# @noble/curves@1.8.1 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:09:43.000Z
- Files reviewed: 66
- Findings: no findings
- Report: https://security.togoder.click/npm/@noble/curves@1.8.1
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @noble/curves@1.8.1 on Oct 4, 2026. An AI review of 66 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `_shortw_utils.js` (safe): No malicious patterns detected; the code is a benign utility module for cryptographic curve operations.
- `abstract/bls.js` (safe): No malicious patterns detected; the code is a legitimate implementation of BLS signatures from the noble-curves library with no data exfiltration, credential harvesting, obfuscation, or suspicious network/process activity.
- `abstract/curve.js` (safe): This is a legitimate elliptic curve cryptography library (noble-curves) implementing wNAF and Pippenger algorithms with no malicious patterns detected.
- `abstract/edwards.js` (safe): No malicious patterns detected; this is a legitimate cryptographic library implementation from noble-curves.
- `abstract/hash-to-curve.js` (safe): No malicious patterns detected; the code is a legitimate implementation of RFC 9380 hash-to-curve primitives for elliptic curve cryptography.
- `abstract/modular.js` (safe): No malicious patterns detected; this is a legitimate cryptographic modular arithmetic utility from the noble-curves library with no data exfiltration, obfuscation, or execution-time side effects.
- `abstract/montgomery.js` (safe): The code is a legitimate implementation of Montgomery curve operations for X25519/X448 from the noble-curves library, with no malicious patterns detected.
- `abstract/poseidon.js` (safe): This file implements the Poseidon cryptographic hash function with only local arithmetic operations, input validation, and no suspicious network, filesystem, or process activity.
- `abstract/tower.js` (safe): No malicious patterns detected; the code is a legitimate cryptographic tower field implementation from the noble-curves library with no network, filesystem, process, or dynamic code execution behavior.
- `abstract/utils.js` (safe): No malicious patterns detected; the file contains standard cryptographic utility functions (hex/byte conversion, HMAC-DRBG, validation helpers) with no network, filesystem, process, or dynamic code execution behavior.
- `abstract/weierstrass.js` (safe): No malicious patterns detected; this is the legitimate noble-curves elliptic curve implementation (MIT licensed, © Paul Miller) containing only cryptographic primitives for Weierstrass curves, ECDSA, and hash-to-curve.
- `bls12-381.js` (safe): No malicious patterns detected; this is a legitimate cryptographic library implementation of BLS12-381 with no network, filesystem, process, or code-execution concerns.
- `bn254.js` (safe): No malicious patterns detected; this is a standard cryptographic library implementation for the bn254 elliptic curve.
- `ed25519.js` (safe): No malicious patterns detected; code is the legitimate @noble/curves ed25519 implementation.
- `ed448.js` (safe): No malicious patterns detected; this is a legitimate cryptographic implementation of Ed448/Decaf448/X448 from the noble-curves library.
- `esm/_shortw_utils.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/abstract/bls.js` (safe): No malicious patterns detected
- `esm/abstract/curve.js` (safe): No malicious patterns detected; the code implements standard elliptic curve multiplication algorithms from the noble-curves library without any exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
- `esm/abstract/edwards.js` (safe): No malicious patterns detected; the code is a legitimate implementation of Twisted Edwards curve cryptography from the noble-curves library.
- `esm/abstract/hash-to-curve.js` (safe): No malicious patterns detected; the code implements RFC 9380 hash-to-curve primitives with no network, filesystem, process, or dynamic execution behavior.
- `esm/abstract/modular.js` (safe): This is a standard cryptographic modular arithmetic utility from the noble-curves library with no malicious patterns detected; all operations are local mathematical computations with no network, filesystem, process, or dynamic code execution.
- `esm/abstract/montgomery.js` (safe): This is a legitimate implementation of Montgomery curve operations for X25519/X448 from the noble-curves library with no malicious patterns detected.
- `esm/abstract/poseidon.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/abstract/tower.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/abstract/utils.js` (safe): No malicious patterns detected; the code is a standard cryptographic utility library (noble-curves) with no exfiltration, obfuscation, or suspicious behavior.
- `esm/abstract/weierstrass.js` (safe): No malicious patterns detected; this is a legitimate cryptographic library implementation of short Weierstrass elliptic curves from noble-curves.
- `esm/bls12-381.js` (safe): This is the legitimate noble-curves BLS12-381 implementation; no malicious patterns, exfiltration, or obfuscation detected.
- `esm/bn254.js` (safe): No malicious patterns detected; the code is a legitimate cryptographic library implementation for the bn254 curve with no signs of data exfiltration, obfuscation, or other security concerns.
- `esm/ed25519.js` (safe): No malicious patterns detected
- `esm/ed448.js` (safe): No malicious patterns detected; the code is a legitimate cryptographic implementation of Ed448 and related primitives from the noble-curves library.
- `esm/index.js` (safe): No malicious patterns detected; the file intentionally throws an error to prevent direct import of the root module and contains no executable malicious code.
- `esm/jubjub.js` (safe): No malicious patterns detected; this is a legitimate cryptographic curve implementation from the noble-curves library with no network, file system, process, or dynamic code execution behavior.
- `esm/p256.js` (safe): No malicious patterns detected; the file is a legitimate implementation of the NIST P-256 curve from the noble-curves library.
