Togoder security

npm package security report

@noble/curves@1.9.1 security report

No malicious code found.

No issues Version 1.9.1 Files reviewed 75 Size 941.6 KB Scanned

Summary

Togoder Security scanned the npm package @noble/curves@1.9.1 on Oct 4, 2026. An AI review of 75 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
1
low

Findings 1

low

No malicious patterns

NPS-D697DF322D8A

The code is a legitimate implementation of the Poseidon hash function and sponge construction. It contains no data exfiltration, credential harvesting, obfuscated code, dynamic code execution, cryptocurrency mining, backdoors, suspicious network requests, file system manipulation, process spawning, or dynamic imports. All operations are purely cryptographic computations within the provided finite field abstraction.

src/abstract/poseidon.ts

Files reviewed

FileVerdictWhat the reviewer saw
_shortw_utils.js safe No malicious patterns detected; the code is a legitimate utility module from noble-curves for connecting hash functions to elliptic curve implementations.
abstract/bls.js safe No malicious patterns detected; this is a legitimate implementation of BLS signatures from the noble-curves cryptography library.
abstract/curve.js safe No malicious patterns detected; this is legitimate elliptic curve cryptography code from the noble-curves library.
abstract/edwards.js safe This is a legitimate cryptographic implementation of Twisted Edwards curves from the noble-curves library; no malicious patterns or security concerns were detected.
abstract/fft.js safe No malicious patterns detected; the code is a pure mathematical FFT/NTT implementation with no network, filesystem, process, or dynamic execution activity.
abstract/hash-to-curve.js safe No malicious patterns detected
abstract/modular.js safe No malicious patterns detected; the file contains standard modular arithmetic and finite field utilities from the noble-curves library with no network, filesystem, process, or dynamic code execution behavior.
abstract/montgomery.js safe No malicious patterns detected; the code is a legitimate implementation of Montgomery curve methods for X25519/X448 from the noble-curves library.
abstract/poseidon.js safe This is a legitimate cryptographic Poseidon hash implementation from the noble-curves library with no malicious patterns detected
abstract/tower.js safe This is a legitimate cryptographic library implementation of tower field arithmetic for pairing-based cryptography from the noble-curves project, with no malicious patterns detected.
abstract/utils.js safe No malicious patterns detected; the file contains standard cryptographic utility functions from the noble-curves library without any exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
abstract/weierstrass.js safe Legitimate noble-curves cryptography library implementing Weierstrass elliptic curve operations with no malicious patterns, no external network calls, no environment variable harvesting, and no dynamic code execution.
bls12-381.js safe No malicious patterns detected; the code is a standard cryptographic implementation of BLS12-381 with no data exfiltration, obfuscation, or dynamic execution.
bn254.js safe No malicious patterns detected; the code is a legitimate cryptographic implementation of the bn254 curve from the noble-curves library.
ed25519.js safe No malicious patterns detected in this cryptographic library implementation of ed25519, x25519, and Ristretto255.
ed448.js safe No malicious patterns detected; this is a legitimate cryptographic library implementing Ed448/X448/Decaf448 curves from noble-curves.
esm/_shortw_utils.js safe Cleared by Jev triage; no further analysis needed
esm/abstract/bls.js safe No malicious patterns detected; the code is a legitimate BLS signature implementation from the noble-curves library with no exfiltration, credential harvesting, obfuscation, or other security concerns.
esm/abstract/curve.js safe No malicious patterns detected; this is legitimate elliptic curve cryptography code from the noble-curves library with no exfiltration, dynamic execution, or other red flags.
esm/abstract/edwards.js safe No malicious patterns detected
esm/abstract/fft.js safe Cleared by Jev triage; no further analysis needed
esm/abstract/hash-to-curve.js safe This is a clean implementation of RFC 9380 hash-to-curve cryptography with no malicious patterns detected.
esm/abstract/modular.js safe This is a legitimate cryptographic utility module from the noble-curves library implementing modular arithmetic and finite field operations, with no malicious patterns detected.
esm/abstract/montgomery.js safe No malicious patterns detected; the code is a standard implementation of Montgomery curve X25519/X448 cryptography from the noble-curves library.
esm/abstract/poseidon.js safe Cleared by Jev triage; no further analysis needed
Show 50 more files
FileVerdictWhat the reviewer saw
esm/abstract/tower.js safe Cleared by Jev triage; no further analysis needed
esm/abstract/utils.js safe No malicious patterns detected
esm/abstract/weierstrass.js safe No malicious patterns detected
esm/bls12-381.js safe No malicious patterns detected; the code is a legitimate implementation of the BLS12-381 cryptographic curve from the noble-curves library.
esm/bn254.js safe No malicious patterns detected; the file is a legitimate cryptographic library implementation for the bn254 curve from noble-curves.
esm/ed25519.js safe No malicious patterns detected; this is legitimate cryptographic code from the noble-curves library implementing Ed25519, X25519, and Ristretto255 primitives with no network, filesystem, process, or dynamic code execution activity.
esm/ed448.js safe No malicious patterns detected; this is a legitimate cryptographic library implementation of Ed448, X448, and Decaf448 with no data exfiltration, obfuscation, or suspicious behavior.
esm/index.js safe No malicious patterns detected; the file intentionally throws an error to prevent direct import of the root module and contains no executable malicious code.
esm/jubjub.js safe Cleared by Jev triage; no further analysis needed
esm/misc.js safe Cleared by Jev triage; no further analysis needed
esm/nist.js safe No malicious patterns detected; the file contains standard cryptographic curve definitions for NIST P-256, P-384, and P-521 from the noble-curves library.
