls.js` (safe): No malicious patterns detected
- `esm/abstract/curve.js` (safe): No malicious patterns detected; the code is a legitimate implementation of elliptic curve multiplication algorithms from the noble-curves library with no network, filesystem, process, or credential access.
- `esm/abstract/edwards.js` (safe): No malicious patterns detected; the code is a legitimate cryptographic implementation of Twisted Edwards curves and EdDSA signatures from the noble-curves library.
- `esm/abstract/hash-to-curve.js` (safe): No malicious patterns detected; the code implements RFC 9380 hash-to-curve primitives with no network, filesystem, process, or dynamic execution behavior.
- `esm/abstract/modular.js` (safe): This is a standard cryptographic modular arithmetic utility from the noble-curves library with no malicious patterns detected; all operations are local mathematical computations with no network, filesystem, process, or dynamic code execution.
- `esm/abstract/montgomery.js` (safe): This is a legitimate implementation of Montgomery curve operations for X25519/X448 from the noble-curves library with no malicious patterns detected.
- `esm/abstract/poseidon.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/abstract/tower.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/abstract/utils.js` (safe): No malicious patterns detected; the code is a standard cryptographic utility library (noble-curves) with no exfiltration, obfuscation, or suspicious behavior.
- `esm/abstract/weierstrass.js` (safe): No malicious patterns detected; the code is a legitimate cryptographic library implementation for short Weierstrass elliptic curves with no signs of data exfiltration, credential harvesting, obfuscation, or other security concerns.
- `esm/bls12-381.js` (safe): No malicious patterns detected in the BLS12-381 cryptographic implementation.
- `esm/bn254.js` (safe): No malicious patterns detected; the file is a legitimate cryptographic implementation of the bn254 curve from the noble-curves library with no data exfiltration, credential harvesting, obfuscation, network calls, process spawning, or dynamic code execution.
- `esm/ed25519.js` (safe): No malicious patterns detected; the file is a legitimate cryptographic library implementation for ed25519 and related primitives.
- `esm/ed448.js` (safe): No malicious patterns detected; the code is a legitimate cryptographic implementation of Ed448, X448, and Decaf448 from the noble-curves library.
- `esm/index.js` (safe): The file intentionally throws an error to prevent root module imports, contains no dynamic code execution, network, filesystem, credential, or process-spawning behavior, and is benign.
- `esm/jubjub.js` (safe): No malicious patterns detected; this is a legitimate cryptographic curve implementation from the noble-curves library with no network, file system, process, or dynamic code execution behavior.
- `esm/p256.js` (safe): No malicious patterns detected; the file is a legitimate implementation of the NIST P-256 curve from the noble-curves library.
- `esm/p384.js` (safe): No malicious patterns detected; the code is a standard cryptographic implementation for the NIST P-384 elliptic curve.
- `esm/p521.js` (safe): No malicious patterns detected; the code is a standard cryptographic implementation of NIST P-521 elliptic curve from the noble-curves library.
- `esm/pasta.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/secp256k1.js` (safe): No malicious patterns detected; this is the legitimate @noble/curves secp256k1 cryptographic implementation.
- `index.js` (safe): No malicious patterns detected; the file simply throws an error instructing users to import submodules.
- `jubjub.js` (safe): No malicious patterns detected; the code is a standard implementation of the JubJub elliptic curve from the noble-curves library with no suspicious behavior.
- `p256.js` (safe): No malicious patterns detected
- `p384.js` (safe): No malicious patterns detected; this is a legitimate cryptographic implementation of the NIST P-384 elliptic curve from the noble-curves library.
- `p521.js` (safe): No malicious patterns detected
- `pasta.js` (safe): No malicious patterns detected; the code is a legitimate cryptographic library defining Pasta curves with standard imports and no suspicious behavior.
- `secp256k1.js` (safe): This is a legitimate secp256k1 elliptic curve cryptography implementation from the noble-curves library with no malicious patterns detected.
