Summary
Togoder Security scanned the npm package @noble/curves@1.9.7 on Oct 4, 2026. An AI review of 78 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings 1
intentional_import_guard
NPS-B65BAC756F6F
The root module throws an Error when imported directly, instructing users to import submodules instead. This is a deliberate design choice by the @noble/curves library to prevent importing the root entry point, which would load all curve variants. It is not a malicious pattern; no data exfiltration, credential harvesting, obfuscation, dynamic execution, network activity, filesystem manipulation, or process spawning is present.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| _shortw_utils.js | safe | No malicious patterns detected |
| abstract/bls.js | safe | No malicious patterns detected; the code is a standard cryptographic implementation for BLS signatures with no signs of data exfiltration, environment harvesting, dynamic code execution, or other security concerns. |
| abstract/curve.js | safe | This is the legitimate noble-curves elliptic curve cryptography library; no malicious patterns, data exfiltration, obfuscation, or backdoors were detected. |
| abstract/edwards.js | safe | No malicious patterns detected; this is a legitimate implementation of twisted Edwards curve cryptography from the noble-curves library. |
| abstract/fft.js | safe | No malicious patterns detected; the code is a pure mathematical FFT/NTT implementation with no network, filesystem, process, or dynamic execution behavior. |
| abstract/hash-to-curve.js | safe | No malicious patterns detected |
| abstract/modular.js | safe | No malicious patterns detected; the code is a legitimate cryptographic modular arithmetic utility from the noble-curves library. |
| abstract/montgomery.js | safe | This is a legitimate implementation of the Montgomery curve ladder for X25519/X448 cryptography from the noble-curves library with no malicious patterns detected. |
| abstract/poseidon.js | safe | No malicious patterns detected; this is a legitimate cryptographic hash implementation with no data exfiltration, credential harvesting, obfuscation, or other red flags. |
| abstract/tower.js | safe | No malicious patterns detected |
| abstract/utils.js | safe | No malicious patterns detected; this is a deprecated re-export shim forwarding utility functions from a local module. |
| abstract/weierstrass.js | safe | No malicious patterns detected; this is the legitimate noble-curves elliptic curve cryptography library implementing standard ECDH/ECDSA with no exfiltration, backdoors, or suspicious behavior. |
| bls12-381.js | safe | This is a legitimate BLS12-381 elliptic curve cryptography implementation from the noble-curves library with no malicious patterns detected. |
| bn254.js | safe | No malicious patterns detected; this is a legitimate implementation of the bn254 elliptic curve from the noble-curves library. |
| ed25519.js | safe | This file is the legitimate open-source noble-curves ed25519 implementation containing only cryptographic curve math and no malicious patterns such as exfiltration, credential harvesting, obfuscation, or process spawning. |
| ed448.js | safe | No malicious patterns detected; this is a legitimate cryptographic library implementation for Ed448 and related curves from the noble-curves project. |
| esm/_shortw_utils.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/abstract/bls.js | safe | No malicious patterns detected in the BLS signature implementation from the noble-curves library. |
| esm/abstract/curve.js | safe | No malicious patterns detected; the file implements well-known cryptographic algorithms from the noble-curves library with no network, filesystem, process, or obfuscated code. |
| esm/abstract/edwards.js | safe | No malicious patterns detected; the code is a legitimate cryptographic implementation of the Twisted Edwards curve and EdDSA. |
| esm/abstract/fft.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/abstract/hash-to-curve.js | safe | No malicious patterns detected; the code is a standard cryptographic hash-to-curve implementation. |
| esm/abstract/modular.js | safe | No malicious patterns detected; the file is a legitimate cryptographic modular arithmetic utility from the noble-curves library. |
| esm/abstract/montgomery.js | safe | No malicious patterns detected; the code is a legitimate implementation of Montgomery curve operations from the noble-curves cryptographic library. |
| esm/abstract/poseidon.js | safe | No malicious patterns detected |
Show 53 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| esm/abstract/tower.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/abstract/utils.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/abstract/weierstrass.js | safe | The code is a standard implementation of elliptic curve cryptography (Weierstrass curves) from the noble-curves library, with no malicious patterns detected. |
| esm/bls12-381.js | safe | No malicious patterns detected |
| esm/bn254.js | safe | No malicious patterns detected in this bn254 elliptic curve implementation; it is a legitimate cryptographic library module with no data exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
| esm/ed25519.js | safe | No malicious patterns detected; this is a legitimate cryptographic library implementation of Ed25519, X25519, and Ristretto255 from noble-curves. |
| esm/ed448.js | safe | No malicious patterns detected; the file is a legitimate cryptographic implementation for the Noble Curves library (Ed448, X448, Decaf448). |
| esm/index.js | safe | The file is a benign guard that prevents direct import of the package root, with no malicious behavior detected. |
| esm/jubjub.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/misc.js | safe | No malicious patterns detected |
| esm/nist.js | safe | This is a legitimate cryptographic library implementation for NIST P256/P384/P521 curves with no malicious patterns detected. |
| esm/p256.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/p384.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/p521.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/pasta.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/secp256k1.js | safe | No malicious patterns detected in this secp256k1 elliptic curve implementation from the noble-curves library. |
| esm/utils.js | safe | No malicious patterns detected; the file contains only legitimate cryptographic utility functions for the noble-curves library. |
