Togoder security

npm package security report

@noble/hashes npm package: is it safe?

No malicious code found.

No issues Version 1.8.0 Files reviewed 81 Size 516.6 KB Scanned

Summary

Togoder Security scanned the npm package @noble/hashes@1.8.0 on Oct 4, 2026. An AI review of 81 source files produced 4 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
4
low

Findings 4

low

Deprecation notice

NPS-FA8BBC5D7CFB

The module is marked as deprecated and re-exports symbols from other modules. This is not a security issue but may indicate an old API surface.

blake2s.js
low

global_shared_buffer

NPS-F930CF318838

A2_BUF is a module-level shared buffer used by block()/G(). This is standard for performance in Argon2 implementations, but it is not re-entrant; if used with worker threads concurrently it could cause races. The async variants yield to event loop while using this shared state, which is a design tradeoff rather than malicious behavior.

esm/argon2.js:61
low

memory_cleanup_side_effect

NPS-7962B732A64A

The shared A2_BUF temporary buffer is zeroed with clean(A2_BUF) after each block() call. This is a hygiene measure, not a security flaw, and is consistent with clearing cryptographic intermediates.

esm/argon2.js:143
low

weak cryptography

NPS-4E2BBF9F55E3

The file implements legacy, cryptographically weak hash functions (MD5, SHA1, RIPEMD160). The code itself documents these as deprecated and warns against their use in new protocols. While weak for security purposes, this is a known and intentional library implementation, not malicious.

