# @noble/curves@1.9.7 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:28:06.000Z
- Files reviewed: 78
- Findings: 1 low severity finding
- Report: https://security.togoder.click/npm/@noble/curves@1.9.7
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @noble/curves@1.9.7 on Oct 4, 2026. An AI review of 78 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] intentional_import_guard

Finding ID: `NPS-B65BAC756F6F`

File: `esm/index.js:14`

The root module throws an Error when imported directly, instructing users to import submodules instead. This is a deliberate design choice by the @noble/curves library to prevent importing the root entry point, which would load all curve variants. It is not a malicious pattern; no data exfiltration, credential harvesting, obfuscation, dynamic execution, network activity, filesystem manipulation, or process spawning is present.

## Files reviewed

- `_shortw_utils.js` (safe): No malicious patterns detected
- `abstract/bls.js` (safe): No malicious patterns detected; the code is a standard cryptographic implementation for BLS signatures with no signs of data exfiltration, environment harvesting, dynamic code execution, or other security concerns.
- `abstract/curve.js` (safe): This is the legitimate noble-curves elliptic curve cryptography library; no malicious patterns, data exfiltration, obfuscation, or backdoors were detected.
- `abstract/edwards.js` (safe): No malicious patterns detected; this is a legitimate implementation of twisted Edwards curve cryptography from the noble-curves library.
- `abstract/fft.js` (safe): No malicious patterns detected; the code is a pure mathematical FFT/NTT implementation with no network, filesystem, process, or dynamic execution behavior.
- `abstract/hash-to-curve.js` (safe): No malicious patterns detected
- `abstract/modular.js` (safe): No malicious patterns detected; the code is a legitimate cryptographic modular arithmetic utility from the noble-curves library.
- `abstract/montgomery.js` (safe): This is a legitimate implementation of the Montgomery curve ladder for X25519/X448 cryptography from the noble-curves library with no malicious patterns detected.
- `abstract/poseidon.js` (safe): No malicious patterns detected; this is a legitimate cryptographic hash implementation with no data exfiltration, credential harvesting, obfuscation, or other red flags.
- `abstract/tower.js` (safe): No malicious patterns detected
- `abstract/utils.js` (safe): No malicious patterns detected; this is a deprecated re-export shim forwarding utility functions from a local module.
- `abstract/weierstrass.js` (safe): No malicious patterns detected; this is the legitimate noble-curves elliptic curve cryptography library implementing standard ECDH/ECDSA with no exfiltration, backdoors, or suspicious behavior.
- `bls12-381.js` (safe): This is a legitimate BLS12-381 elliptic curve cryptography implementation from the noble-curves library with no malicious patterns detected.
- `bn254.js` (safe): No malicious patterns detected; this is a legitimate implementation of the bn254 elliptic curve from the noble-curves library.
- `ed25519.js` (safe): This file is the legitimate open-source noble-curves ed25519 implementation containing only cryptographic curve math and no malicious patterns such as exfiltration, credential harvesting, obfuscation, or process spawning.
- `ed448.js` (safe): No malicious patterns detected; this is a legitimate cryptographic library implementation for Ed448 and related curves from the noble-curves project.
- `esm/_shortw_utils.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/abstract/bls.js` (safe): No malicious patterns detected in the BLS signature implementation from the noble-curves library.
- `esm/abstract/curve.js` (safe): No malicious patterns detected; the file implements well-known cryptographic algorithms from the noble-curves library with no network, filesystem, process, or obfuscated code.
- `esm/abstract/edwards.js` (safe): No malicious patterns detected; the code is a legitimate cryptographic implementation of the Twisted Edwards curve and EdDSA.
- `esm/abstract/fft.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/abstract/hash-to-curve.js` (safe): No malicious patterns detected; the code is a standard cryptographic hash-to-curve implementation.
- `esm/abstract/modular.js` (safe): No malicious patterns detected; the file is a legitimate cryptographic modular arithmetic utility from the noble-curves library.
- `esm/abstract/montgomery.js` (safe): No malicious patterns detected; the code is a legitimate implementation of Montgomery curve operations from the noble-curves cryptographic library.
- `esm/abstract/poseidon.js` (safe): No malicious patterns detected
- `esm/abstract/tower.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/abstract/utils.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/abstract/weierstrass.js` (safe): The code is a standard implementation of elliptic curve cryptography (Weierstrass curves) from the noble-curves library, with no malicious patterns detected.
- `esm/bls12-381.js` (safe): No malicious patterns detected
- `esm/bn254.js` (safe): No malicious patterns detected in this bn254 elliptic curve implementation; it is a legitimate cryptographic library module with no data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
- `esm/ed25519.js` (safe): No malicious patterns detected; this is a legitimate cryptographic library implementation of Ed25519, X25519, and Ristretto255 from noble-curves.
- `esm/ed448.js` (safe): No malicious patterns detected; the file is a legitimate cryptographic implementation for the Noble Curves library (Ed448, X448, Decaf448).
- `esm/index.js` (safe): The file is a benign guard that prevents direct import of the package root, with no malicious behavior detected.
- `esm/jubjub.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/misc.js` (safe): No malicious patterns detected
- `esm/nist.js` (safe): This is a legitimate cryptographic library implementation for NIST P256/P384/P521 curves with no malicious patterns detected.
- `esm/p256.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/p384.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/p521.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/pasta.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/secp256k1.js` (safe): No malicious patterns detected in this secp256k1 elliptic curve implementation from the noble-curves library.
- `esm/utils.js` (safe): No malicious patterns detected; the file contains only legitimate cryptographic utility functions for the noble-curves library.
