# @noble/curves@1.9.1 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:09:03.000Z
- Files reviewed: 75
- Findings: 1 low severity finding
- Report: https://security.togoder.click/npm/@noble/curves@1.9.1
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @noble/curves@1.9.1 on Oct 4, 2026. An AI review of 75 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] No malicious patterns

Finding ID: `NPS-D697DF322D8A`

File: `src/abstract/poseidon.ts`

The code is a legitimate implementation of the Poseidon hash function and sponge construction. It contains no data exfiltration, credential harvesting, obfuscated code, dynamic code execution, cryptocurrency mining, backdoors, suspicious network requests, file system manipulation, process spawning, or dynamic imports. All operations are purely cryptographic computations within the provided finite field abstraction.

## Files reviewed

- `_shortw_utils.js` (safe): No malicious patterns detected; the code is a legitimate utility module from noble-curves for connecting hash functions to elliptic curve implementations.
- `abstract/bls.js` (safe): No malicious patterns detected; this is a legitimate implementation of BLS signatures from the noble-curves cryptography library.
- `abstract/curve.js` (safe): No malicious patterns detected; this is legitimate elliptic curve cryptography code from the noble-curves library.
- `abstract/edwards.js` (safe): This is a legitimate cryptographic implementation of Twisted Edwards curves from the noble-curves library; no malicious patterns or security concerns were detected.
- `abstract/fft.js` (safe): No malicious patterns detected; the code is a pure mathematical FFT/NTT implementation with no network, filesystem, process, or dynamic execution activity.
- `abstract/hash-to-curve.js` (safe): No malicious patterns detected
- `abstract/modular.js` (safe): No malicious patterns detected; the file contains standard modular arithmetic and finite field utilities from the noble-curves library with no network, filesystem, process, or dynamic code execution behavior.
- `abstract/montgomery.js` (safe): No malicious patterns detected; the code is a legitimate implementation of Montgomery curve methods for X25519/X448 from the noble-curves library.
- `abstract/poseidon.js` (safe): This is a legitimate cryptographic Poseidon hash implementation from the noble-curves library with no malicious patterns detected
- `abstract/tower.js` (safe): This is a legitimate cryptographic library implementation of tower field arithmetic for pairing-based cryptography from the noble-curves project, with no malicious patterns detected.
- `abstract/utils.js` (safe): No malicious patterns detected; the file contains standard cryptographic utility functions from the noble-curves library without any exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
- `abstract/weierstrass.js` (safe): Legitimate noble-curves cryptography library implementing Weierstrass elliptic curve operations with no malicious patterns, no external network calls, no environment variable harvesting, and no dynamic code execution.
- `bls12-381.js` (safe): No malicious patterns detected; the code is a standard cryptographic implementation of BLS12-381 with no data exfiltration, obfuscation, or dynamic execution.
- `bn254.js` (safe): No malicious patterns detected; the code is a legitimate cryptographic implementation of the bn254 curve from the noble-curves library.
- `ed25519.js` (safe): No malicious patterns detected in this cryptographic library implementation of ed25519, x25519, and Ristretto255.
- `ed448.js` (safe): No malicious patterns detected; this is a legitimate cryptographic library implementing Ed448/X448/Decaf448 curves from noble-curves.
- `esm/_shortw_utils.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/abstract/bls.js` (safe): No malicious patterns detected; the code is a legitimate BLS signature implementation from the noble-curves library with no exfiltration, credential harvesting, obfuscation, or other security concerns.
- `esm/abstract/curve.js` (safe): No malicious patterns detected; this is legitimate elliptic curve cryptography code from the noble-curves library with no exfiltration, dynamic execution, or other red flags.
- `esm/abstract/edwards.js` (safe): No malicious patterns detected
- `esm/abstract/fft.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/abstract/hash-to-curve.js` (safe): This is a clean implementation of RFC 9380 hash-to-curve cryptography with no malicious patterns detected.
- `esm/abstract/modular.js` (safe): This is a legitimate cryptographic utility module from the noble-curves library implementing modular arithmetic and finite field operations, with no malicious patterns detected.
- `esm/abstract/montgomery.js` (safe): No malicious patterns detected; the code is a standard implementation of Montgomery curve X25519/X448 cryptography from the noble-curves library.
- `esm/abstract/poseidon.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/abstract/tower.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/abstract/utils.js` (safe): No malicious patterns detected
- `esm/abstract/weierstrass.js` (safe): No malicious patterns detected
- `esm/bls12-381.js` (safe): No malicious patterns detected; the code is a legitimate implementation of the BLS12-381 cryptographic curve from the noble-curves library.
- `esm/bn254.js` (safe): No malicious patterns detected; the file is a legitimate cryptographic library implementation for the bn254 curve from noble-curves.
- `esm/ed25519.js` (safe): No malicious patterns detected; this is legitimate cryptographic code from the noble-curves library implementing Ed25519, X25519, and Ristretto255 primitives with no network, filesystem, process, or dynamic code execution activity.
- `esm/ed448.js` (safe): No malicious patterns detected; this is a legitimate cryptographic library implementation of Ed448, X448, and Decaf448 with no data exfiltration, obfuscation, or suspicious behavior.
- `esm/index.js` (safe): No malicious patterns detected; the file intentionally throws an error to prevent direct import of the root module and contains no executable malicious code.