legacy.js

Files reviewed

FileVerdictWhat the reviewer saw
_assert.js safe No malicious patterns detected; the file only contains deprecated re-exports of assertion helper functions from an internal utility module.
_blake.js safe No malicious patterns detected
_md.js safe This file implements standard Merkle-Damgard hash utilities (SHA-2 family) with no malicious patterns detected.
_u64.js safe No malicious patterns detected; the file contains only pure 64-bit integer arithmetic helper functions with no I/O, network, environment access, or dynamic code execution.
argon2.js safe No malicious patterns detected; the code is a pure JavaScript implementation of the Argon2 key derivation function with no network, filesystem, process, or dynamic code execution activities.
blake1.js safe No malicious patterns detected; the code is a legitimate BLAKE1 hash implementation with no network, filesystem, or dynamic code execution behavior.
blake2.js safe No malicious patterns detected; the code is a standard implementation of BLAKE2b and BLAKE2s cryptographic hash functions.
blake2b.js safe Cleared by Jev triage; no further analysis needed
blake2s.js safe No malicious patterns detected; the file only re-exports cryptographic primitives from internal modules.
blake3.js safe This is a legitimate BLAKE3 cryptographic hash implementation with no suspicious network, filesystem, process, or obfuscated code patterns.
crypto.js safe No malicious patterns detected; the file is a harmless utility that exports the global crypto object if available.
cryptoNode.js safe No malicious patterns detected; the code simply provides a WebCrypto alias using Node.js built-in crypto module.
eskdf.js safe No malicious patterns detected; the file implements a legitimate experimental key-derivation function (ESKDF) using scrypt, PBKDF2, and HKDF with no exfiltration, dynamic execution, process spawning, or install-time hooks.
esm/_assert.js safe Cleared by Jev triage; no further analysis needed
esm/_blake.js safe Cleared by Jev triage; no further analysis needed
esm/_md.js safe Cleared by Jev triage; no further analysis needed
esm/_u64.js safe Cleared by Jev triage; no further analysis needed
esm/argon2.js safe This is a legitimate pure-JS Argon2 KDF implementation with no malicious patterns, network activity, file system access, or code execution.
esm/blake1.js safe No malicious patterns detected; this is a standard implementation of the BLAKE1 hash function with no network, filesystem, or dynamic code execution activity.
esm/blake2.js safe Cleared by Jev triage; no further analysis needed
esm/blake2b.js safe Cleared by Jev triage; no further analysis needed
esm/blake2s.js safe Cleared by Jev triage; no further analysis needed
esm/blake3.js safe No malicious patterns detected; the file is a standard BLAKE3 cryptographic hash implementation with no network, filesystem, process, or dynamic execution behavior.
esm/crypto.js safe Cleared by Jev triage; no further analysis needed
esm/cryptoNode.js safe Cleared by Jev triage; no further analysis needed
Show 56 more files
FileVerdictWhat the reviewer saw
esm/eskdf.js safe The code is a legitimate key derivation function implementation with no malicious patterns detected.
esm/hkdf.js safe Cleared by Jev triage; no further analysis needed
esm/hmac.js safe Cleared by Jev triage; no further analysis needed
esm/index.js safe The file contains only documentation and a deliberate error throw to prevent root module import; no malicious patterns detected.
esm/legacy.js safe Cleared by Jev triage; no further analysis needed
esm/pbkdf2.js safe Cleared by Jev triage; no further analysis needed
esm/ripemd160.js safe Cleared by Jev triage; no further analysis needed
esm/scrypt.js safe Cleared by Jev triage; no further analysis needed
esm/sha1.js safe Cleared by Jev triage; no further analysis needed
esm/sha2.js safe No malicious patterns detected; the file is a legitimate SHA-2 hash implementation with no network, filesystem, process, or dynamic code execution activity.
esm/sha256.js safe Cleared by Jev triage; no further analysis needed
esm/sha3-addons.js safe Cleared by Jev triage; no further analysis needed
esm/sha3.js safe No malicious patterns detected; the file is a legitimate SHA-3/Keccak hash implementation with no exfiltration, credential harvesting, obfuscation, mining, backdoor, or install-time execution.
esm/sha512.js safe Cleared by Jev triage; no further analysis needed
esm/utils.js safe No malicious patterns detected; the file contains standard cryptographic utility functions from the noble-hashes library with no exfiltration, obfuscation, or dynamic code execution.
hkdf.js safe Cleared by Jev triage; no further analysis needed
hmac.js safe No malicious patterns detected; the file is a standard HMAC implementation from the @noble/hashes library.
index.js safe The file is an index module that only throws an error directing users to import submodules; no malicious patterns detected.
legacy.js safe No malicious patterns detected; the code is a standard implementation of legacy hash functions with clear warnings about their cryptographic weaknesses.
pbkdf2.js safe No malicious patterns detected; this is a legitimate implementation of PBKDF2-HMAC key derivation with standard cryptographic cleanup and no external network, filesystem, or process interactions.
ripemd160.js safe No malicious patterns detected; the file is a simple re-export shim for the deprecated noble/hashes RIPEMD-160 implementation with no executable code beyond module exports.
