Togoder security

npm package security report

@noble/hashes@1.3.3 security report

No malicious code found.

No issues Version 1.3.3 Files reviewed 72 Size 380.3 KB Scanned

Summary

Togoder Security scanned the npm package @noble/hashes@1.3.3 on Oct 4, 2026. An AI review of 72 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
0
low

Findings

No findings. The reviewer saw nothing malicious or risky in this version.

Files reviewed

FileVerdictWhat the reviewer saw
_assert.js safe No malicious patterns detected
_blake2.js safe No malicious patterns detected; the code is a standard BLAKE2 hash implementation with no network, filesystem, process, or dynamic execution activity.
_sha2.js safe No malicious patterns detected; this is a standard SHA-2 cryptographic hash implementation with no network, filesystem, process, or dynamic code execution concerns.
_u64.js safe No malicious patterns detected; the file implements standard 64-bit arithmetic helpers using BigInt and typed arrays without any network, filesystem, or process-related operations.
argon2.js safe No malicious patterns detected; the code is a legitimate Argon2 password hashing implementation with no exfiltration, credential harvesting, obfuscation, or process execution.
blake2b.js safe No malicious patterns detected in this BLAKE2b cryptographic hash implementation
blake2s.js safe No malicious patterns detected; the file is a standard BLAKE2s cryptographic hash implementation with no network, filesystem, process, or dynamic execution behavior.
blake3.js safe The code is a clean implementation of the BLAKE3 cryptographic hash function with no malicious patterns detected.
crypto.js safe No malicious patterns detected; the file is a harmless utility that exports the global crypto object if available.
cryptoNode.js safe No malicious patterns detected
eskdf.js safe No malicious patterns detected; the code implements a cryptographic key derivation function using standard primitives (scrypt, pbkdf2, hkdf) with no network, filesystem, process, or dynamic code execution.
esm/_assert.js safe Cleared by Jev triage; no further analysis needed
esm/_blake2.js safe Cleared by Jev triage; no further analysis needed
esm/_sha2.js safe Cleared by Jev triage; no further analysis needed
esm/_u64.js safe Cleared by Jev triage; no further analysis needed
esm/argon2.js safe No malicious patterns detected; the code is a legitimate Argon2 password hashing implementation without any exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
esm/blake2b.js safe Cleared by Jev triage; no further analysis needed
esm/blake2s.js safe Cleared by Jev triage; no further analysis needed
esm/blake3.js safe No malicious patterns detected; the code is a standard BLAKE3 cryptographic hash implementation with no network, filesystem, process execution, or obfuscation concerns.
esm/crypto.js safe Cleared by Jev triage; no further analysis needed
esm/cryptoNode.js safe Cleared by Jev triage; no further analysis needed
esm/eskdf.js safe No malicious patterns detected; the code implements a standard, self-contained KDF library without network, filesystem, process, or dynamic execution behavior.
esm/hkdf.js safe Cleared by Jev triage; no further analysis needed
esm/hmac.js safe Cleared by Jev triage; no further analysis needed
esm/index.js safe No malicious patterns detected; the file intentionally throws an error to prevent direct import, which is a legitimate design pattern for this package.
Show 47 more files
FileVerdictWhat the reviewer saw
esm/pbkdf2.js safe Cleared by Jev triage; no further analysis needed
esm/ripemd160.js safe No malicious patterns detected; the code is a standard RIPEMD-160 hash implementation with no network, filesystem, process, or dynamic execution activity.
esm/scrypt.js safe Cleared by Jev triage; no further analysis needed
esm/sha1.js safe Cleared by Jev triage; no further analysis needed
esm/sha2.js safe Cleared by Jev triage; no further analysis needed
esm/sha256.js safe Cleared by Jev triage; no further analysis needed
esm/sha3-addons.js safe Cleared by Jev triage; no further analysis needed
esm/sha3.js safe No malicious patterns detected
esm/sha512.js safe No malicious patterns detected
esm/utils.js safe This is a legitimate utility module from the noble-hashes cryptographic library containing only standard hashing helpers with no malicious patterns.
hkdf.js safe Cleared by Jev triage; no further analysis needed
hmac.js safe No malicious patterns detected; the code is a clean implementation of HMAC (RFC 2104) using standard cryptographic primitives.
index.js safe No malicious patterns detected; the file intentionally throws an error to prevent direct import, which is a legitimate design pattern for this package.
pbkdf2.js safe This is a legitimate implementation of the PBKDF2 key derivation function from the @noble/hashes library, with no malicious patterns detected.
ripemd160.js safe No malicious patterns detected; the code is a legitimate RIPEMD-160 hash implementation.