- `esm/jubjub.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/misc.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/nist.js` (safe): No malicious patterns detected; the file contains standard cryptographic curve definitions for NIST P-256, P-384, and P-521 from the noble-curves library.
- `esm/p256.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/p384.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/p521.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/pasta.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/secp256k1.js` (safe): No malicious patterns detected; the file is a legitimate well-known cryptographic implementation for secp256k1 with no data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
- `index.js` (safe): No malicious patterns detected; the file only throws an error to prevent root module import, which is a legitimate design choice in the @noble/curves library.
- `jubjub.js` (safe): No malicious patterns detected
- `misc.js` (safe): No malicious patterns detected; the file defines well-known elliptic curves (jubjub, babyjubjub, pallas, vesta) using standard noble-curves primitives without any exfiltration, obfuscation, network, filesystem, or process execution behavior.
- `nist.js` (safe): No malicious patterns detected
- `p256.js` (safe): No malicious patterns detected; the file is a simple re-export module that delegates to the local nist.js implementation.
- `p384.js` (safe): No malicious patterns detected; the file only re-exports symbols from the local nist.js module and contains no external calls, dynamic execution, or filesystem/network activity.
- `p521.js` (safe): No malicious patterns detected
- `pasta.js` (safe): No malicious patterns detected; the file only re-exports deprecated functions from a local module.
- `secp256k1.js` (safe): This is a legitimate implementation of secp256k1 cryptographic curve operations from the noble-curves library, with no malicious patterns detected.
- `src/_shortw_utils.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/abstract/bls.ts` (safe): No malicious patterns detected; the file is a legitimate implementation of BLS signature cryptography from the noble-curves library.
- `src/abstract/curve.ts` (safe): No malicious patterns detected; the code is a legitimate elliptic curve cryptography implementation from the noble-curves library with no data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
- `src/abstract/edwards.ts` (safe): No malicious patterns detected
- `src/abstract/fft.ts` (safe): No malicious patterns detected; the code is a legitimate FFT/NTT implementation over finite fields with no network, filesystem, process, or credential-access operations.
- `src/abstract/hash-to-curve.ts` (safe): No malicious patterns detected; the code is a legitimate implementation of RFC 9380 hash-to-curve for cryptographic libraries.
- `src/abstract/modular.ts` (safe): No malicious patterns detected; the code implements standard modular arithmetic and finite field operations for cryptographic purposes.
- `src/abstract/montgomery.ts` (safe): No malicious patterns detected; the code is a legitimate implementation of X25519/X448 Montgomery curve operations from the noble-curves library.
- `src/abstract/poseidon.ts` (safe): No malicious patterns detected; the code is a standard cryptographic implementation of Poseidon hash and sponge.
- `src/abstract/tower.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/abstract/utils.ts` (safe): No malicious patterns detected
- `src/abstract/weierstrass.ts` (safe): No malicious patterns detected; this is a legitimate cryptographic library implementation for Weierstrass elliptic curves.
- `src/bls12-381.ts` (safe): The file is a legitimate implementation of the BLS12-381 elliptic curve from the noble-curves library, with no malicious patterns, network activity, credential access, or dynamic code execution detected.
- `src/bn254.ts` (safe): No malicious patterns detected; the file is a legitimate cryptographic implementation of the bn254 curve with no network, filesystem, process, or obfuscated code.
- `src/ed25519.ts` (safe): No malicious patterns detected
- `src/ed448.ts` (safe): No malicious patterns detected; the code is a legitimate cryptographic implementation of Ed448, X448, and Decaf448 from the noble-curves library.
- `src/index.ts` (safe): No malicious patterns detected; the file only throws a static error message intended to prevent incorrect root module imports.
- `src/jubjub.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/misc.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/nist.ts` (safe): No malicious patterns detected in this standard cryptographic curve implementation file.
- `src/p256.ts` (safe): No malicious patterns detected; the file only re-exports P-256 curve primitives and hash-to-curve helpers with no network, filesystem, process, or dynamic code execution behavior.
- `src/p384.ts` (safe): No malicious patterns detected; the code is a straightforward cryptographic module re-exporting secp384r1 primitives from the noble-curves library.
- `src/p521.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/pasta.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/secp256k1.ts` (safe): No malicious patterns detected; the file is a standard cryptographic implementation of secp256k1 and Schnorr signatures from the noble-curves library with no data exfiltration, credential harvesting, obfuscated payloads, or suspicious runtime behavior.

## Version ranges

None of the 5 scanned versions of @noble/curves are flagged high or critical. The latest scanned version, 1.9.7, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 1.9.1 – 1.9.7 (`>=1.9.1 <=1.9.7`): clean
- 1.8.2 – 1.9.0 (`>=1.8.2 <=1.9.0`): not scanned
- 1.4.2 – 1.8.1 (`>=1.4.2 <=1.8.1`): clean
- 1.2.0 (`1.2.0`): not scanned

## Scanned versions

- [1.9.7](https://security.togoder.click/npm/@noble/curves@1.9.7): safe, 2026-10-04T16:28:06.000Z
- [1.9.1](https://security.togoder.click/npm/@noble/curves@1.9.1): safe, 2026-10-04T16:09:03.000Z
- [1.8.1](https://security.togoder.click/npm/@noble/curves@1.8.1): safe, 2026-10-04T16:09:43.000Z
- [1.8.0](https://security.togoder.click/npm/@noble/curves@1.8.0): safe, 2026-10-04T16:20:25.000Z
- [1.4.2](https://security.togoder.click/npm/@noble/curves@1.4.2): safe, 2026-10-04T16:30:03.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