scrypt.js safe No malicious patterns detected; the code is a standard, clean implementation of the RFC 7914 scrypt key derivation function with no network, filesystem, process, or dynamic execution activity.
sha1.js safe No malicious patterns detected
sha2.js safe No malicious patterns detected: the code is a standard SHA-2 hash implementation with no network, filesystem, process execution, obfuscation, or credential harvesting activity.
sha256.js safe This file is a simple deprecated re-export module for SHA-256/224 hash functions from the noble/hashes library, containing no malicious patterns or suspicious behavior.
sha3-addons.js safe No malicious patterns detected; the code is a clean implementation of SHA-3 addons (cSHAKE, KMAC, TupleHash, ParallelHash, KangarooTwelve, TurboSHAKE, KeccakPRG) with no network, filesystem, process, or dynamic code execution behavior.
sha3.js safe No malicious patterns detected; the file implements standard SHA-3/Keccak hashing without network, filesystem, process, or dynamic execution behavior.
sha512.js safe No malicious patterns detected; the file is a deprecated re-export shim for SHA-2 hash functions from a sibling module.
src/_assert.ts safe Cleared by Jev triage; no further analysis needed
src/_blake.ts safe Cleared by Jev triage; no further analysis needed
src/_md.ts safe Cleared by Jev triage; no further analysis needed
src/_u64.ts safe Cleared by Jev triage; no further analysis needed
src/argon2.ts safe No malicious patterns detected; this is a pure TypeScript implementation of the Argon2 password hashing algorithm from RFC 9106 with no network, filesystem, process spawning, or credential access behaviors.
src/blake1.ts safe No malicious patterns detected
src/blake2.ts safe Cleared by Jev triage; no further analysis needed
src/blake2b.ts safe Cleared by Jev triage; no further analysis needed
src/blake2s.ts safe Cleared by Jev triage; no further analysis needed
src/blake3.ts safe No malicious patterns detected; the code is a standard cryptographic BLAKE3 hash implementation with no network, filesystem, process, or dynamic code execution behaviors.
src/crypto.ts safe Cleared by Jev triage; no further analysis needed
src/cryptoNode.ts safe Cleared by Jev triage; no further analysis needed
src/eskdf.ts safe No malicious patterns detected; the code is a standard cryptographic key derivation module using scrypt, PBKDF2, and HKDF without any exfiltration, obfuscation, or system-level access.
src/hkdf.ts safe Cleared by Jev triage; no further analysis needed
src/hmac.ts safe Cleared by Jev triage; no further analysis needed
src/index.ts safe The file only throws an error to prevent direct import of the root module; no malicious patterns detected.
src/legacy.ts safe Cleared by Jev triage; no further analysis needed
src/pbkdf2.ts safe Cleared by Jev triage; no further analysis needed
src/ripemd160.ts safe Cleared by Jev triage; no further analysis needed
src/scrypt.ts safe No malicious patterns detected; the code is a legitimate, well-known implementation of the scrypt key derivation function with no signs of data exfiltration, credential harvesting, obfuscation, or other security concerns.
src/sha1.ts safe Cleared by Jev triage; no further analysis needed
src/sha2.ts safe This is a legitimate and standard implementation of SHA-2 hash functions (SHA-256, SHA-384, SHA-512, etc.) with no malicious patterns, network activity, or suspicious behavior detected.
src/sha256.ts safe Cleared by Jev triage; no further analysis needed
src/sha3-addons.ts safe Cleared by Jev triage; no further analysis needed
src/sha3.ts safe This is a legitimate implementation of SHA-3/Keccak hashing with no malicious patterns, network activity, credential access, or code execution observed.
src/sha512.ts safe Cleared by Jev triage; no further analysis needed
src/utils.ts safe No malicious patterns detected; the code is a legitimate utility module from the noble-hashes cryptographic library with standard hash/encoding helpers and CSPRNG access.
utils.js safe No malicious patterns detected; this is the well-known noble-hashes utility module providing legitimate cryptographic primitives and CSPRNG access via the platform crypto API.

Affected version ranges

None of the 5 scanned versions of @noble/hashes are flagged high or critical. The latest scanned version, 2.2.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

1.3.22.2.0
VersionsVerdictCountRangeTop findings
2.2.0 Not scanned 1 2.2.0
1.8.0 No issues 1 1.8.0
1.7.2 Not scanned 1 1.7.2
1.3.3 โ€“ 1.7.1 No issues 4 >=1.3.3 <=1.7.1
1.3.2 Not scanned 1 1.3.2

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of @noble/hashes

VersionVerdictFilesScanned
1.8.0 No issues 81 Oct 4, 2026
1.7.1 No issues 75 Oct 4, 2026
1.7.0 No issues 72 Oct 4, 2026
1.4.0 No issues 72 Oct 4, 2026
1.3.3 No issues 72 Oct 4, 2026

Frequently asked questions

Is @noble/hashes safe to use?

Our AI source review of @noble/hashes@1.8.0 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does @noble/hashes contain malware?

No malware was identified in @noble/hashes@1.8.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @noble/hashes checked?

Togoder Security downloaded the published npm package and had an AI model read its 81 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @noble/hashes together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @noble/hashes@1.8.0, cost nothing.

Related security reports