- `index.js` (safe): The file is a harmless guard that prevents direct import of the package root, with no malicious patterns detected
- `jubjub.js` (safe): No malicious patterns detected; the file is a simple deprecated re-export shim for @noble/curves with no dynamic execution, network, filesystem, or process activity.
- `misc.js` (safe): No malicious patterns detected in this cryptographic curve implementation from noble-curves.
- `nist.js` (safe): This is a legitimate implementation of NIST elliptic curves from the noble-curves library with no malicious patterns detected.
- `p256.js` (safe): No malicious patterns detected in this deprecation shim that only re-exports p256 curve functions from the internal nist module.
- `p384.js` (safe): This is a simple deprecated re-export shim for the @noble/curves library's P-384 implementation, containing no malicious patterns, network activity, credential harvesting, or dynamic code execution.
- `p521.js` (safe): No malicious patterns detected; file only re-exports deprecated curve utilities from a local nist module.
- `pasta.js` (safe): No malicious patterns detected; the file only re-exports deprecated functions from a local module.
- `secp256k1.js` (safe): No malicious patterns detected; the code is a legitimate implementation of secp256k1 elliptic curve cryptography from the noble-curves library.
- `src/_shortw_utils.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/abstract/bls.ts` (safe): No malicious patterns detected; the file is a legitimate BLS signature implementation with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `src/abstract/curve.ts` (safe): The code is a clean implementation of elliptic curve multiplication algorithms (wNAF, Pippenger) from the noble-curves library with no malicious patterns detected.
- `src/abstract/edwards.ts` (safe): This is a legitimate cryptographic implementation of Edwards curves from the noble-curves library with no malicious patterns detected.
- `src/abstract/fft.ts` (safe): No malicious patterns detected; the code is a pure TypeScript implementation of NTT/FFT over finite fields with no network, filesystem, process execution, or obfuscated behavior.
- `src/abstract/hash-to-curve.ts` (safe): No malicious patterns detected; the file is a legitimate cryptographic hash-to-curve implementation from noble-curves following RFC 9380 with no external communication, credential access, or dynamic code execution.
- `src/abstract/modular.ts` (safe): No malicious patterns detected; the code is a legitimate cryptographic utility library for modular arithmetic and finite fields.
- `src/abstract/montgomery.ts` (safe): No malicious patterns detected; the code is a standard implementation of X25519/X448 Montgomery curve cryptography from the noble-curves library.
- `src/abstract/poseidon.ts` (safe): No malicious patterns detected; the code is a legitimate Poseidon hash implementation with only mathematical operations and validation logic.
- `src/abstract/tower.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/abstract/utils.ts` (safe): This is a deprecated re-export module that simply aliases utility functions from a sibling module without any malicious patterns.
- `src/abstract/weierstrass.ts` (safe): No malicious patterns detected
- `src/bls12-381.ts` (safe): No malicious patterns detected; the file is a legitimate BLS12-381 cryptographic curve implementation with no data exfiltration, credential harvesting, obfuscation, dynamic execution, or suspicious network/process activity.
- `src/bn254.ts` (safe): No malicious patterns detected in this cryptographic curve implementation for bn254.
- `src/ed25519.ts` (safe): This is the legitimate noble-curves ed25519 implementation containing only cryptographic primitives, mathematical operations, and no malicious patterns.
- `src/ed448.ts` (safe): No malicious patterns detected; the code is a legitimate cryptographic implementation of Ed448/Decaf448 from the noble-curves library with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior.
- `src/index.ts` (safe): No malicious patterns detected; the file only throws an informative error directing users to import submodules.
- `src/jubjub.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/misc.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/nist.ts` (safe): No malicious patterns detected; the file contains standard NIST elliptic curve definitions and RFC 9380 hashing logic from the noble-curves library.
- `src/p256.ts` (safe): No malicious patterns detected
- `src/p384.ts` (safe): No malicious patterns detected; this is a thin deprecated re-export wrapper for the noble-curves p384 implementation.
- `src/p521.ts` (safe): No malicious patterns detected; this is a benign re-export module for the noble-curves p521 implementation.
- `src/pasta.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/secp256k1.ts` (safe): No malicious patterns detected; this is a legitimate, standard implementation of secp256k1 cryptography from the noble-curves library with no data exfiltration, obfuscation, dynamic execution, or suspicious behavior.
- `src/utils.ts` (safe): No malicious patterns detected; this is a legitimate cryptographic utility module from the noble-curves library with standard byte/number/hex conversion and validation functions.
- `utils.js` (safe): No malicious patterns detected; this is a legitimate cryptographic utility library (noble-curves) performing standard byte/number conversions, validation, and HMAC-DRBG operations without any exfiltration, dynamic code execution, or process spawning.

## Version ranges

None of the 5 scanned versions of @noble/curves are flagged high or critical. The latest scanned version, 1.9.7, is clean. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 1.9.1 – 1.9.7 (`>=1.9.1 <=1.9.7`): clean
- 1.8.2 – 1.9.0 (`>=1.8.2 <=1.9.0`): not scanned
- 1.4.2 – 1.8.1 (`>=1.4.2 <=1.8.1`): clean
- 1.2.0 (`1.2.0`): not scanned

## Scanned versions

- [1.9.7](https://security.togoder.click/npm/@noble/curves@1.9.7): safe, 2026-10-04T16:28:06.000Z
- [1.9.1](https://security.togoder.click/npm/@noble/curves@1.9.1): safe, 2026-10-04T16:09:03.000Z
- [1.8.1](https://security.togoder.click/npm/@noble/curves@1.8.1): safe, 2026-10-04T16:09:43.000Z
- [1.8.0](https://security.togoder.click/npm/@noble/curves@1.8.0): safe, 2026-10-04T16:20:25.000Z
- [1.4.2](https://security.togoder.click/npm/@noble/curves@1.4.2): safe, 2026-10-04T16:30:03.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