| index.js | safe | The file is a harmless guard that prevents direct import of the package root, with no malicious patterns detected |
| jubjub.js | safe | No malicious patterns detected; the file is a simple deprecated re-export shim for @noble/curves with no dynamic execution, network, filesystem, or process activity. |
| misc.js | safe | No malicious patterns detected in this cryptographic curve implementation from noble-curves. |
| nist.js | safe | This is a legitimate implementation of NIST elliptic curves from the noble-curves library with no malicious patterns detected. |
| p256.js | safe | No malicious patterns detected in this deprecation shim that only re-exports p256 curve functions from the internal nist module. |
| p384.js | safe | This is a simple deprecated re-export shim for the @noble/curves library's P-384 implementation, containing no malicious patterns, network activity, credential harvesting, or dynamic code execution. |
| p521.js | safe | No malicious patterns detected; file only re-exports deprecated curve utilities from a local nist module. |
| pasta.js | safe | No malicious patterns detected; the file only re-exports deprecated functions from a local module. |
| secp256k1.js | safe | No malicious patterns detected; the code is a legitimate implementation of secp256k1 elliptic curve cryptography from the noble-curves library. |
| src/_shortw_utils.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/abstract/bls.ts | safe | No malicious patterns detected; the file is a legitimate BLS signature implementation with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| src/abstract/curve.ts | safe | The code is a clean implementation of elliptic curve multiplication algorithms (wNAF, Pippenger) from the noble-curves library with no malicious patterns detected. |
| src/abstract/edwards.ts | safe | This is a legitimate cryptographic implementation of Edwards curves from the noble-curves library with no malicious patterns detected. |
| src/abstract/fft.ts | safe | No malicious patterns detected; the code is a pure TypeScript implementation of NTT/FFT over finite fields with no network, filesystem, process execution, or obfuscated behavior. |
| src/abstract/hash-to-curve.ts | safe | No malicious patterns detected; the file is a legitimate cryptographic hash-to-curve implementation from noble-curves following RFC 9380 with no external communication, credential access, or dynamic code execution. |
| src/abstract/modular.ts | safe | No malicious patterns detected; the code is a legitimate cryptographic utility library for modular arithmetic and finite fields. |
| src/abstract/montgomery.ts | safe | No malicious patterns detected; the code is a standard implementation of X25519/X448 Montgomery curve cryptography from the noble-curves library. |
| src/abstract/poseidon.ts | safe | No malicious patterns detected; the code is a legitimate Poseidon hash implementation with only mathematical operations and validation logic. |
| src/abstract/tower.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/abstract/utils.ts | safe | This is a deprecated re-export module that simply aliases utility functions from a sibling module without any malicious patterns. |
| src/abstract/weierstrass.ts | safe | No malicious patterns detected |
| src/bls12-381.ts | safe | No malicious patterns detected; the file is a legitimate BLS12-381 cryptographic curve implementation with no data exfiltration, credential harvesting, obfuscation, dynamic execution, or suspicious network/process activity. |
| src/bn254.ts | safe | No malicious patterns detected in this cryptographic curve implementation for bn254. |
| src/ed25519.ts | safe | This is the legitimate noble-curves ed25519 implementation containing only cryptographic primitives, mathematical operations, and no malicious patterns. |
| src/ed448.ts | safe | No malicious patterns detected; the code is a legitimate cryptographic implementation of Ed448/Decaf448 from the noble-curves library with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior. |
| src/index.ts | safe | No malicious patterns detected; the file only throws an informative error directing users to import submodules. |
| src/jubjub.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/misc.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/nist.ts | safe | No malicious patterns detected; the file contains standard NIST elliptic curve definitions and RFC 9380 hashing logic from the noble-curves library. |
| src/p256.ts | safe | No malicious patterns detected |
| src/p384.ts | safe | No malicious patterns detected; this is a thin deprecated re-export wrapper for the noble-curves p384 implementation. |
| src/p521.ts | safe | No malicious patterns detected; this is a benign re-export module for the noble-curves p521 implementation. |
| src/pasta.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/secp256k1.ts | safe | No malicious patterns detected; this is a legitimate, standard implementation of secp256k1 cryptography from the noble-curves library with no data exfiltration, obfuscation, dynamic execution, or suspicious behavior. |
| src/utils.ts | safe | No malicious patterns detected; this is a legitimate cryptographic utility module from the noble-curves library with standard byte/number/hex conversion and validation functions. |
| utils.js | safe | No malicious patterns detected; this is a legitimate cryptographic utility library (noble-curves) performing standard byte/number conversions, validation, and HMAC-DRBG operations without any exfiltration, dynamic code execution, or process spawning. |
Affected version ranges
None of the 5 scanned versions of @noble/curves are flagged high or critical. The latest scanned version, 1.9.7, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 1.9.1 – 1.9.7 | No issues | 2 | >=1.9.1 <=1.9.7 | |
| 1.8.2 – 1.9.0 | Not scanned | 2 | >=1.8.2 <=1.9.0 | |
| 1.4.2 – 1.8.1 | No issues | 3 | >=1.4.2 <=1.8.1 | |
| 1.2.0 | Not scanned | 1 | 1.2.0 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of @noble/curves
Frequently asked questions
Is @noble/curves safe to use?
Our AI source review of @noble/curves@1.9.7 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does @noble/curves contain malware?
No malware was identified in @noble/curves@1.9.7 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @noble/curves checked?
Togoder Security downloaded the published npm package and had an AI model read its 78 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @noble/curves together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @noble/curves@1.9.7, cost nothing.