- `esm/p384.js` (safe): No malicious patterns detected; the code is a standard cryptographic implementation for the NIST P-384 elliptic curve.
- `esm/p521.js` (safe): No malicious patterns detected; the code is a standard cryptographic implementation of NIST P-521 elliptic curve from the noble-curves library.
- `esm/pasta.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/secp256k1.js` (safe): No malicious patterns detected; this is a legitimate cryptographic library implementation for secp256k1 with standard ECDSA and Schnorr signature operations.
- `index.js` (safe): No malicious patterns detected; the file only throws an error to prevent root module import, which is a legitimate design choice in the @noble/curves library.
- `jubjub.js` (safe): No malicious patterns detected; the code is a standard implementation of the JubJub elliptic curve from the noble-curves library with no suspicious behavior.
- `p256.js` (safe): No malicious patterns detected
- `p384.js` (safe): No malicious patterns detected; this is a legitimate cryptographic implementation of the NIST P-384 elliptic curve from the noble-curves library.
- `p521.js` (safe): No malicious patterns detected
- `pasta.js` (safe): No malicious patterns detected; the code is a legitimate cryptographic library defining Pasta curves with standard imports and no suspicious behavior.
- `secp256k1.js` (safe): This is a legitimate secp256k1 elliptic curve cryptography implementation from the noble-curves library with no malicious patterns detected.
- `src/_shortw_utils.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/abstract/bls.ts` (safe): No malicious patterns detected; the code is a legitimate cryptographic implementation of BLS signatures from the noble-curves library.
- `src/abstract/curve.ts` (safe): No malicious patterns detected
- `src/abstract/edwards.ts` (safe): No malicious patterns detected; this is a legitimate implementation of Twisted Edwards elliptic curve cryptography (EdDSA) from the noble-curves library with no network, filesystem, process, or credential access.
- `src/abstract/hash-to-curve.ts` (safe): No malicious patterns detected; the file is a legitimate implementation of RFC 9380 hash-to-curve with no network, filesystem, or code-execution side effects.
- `src/abstract/modular.ts` (safe): This is a legitimate cryptographic utility module from the noble-curves library implementing modular arithmetic and finite field operations, with no malicious patterns detected.
- `src/abstract/montgomery.ts` (safe): No malicious patterns detected
- `src/abstract/poseidon.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/abstract/tower.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/abstract/utils.ts` (safe): No malicious patterns detected; the file contains standard cryptographic utility functions from the noble-curves library with no network, filesystem, process, or dynamic code execution behavior.
- `src/abstract/weierstrass.ts` (safe): No malicious patterns detected; the file is a legitimate implementation of short Weierstrass elliptic curve cryptography from the noble-curves library.
- `src/bls12-381.ts` (safe): No malicious patterns detected; the file is a legitimate BLS12-381 cryptographic curve implementation from the noble-curves library.
- `src/bn254.ts` (safe): No malicious patterns detected in this cryptographic curve implementation; it contains only mathematical operations and standard library imports without any network, filesystem, or execution abuse.
- `src/ed25519.ts` (safe): No malicious patterns detected; the code is a standard cryptographic implementation of Ed25519, X25519, and Ristretto255 from the noble-curves library.
- `src/ed448.ts` (safe): This is a clean implementation of the Ed448/X448 cryptographic curve from the noble-curves library, with no malicious patterns, obfuscation, network activity, or file system access.
- `src/index.ts` (safe): No malicious patterns detected; the file only throws a static error message intended to prevent incorrect root module imports.
- `src/jubjub.ts` (safe): No malicious patterns detected; the code implements cryptographic primitives for the JubJub curve using well-known noble-curves/hashes libraries without any exfiltration, obfuscation, or other red-flag behavior.
- `src/p256.ts` (safe): No malicious patterns detected; the file is a standard cryptographic implementation of NIST P-256 elliptic curve operations from the noble-curves library.
- `src/p384.ts` (safe): No malicious patterns detected; the code is a standard, well-commented implementation of the NIST P-384 elliptic curve with no network, filesystem, credential access, obfuscation, or dynamic execution behavior.
- `src/p521.ts` (safe): No malicious patterns detected; the file implements NIST secp521r1 elliptic curve parameters using noble-curves, with no exfiltration, credential harvesting, dynamic execution, or other red flags.
- `src/pasta.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/secp256k1.ts` (safe): No malicious patterns detected; the code is a standard, well-documented secp256k1 cryptographic implementation from the noble-curves library with no exfiltration, obfuscation, or dynamic execution.

## Version ranges

None of the 5 scanned versions of @noble/curves are flagged high or critical. The latest scanned version, 1.9.7, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 1.9.1 – 1.9.7 (`>=1.9.1 <=1.9.7`): clean
- 1.8.2 – 1.9.0 (`>=1.8.2 <=1.9.0`): not scanned
- 1.4.2 – 1.8.1 (`>=1.4.2 <=1.8.1`): clean
- 1.2.0 (`1.2.0`): not scanned

## Scanned versions

- [1.9.7](https://security.togoder.click/npm/@noble/curves@1.9.7): safe, 2026-10-04T16:28:06.000Z
- [1.9.1](https://security.togoder.click/npm/@noble/curves@1.9.1): safe, 2026-10-04T16:09:03.000Z
- [1.8.1](https://security.togoder.click/npm/@noble/curves@1.8.1): safe, 2026-10-04T16:09:43.000Z
- [1.8.0](https://security.togoder.click/npm/@noble/curves@1.8.0): safe, 2026-10-04T16:20:25.000Z
- [1.4.2](https://security.togoder.click/npm/@noble/curves@1.4.2): safe, 2026-10-04T16:30:03.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
