Togoder security

npm package security report

@noble/curves@1.8.1 security report

No malicious code found.

No issues Version 1.8.1 Files reviewed 66 Size 862.4 KB Scanned

Summary

Togoder Security scanned the npm package @noble/curves@1.8.1 on Oct 4, 2026. An AI review of 66 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
0
low

Findings

No findings. The reviewer saw nothing malicious or risky in this version.

Files reviewed

FileVerdictWhat the reviewer saw
_shortw_utils.js safe No malicious patterns detected; the code is a benign utility module for cryptographic curve operations.
abstract/bls.js safe No malicious patterns detected; the code is a legitimate implementation of BLS signatures from the noble-curves library with no data exfiltration, credential harvesting, obfuscation, or suspicious network/process activity.
abstract/curve.js safe This is a legitimate elliptic curve cryptography library (noble-curves) implementing wNAF and Pippenger algorithms with no malicious patterns detected.
abstract/edwards.js safe No malicious patterns detected; this is a legitimate cryptographic library implementation from noble-curves.
abstract/hash-to-curve.js safe No malicious patterns detected; the code is a legitimate implementation of RFC 9380 hash-to-curve primitives for elliptic curve cryptography.
abstract/modular.js safe No malicious patterns detected; this is a legitimate cryptographic modular arithmetic utility from the noble-curves library with no data exfiltration, obfuscation, or execution-time side effects.
abstract/montgomery.js safe The code is a legitimate implementation of Montgomery curve operations for X25519/X448 from the noble-curves library, with no malicious patterns detected.
abstract/poseidon.js safe This file implements the Poseidon cryptographic hash function with only local arithmetic operations, input validation, and no suspicious network, filesystem, or process activity.
abstract/tower.js safe No malicious patterns detected; the code is a legitimate cryptographic tower field implementation from the noble-curves library with no network, filesystem, process, or dynamic code execution behavior.
abstract/utils.js safe No malicious patterns detected; the file contains standard cryptographic utility functions (hex/byte conversion, HMAC-DRBG, validation helpers) with no network, filesystem, process, or dynamic code execution behavior.
abstract/weierstrass.js safe No malicious patterns detected; this is the legitimate noble-curves elliptic curve implementation (MIT licensed, © Paul Miller) containing only cryptographic primitives for Weierstrass curves, ECDSA, and hash-to-curve.
bls12-381.js safe No malicious patterns detected; this is a legitimate cryptographic library implementation of BLS12-381 with no network, filesystem, process, or code-execution concerns.
bn254.js safe No malicious patterns detected; this is a standard cryptographic library implementation for the bn254 elliptic curve.
ed25519.js safe No malicious patterns detected; code is the legitimate @noble/curves ed25519 implementation.
ed448.js safe No malicious patterns detected; this is a legitimate cryptographic implementation of Ed448/Decaf448/X448 from the noble-curves library.
esm/_shortw_utils.js safe Cleared by Jev triage; no further analysis needed
esm/abstract/bls.js safe No malicious patterns detected
esm/abstract/curve.js safe No malicious patterns detected; the code implements standard elliptic curve multiplication algorithms from the noble-curves library without any exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
esm/abstract/edwards.js safe No malicious patterns detected; the code is a legitimate implementation of Twisted Edwards curve cryptography from the noble-curves library.
esm/abstract/hash-to-curve.js safe No malicious patterns detected; the code implements RFC 9380 hash-to-curve primitives with no network, filesystem, process, or dynamic execution behavior.
esm/abstract/modular.js safe This is a standard cryptographic modular arithmetic utility from the noble-curves library with no malicious patterns detected; all operations are local mathematical computations with no network, filesystem, process, or dynamic code execution.
esm/abstract/montgomery.js safe This is a legitimate implementation of Montgomery curve operations for X25519/X448 from the noble-curves library with no malicious patterns detected.
esm/abstract/poseidon.js safe Cleared by Jev triage; no further analysis needed
esm/abstract/tower.js safe Cleared by Jev triage; no further analysis needed
esm/abstract/utils.js safe No malicious patterns detected; the code is a standard cryptographic utility library (noble-curves) with no exfiltration, obfuscation, or suspicious behavior.
Show 41 more files
FileVerdictWhat the reviewer saw
esm/abstract/weierstrass.js safe No malicious patterns detected; this is a legitimate cryptographic library implementation of short Weierstrass elliptic curves from noble-curves.
esm/bls12-381.js safe This is the legitimate noble-curves BLS12-381 implementation; no malicious patterns, exfiltration, or obfuscation detected.
esm/bn254.js safe No malicious patterns detected; the code is a legitimate cryptographic library implementation for the bn254 curve with no signs of data exfiltration, obfuscation, or other security concerns.
esm/ed25519.js safe No malicious patterns detected
esm/ed448.js safe No malicious patterns detected; the code is a legitimate cryptographic implementation of Ed448 and related primitives from the noble-curves library.
esm/index.js safe No malicious patterns detected; the file intentionally throws an error to prevent direct import of the root module and contains no executable malicious code.
esm/jubjub.js safe No malicious patterns detected; this is a legitimate cryptographic curve implementation from the noble-curves library with no network, file system, process, or dynamic code execution behavior.
esm/p256.js safe No malicious patterns detected; the file is a legitimate implementation of the NIST P-256 curve from the noble-curves library.
esm/p384.js safe No malicious patterns detected; the code is a standard cryptographic implementation for the NIST P-384 elliptic curve.