scrypt.js safe This is a legitimate implementation of the Scrypt key derivation function with no malicious patterns detected.
sha1.js safe No malicious patterns detected; the code is a standard implementation of the SHA-1 hashing algorithm.
sha2.js safe No malicious patterns detected; this is a simple re-export module for SHA-2 hash functions.
sha256.js safe No malicious patterns detected; this is a legitimate SHA-256/SHA-224 hash implementation with standard algorithm constants and no network, filesystem, process, or dynamic execution behavior.
sha3-addons.js safe No malicious patterns detected; the code is a legitimate implementation of SHA-3 and NIST SP800-185 add-on cryptographic functions without any exfiltration, obfuscation, or backdoor logic.
sha3.js safe No malicious patterns detected; the code is a standard SHA-3/Keccak cryptographic hash implementation with no network, filesystem, process, or dynamic execution behavior.
sha512.js safe No malicious patterns detected; this is a legitimate SHA-512 cryptographic hash implementation with only internal module imports and no network, filesystem, or process operations.
src/_assert.ts safe Cleared by Jev triage; no further analysis needed
src/_blake2.ts safe Cleared by Jev triage; no further analysis needed
src/_sha2.ts safe Cleared by Jev triage; no further analysis needed
src/_u64.ts safe Cleared by Jev triage; no further analysis needed
src/argon2.ts safe No malicious patterns detected; the code is a clean implementation of the Argon2 password hashing algorithm with no network, filesystem, or process manipulation.
src/blake2b.ts safe Cleared by Jev triage; no further analysis needed
src/blake2s.ts safe Cleared by Jev triage; no further analysis needed
src/blake3.ts safe No malicious patterns detected; this is a legitimate BLAKE3 hash function implementation with no network, filesystem, process, or dynamic execution behavior.
src/crypto.ts safe Cleared by Jev triage; no further analysis needed
src/cryptoNode.ts safe Cleared by Jev triage; no further analysis needed
src/eskdf.ts safe No malicious patterns detected; the code is a legitimate key derivation function implementation with no network, filesystem, process, or obfuscated code activity.
src/hkdf.ts safe Cleared by Jev triage; no further analysis needed
src/hmac.ts safe Cleared by Jev triage; no further analysis needed
src/index.ts safe No malicious patterns detected
src/pbkdf2.ts safe Cleared by Jev triage; no further analysis needed
src/ripemd160.ts safe No malicious patterns detected; the file is a standard implementation of the RIPEMD-160 hash algorithm with no network, filesystem, credential, or dynamic code execution behavior.
src/scrypt.ts safe No malicious patterns detected; the code is a legitimate Scrypt KDF implementation without data exfiltration, credential harvesting, obfuscation, or other security concerns.
src/sha1.ts safe Cleared by Jev triage; no further analysis needed
src/sha2.ts safe Cleared by Jev triage; no further analysis needed
src/sha256.ts safe Cleared by Jev triage; no further analysis needed
src/sha3-addons.ts safe Cleared by Jev triage; no further analysis needed
src/sha3.ts safe No malicious patterns detected; the file is a legitimate SHA-3/Keccak implementation from the @noble/hashes library.
src/sha512.ts safe No malicious patterns detected; this is a standard SHA-512/384/224/256 hash implementation from the audited @noble/hashes library.
src/utils.ts safe No malicious patterns detected; this is a legitimate utility module from the noble-hashes cryptography library with standard byte/hex conversion, hashing helpers, and secure RNG usage.
utils.js safe No malicious patterns detected; the code is a standard cryptographic utility library (noble-hashes) with no exfiltration, obfuscation, or suspicious behavior.

Affected version ranges

None of the 5 scanned versions of @noble/hashes are flagged high or critical. The latest scanned version, 2.2.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

1.3.22.2.0
VersionsVerdictCountRangeTop findings
2.2.0 Not scanned 1 2.2.0
1.8.0 No issues 1 1.8.0
1.7.2 Not scanned 1 1.7.2
1.3.3 โ€“ 1.7.1 No issues 4 >=1.3.3 <=1.7.1
1.3.2 Not scanned 1 1.3.2

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of @noble/hashes

VersionVerdictFilesScanned
1.8.0 No issues 81 Oct 4, 2026
1.7.1 No issues 75 Oct 4, 2026
1.7.0 No issues 72 Oct 4, 2026
1.4.0 No issues 72 Oct 4, 2026
1.3.3 No issues 72 Oct 4, 2026

Frequently asked questions

Is @noble/hashes safe to use?

Our AI source review of @noble/hashes@1.3.3 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does @noble/hashes contain malware?

No malware was identified in @noble/hashes@1.3.3 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @noble/hashes checked?

Togoder Security downloaded the published npm package and had an AI model read its 72 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @noble/hashes together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @noble/hashes@1.3.3, cost nothing.

Related security reports