esm/p256.js safe Cleared by Jev triage; no further analysis needed
esm/p384.js safe Cleared by Jev triage; no further analysis needed
esm/p521.js safe Cleared by Jev triage; no further analysis needed
esm/pasta.js safe Cleared by Jev triage; no further analysis needed
esm/secp256k1.js safe No malicious patterns detected; the file is a legitimate well-known cryptographic implementation for secp256k1 with no data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
index.js safe No malicious patterns detected; the file only throws an error to prevent root module import, which is a legitimate design choice in the @noble/curves library.
jubjub.js safe No malicious patterns detected
misc.js safe No malicious patterns detected; the file defines well-known elliptic curves (jubjub, babyjubjub, pallas, vesta) using standard noble-curves primitives without any exfiltration, obfuscation, network, filesystem, or process execution behavior.
nist.js safe No malicious patterns detected
p256.js safe No malicious patterns detected; the file is a simple re-export module that delegates to the local nist.js implementation.
p384.js safe No malicious patterns detected; the file only re-exports symbols from the local nist.js module and contains no external calls, dynamic execution, or filesystem/network activity.
p521.js safe No malicious patterns detected
pasta.js safe No malicious patterns detected; the file only re-exports deprecated functions from a local module.
secp256k1.js safe This is a legitimate implementation of secp256k1 cryptographic curve operations from the noble-curves library, with no malicious patterns detected.
src/_shortw_utils.ts safe Cleared by Jev triage; no further analysis needed
src/abstract/bls.ts safe No malicious patterns detected; the file is a legitimate implementation of BLS signature cryptography from the noble-curves library.
src/abstract/curve.ts safe No malicious patterns detected; the code is a legitimate elliptic curve cryptography implementation from the noble-curves library with no data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
src/abstract/edwards.ts safe No malicious patterns detected
src/abstract/fft.ts safe No malicious patterns detected; the code is a legitimate FFT/NTT implementation over finite fields with no network, filesystem, process, or credential-access operations.
src/abstract/hash-to-curve.ts safe No malicious patterns detected; the code is a legitimate implementation of RFC 9380 hash-to-curve for cryptographic libraries.
src/abstract/modular.ts safe No malicious patterns detected; the code implements standard modular arithmetic and finite field operations for cryptographic purposes.
src/abstract/montgomery.ts safe No malicious patterns detected; the code is a legitimate implementation of X25519/X448 Montgomery curve operations from the noble-curves library.
src/abstract/poseidon.ts safe No malicious patterns detected; the code is a standard cryptographic implementation of Poseidon hash and sponge.
src/abstract/tower.ts safe Cleared by Jev triage; no further analysis needed
src/abstract/utils.ts safe No malicious patterns detected
src/abstract/weierstrass.ts safe No malicious patterns detected; this is a legitimate cryptographic library implementation for Weierstrass elliptic curves.
src/bls12-381.ts safe The file is a legitimate implementation of the BLS12-381 elliptic curve from the noble-curves library, with no malicious patterns, network activity, credential access, or dynamic code execution detected.
src/bn254.ts safe No malicious patterns detected; the file is a legitimate cryptographic implementation of the bn254 curve with no network, filesystem, process, or obfuscated code.
src/ed25519.ts safe No malicious patterns detected
src/ed448.ts safe No malicious patterns detected; the code is a legitimate cryptographic implementation of Ed448, X448, and Decaf448 from the noble-curves library.
src/index.ts safe No malicious patterns detected; the file only throws a static error message intended to prevent incorrect root module imports.
src/jubjub.ts safe Cleared by Jev triage; no further analysis needed
src/misc.ts safe Cleared by Jev triage; no further analysis needed
src/nist.ts safe No malicious patterns detected in this standard cryptographic curve implementation file.
src/p256.ts safe No malicious patterns detected; the file only re-exports P-256 curve primitives and hash-to-curve helpers with no network, filesystem, process, or dynamic code execution behavior.
src/p384.ts safe No malicious patterns detected; the code is a straightforward cryptographic module re-exporting secp384r1 primitives from the noble-curves library.
src/p521.ts safe Cleared by Jev triage; no further analysis needed
src/pasta.ts safe Cleared by Jev triage; no further analysis needed
src/secp256k1.ts safe No malicious patterns detected; the file is a standard cryptographic implementation of secp256k1 and Schnorr signatures from the noble-curves library with no data exfiltration, credential harvesting, obfuscated payloads, or suspicious runtime behavior.

Affected version ranges

None of the 5 scanned versions of @noble/curves are flagged high or critical. The latest scanned version, 1.9.7, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

1.2.01.9.7
VersionsVerdictCountRangeTop findings
1.9.1 – 1.9.7 No issues 2 >=1.9.1 <=1.9.7
1.8.2 – 1.9.0 Not scanned 2 >=1.8.2 <=1.9.0
1.4.2 – 1.8.1 No issues 3 >=1.4.2 <=1.8.1
1.2.0 Not scanned 1 1.2.0

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of @noble/curves

VersionVerdictFilesScanned
1.9.7 No issues 78 Oct 4, 2026
1.9.1 No issues 75 Oct 4, 2026
1.8.1 No issues 66 Oct 4, 2026
1.8.0 No issues 66 Oct 4, 2026
1.4.2 No issues 63 Oct 4, 2026

Frequently asked questions

Is @noble/curves safe to use?

Our AI source review of @noble/curves@1.9.1 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does @noble/curves contain malware?

No malware was identified in @noble/curves@1.9.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @noble/curves checked?

Togoder Security downloaded the published npm package and had an AI model read its 75 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @noble/curves together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @noble/curves@1.9.1, cost nothing.

Related security reports