esm/p521.js safe No malicious patterns detected; the code is a standard cryptographic implementation of NIST P-521 elliptic curve from the noble-curves library.
esm/pasta.js safe Cleared by Jev triage; no further analysis needed
esm/secp256k1.js safe No malicious patterns detected; this is a legitimate cryptographic library implementation for secp256k1 with standard ECDSA and Schnorr signature operations.
index.js safe No malicious patterns detected; the file only throws an error to prevent root module import, which is a legitimate design choice in the @noble/curves library.
jubjub.js safe No malicious patterns detected; the code is a standard implementation of the JubJub elliptic curve from the noble-curves library with no suspicious behavior.
p256.js safe No malicious patterns detected
p384.js safe No malicious patterns detected; this is a legitimate cryptographic implementation of the NIST P-384 elliptic curve from the noble-curves library.
p521.js safe No malicious patterns detected
pasta.js safe No malicious patterns detected; the code is a legitimate cryptographic library defining Pasta curves with standard imports and no suspicious behavior.
secp256k1.js safe This is a legitimate secp256k1 elliptic curve cryptography implementation from the noble-curves library with no malicious patterns detected.
src/_shortw_utils.ts safe Cleared by Jev triage; no further analysis needed
src/abstract/bls.ts safe No malicious patterns detected; the code is a legitimate cryptographic implementation of BLS signatures from the noble-curves library.
src/abstract/curve.ts safe No malicious patterns detected
src/abstract/edwards.ts safe No malicious patterns detected; this is a legitimate implementation of Twisted Edwards elliptic curve cryptography (EdDSA) from the noble-curves library with no network, filesystem, process, or credential access.
src/abstract/hash-to-curve.ts safe No malicious patterns detected; the file is a legitimate implementation of RFC 9380 hash-to-curve with no network, filesystem, or code-execution side effects.
src/abstract/modular.ts safe This is a legitimate cryptographic utility module from the noble-curves library implementing modular arithmetic and finite field operations, with no malicious patterns detected.
src/abstract/montgomery.ts safe No malicious patterns detected
src/abstract/poseidon.ts safe Cleared by Jev triage; no further analysis needed
src/abstract/tower.ts safe Cleared by Jev triage; no further analysis needed
src/abstract/utils.ts safe No malicious patterns detected; the file contains standard cryptographic utility functions from the noble-curves library with no network, filesystem, process, or dynamic code execution behavior.
src/abstract/weierstrass.ts safe No malicious patterns detected; the file is a legitimate implementation of short Weierstrass elliptic curve cryptography from the noble-curves library.
src/bls12-381.ts safe No malicious patterns detected; the file is a legitimate BLS12-381 cryptographic curve implementation from the noble-curves library.
src/bn254.ts safe No malicious patterns detected in this cryptographic curve implementation; it contains only mathematical operations and standard library imports without any network, filesystem, or execution abuse.
src/ed25519.ts safe No malicious patterns detected; the code is a standard cryptographic implementation of Ed25519, X25519, and Ristretto255 from the noble-curves library.
src/ed448.ts safe This is a clean implementation of the Ed448/X448 cryptographic curve from the noble-curves library, with no malicious patterns, obfuscation, network activity, or file system access.
src/index.ts safe No malicious patterns detected; the file only throws a static error message intended to prevent incorrect root module imports.
src/jubjub.ts safe No malicious patterns detected; the code implements cryptographic primitives for the JubJub curve using well-known noble-curves/hashes libraries without any exfiltration, obfuscation, or other red-flag behavior.
src/p256.ts safe No malicious patterns detected; the file is a standard cryptographic implementation of NIST P-256 elliptic curve operations from the noble-curves library.
src/p384.ts safe No malicious patterns detected; the code is a standard, well-commented implementation of the NIST P-384 elliptic curve with no network, filesystem, credential access, obfuscation, or dynamic execution behavior.
src/p521.ts safe No malicious patterns detected; the file implements NIST secp521r1 elliptic curve parameters using noble-curves, with no exfiltration, credential harvesting, dynamic execution, or other red flags.
src/pasta.ts safe Cleared by Jev triage; no further analysis needed
src/secp256k1.ts safe No malicious patterns detected; the code is a standard, well-documented secp256k1 cryptographic implementation from the noble-curves library with no exfiltration, obfuscation, or dynamic execution.

Affected version ranges

None of the 5 scanned versions of @noble/curves are flagged high or critical. The latest scanned version, 1.9.7, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

1.2.01.9.7
VersionsVerdictCountRangeTop findings
1.9.1 – 1.9.7 No issues 2 >=1.9.1 <=1.9.7
1.8.2 – 1.9.0 Not scanned 2 >=1.8.2 <=1.9.0
1.4.2 – 1.8.1 No issues 3 >=1.4.2 <=1.8.1
1.2.0 Not scanned 1 1.2.0

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of @noble/curves

VersionVerdictFilesScanned
1.9.7 No issues 78 Oct 4, 2026
1.9.1 No issues 75 Oct 4, 2026
1.8.1 No issues 66 Oct 4, 2026
1.8.0 No issues 66 Oct 4, 2026
1.4.2 No issues 63 Oct 4, 2026

Frequently asked questions

Is @noble/curves safe to use?

Our AI source review of @noble/curves@1.8.1 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does @noble/curves contain malware?

No malware was identified in @noble/curves@1.8.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @noble/curves checked?

Togoder Security downloaded the published npm package and had an AI model read its 66 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @noble/curves together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @noble/curves@1.8.1, cost nothing.

Related security reports