- `src/_shortw_utils.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/abstract/bls.ts` (safe): No malicious patterns detected; the code is a legitimate cryptographic implementation of BLS signatures from the noble-curves library.
- `src/abstract/curve.ts` (safe): No malicious patterns detected; the code is a standard, well-documented elliptic curve cryptography library implementation for elliptic curve multiplication, Pippenger algorithm, and MSM precomputation, with no data exfiltration, credential harvesting, obfuscation, dynamic execution, or filesystem/process manipulation.
- `src/abstract/edwards.ts` (safe): The code is a legitimate cryptographic library implementation of Twisted Edwards curves and EdDSA signatures with no malicious patterns detected.
- `src/abstract/hash-to-curve.ts` (safe): No malicious patterns detected; the code is a legitimate implementation of RFC 9380 hash-to-curve from the noble-curves library, with no data exfiltration, credential harvesting, obfuscation, or network/process activity.
- `src/abstract/modular.ts` (safe): This is a legitimate cryptographic utility module from the noble-curves library implementing modular arithmetic and finite field operations, with no malicious patterns detected.
- `src/abstract/montgomery.ts` (safe): No malicious patterns detected
- `src/abstract/poseidon.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/abstract/tower.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/abstract/utils.ts` (safe): No malicious patterns detected; the file contains standard cryptographic utility functions from the noble-curves library with no network, filesystem, process, or dynamic code execution behavior.
- `src/abstract/weierstrass.ts` (safe): This is a legitimate cryptographic library implementing Weierstrass elliptic curve and ECDSA operations with no malicious patterns.
- `src/bls12-381.ts` (safe): No malicious patterns detected
- `src/bn254.ts` (safe): No malicious patterns detected; the file is a legitimate cryptographic implementation of the bn254 curve from the noble-curves library.
- `src/ed25519.ts` (safe): This is the legitimate @noble/curves ed25519 implementation with no malicious patterns detected.
- `src/ed448.ts` (safe): No malicious patterns detected; the code is a legitimate cryptographic library implementation of Ed448, X448, and Decaf448 with no external calls, obfuscation, or suspicious behavior.
- `src/index.ts` (safe): The file only throws an error to prevent direct root module import, with no malicious patterns detected.
- `src/jubjub.ts` (safe): No malicious patterns detected; the file contains standard elliptic curve cryptography implementation for the JubJub curve with no exfiltration, credential harvesting, dynamic execution, or suspicious behavior.
- `src/p256.ts` (safe): No malicious patterns detected; the code is a standard implementation of the NIST P-256 elliptic curve from the noble-curves library.
- `src/p384.ts` (safe): No malicious patterns detected; the file is a legitimate implementation of the NIST P-384 elliptic curve from the noble-curves library with no network, process, or filesystem side effects.
- `src/p521.ts` (safe): Cryptographic curve implementation with no malicious patterns detected
- `src/pasta.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/secp256k1.ts` (safe): No malicious patterns detected; the code is a standard, well-known implementation of secp256k1 elliptic curve cryptography from the @noble/curves library with no signs of exfiltration, credential harvesting, obfuscation, or other security concerns.

## Version ranges

None of the 5 scanned versions of @noble/curves are flagged high or critical. The latest scanned version, 1.9.7, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 1.9.1 – 1.9.7 (`>=1.9.1 <=1.9.7`): clean
- 1.8.2 – 1.9.0 (`>=1.8.2 <=1.9.0`): not scanned
- 1.4.2 – 1.8.1 (`>=1.4.2 <=1.8.1`): clean
- 1.2.0 (`1.2.0`): not scanned

## Scanned versions

- [1.9.7](https://security.togoder.click/npm/@noble/curves@1.9.7): safe, 2026-10-04T16:28:06.000Z
- [1.9.1](https://security.togoder.click/npm/@noble/curves@1.9.1): safe, 2026-10-04T16:09:03.000Z
- [1.8.1](https://security.togoder.click/npm/@noble/curves@1.8.1): safe, 2026-10-04T16:09:43.000Z
- [1.8.0](https://security.togoder.click/npm/@noble/curves@1.8.0): safe, 2026-10-04T16:20:25.000Z
- [1.4.2](https://security.togoder.click/npm/@noble/curves@1.4.2): safe, 2026-10-04T16:30:03.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
