# @noble/hashes@1.3.3 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T21:27:29.000Z
- Files reviewed: 72
- Findings: no findings
- Report: https://security.togoder.click/npm/@noble/hashes@1.3.3
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @noble/hashes@1.3.3 on Oct 4, 2026. An AI review of 72 source files produced no findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

No findings.

## Files reviewed

- `_assert.js` (safe): No malicious patterns detected
- `_blake2.js` (safe): No malicious patterns detected; the code is a standard BLAKE2 hash implementation with no network, filesystem, process, or dynamic execution activity.
- `_sha2.js` (safe): No malicious patterns detected; this is a standard SHA-2 cryptographic hash implementation with no network, filesystem, process, or dynamic code execution concerns.
- `_u64.js` (safe): No malicious patterns detected; the file implements standard 64-bit arithmetic helpers using BigInt and typed arrays without any network, filesystem, or process-related operations.
- `argon2.js` (safe): No malicious patterns detected; the code is a legitimate Argon2 password hashing implementation with no exfiltration, credential harvesting, obfuscation, or process execution.
- `blake2b.js` (safe): No malicious patterns detected in this BLAKE2b cryptographic hash implementation
- `blake2s.js` (safe): No malicious patterns detected; the file is a standard BLAKE2s cryptographic hash implementation with no network, filesystem, process, or dynamic execution behavior.
- `blake3.js` (safe): The code is a clean implementation of the BLAKE3 cryptographic hash function with no malicious patterns detected.
- `crypto.js` (safe): No malicious patterns detected; the file is a harmless utility that exports the global crypto object if available.
- `cryptoNode.js` (safe): No malicious patterns detected
- `eskdf.js` (safe): No malicious patterns detected; the code implements a cryptographic key derivation function using standard primitives (scrypt, pbkdf2, hkdf) with no network, filesystem, process, or dynamic code execution.
- `esm/_assert.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_blake2.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_sha2.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_u64.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/argon2.js` (safe): No malicious patterns detected; the code is a legitimate Argon2 password hashing implementation without any exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
- `esm/blake2b.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/blake2s.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/blake3.js` (safe): No malicious patterns detected; the code is a standard BLAKE3 cryptographic hash implementation with no network, filesystem, process execution, or obfuscation concerns.
- `esm/crypto.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/cryptoNode.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/eskdf.js` (safe): No malicious patterns detected; the code implements a standard, self-contained KDF library without network, filesystem, process, or dynamic execution behavior.
- `esm/hkdf.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/hmac.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/index.js` (safe): No malicious patterns detected; the file intentionally throws an error to prevent direct import, which is a legitimate design pattern for this package.
- `esm/pbkdf2.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/ripemd160.js` (safe): No malicious patterns detected; the code is a standard RIPEMD-160 hash implementation with no network, filesystem, process, or dynamic execution activity.
- `esm/scrypt.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/sha1.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/sha2.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/sha256.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/sha3-addons.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/sha3.js` (safe): No malicious patterns detected
- `esm/sha512.js` (safe): No malicious patterns detected
- `esm/utils.js` (safe): This is a legitimate utility module from the noble-hashes cryptographic library containing only standard hashing helpers with no malicious patterns.
- `hkdf.js` (safe): Cleared by Jev triage; no further analysis needed
- `hmac.js` (safe): No malicious patterns detected; the code is a clean implementation of HMAC (RFC 2104) using standard cryptographic primitives.
- `index.js` (safe): No malicious patterns detected; the file intentionally throws an error to prevent direct import, which is a legitimate design pattern for this package.
- `pbkdf2.js` (safe): This is a legitimate implementation of the PBKDF2 key derivation function from the @noble/hashes library, with no malicious patterns detected.
- `ripemd160.js` (safe): No malicious patterns detected; the code is a legitimate RIPEMD-160 hash implementation.
- `scrypt.js` (safe): This is a legitimate implementation of the Scrypt key derivation function with no malicious patterns detected.
- `sha1.js` (safe): No malicious patterns detected; the code is a standard implementation of the SHA-1 hashing algorithm.
- `sha2.js` (safe): No malicious patterns detected; this is a simple re-export module for SHA-2 hash functions.
- `sha256.js` (safe): No malicious patterns detected; this is a legitimate SHA-256/SHA-224 hash implementation with standard algorithm constants and no network, filesystem, process, or dynamic execution behavior.
- `sha3-addons.js` (safe): No malicious patterns detected; the code is a legitimate implementation of SHA-3 and NIST SP800-185 add-on cryptographic functions without any exfiltration, obfuscation, or backdoor logic.
- `sha3.js` (safe): No malicious patterns detected; the code is a standard SHA-3/Keccak cryptographic hash implementation with no network, filesystem, process, or dynamic execution behavior.
- `sha512.js` (safe): No malicious patterns detected; this is a legitimate SHA-512 cryptographic hash implementation with only internal module imports and no network, filesystem, or process operations.
- `src/_assert.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/_blake2.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/_sha2.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/_u64.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/argon2.ts` (safe): No malicious patterns detected; the code is a clean implementation of the Argon2 password hashing algorithm with no network, filesystem, or process manipulation.
- `src/blake2b.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/blake2s.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/blake3.ts` (safe): No malicious patterns detected; this is a legitimate BLAKE3 hash function implementation with no network, filesystem, process, or dynamic execution behavior.
- `src/crypto.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/cryptoNode.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/eskdf.ts` (safe): No malicious patterns detected; the code is a legitimate key derivation function implementation with no network, filesystem, process, or obfuscated code activity.
- `src/hkdf.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/hmac.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/index.ts` (safe): No malicious patterns detected
- `src/pbkdf2.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/ripemd160.ts` (safe): No malicious patterns detected; the file is a standard implementation of the RIPEMD-160 hash algorithm with no network, filesystem, credential, or dynamic code execution behavior.
- `src/scrypt.ts` (safe): No malicious patterns detected; the code is a legitimate Scrypt KDF implementation without data exfiltration, credential harvesting, obfuscation, or other security concerns.
- `src/sha1.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/sha2.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/sha256.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/sha3-addons.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/sha3.ts` (safe): No malicious patterns detected; the file is a legitimate SHA-3/Keccak implementation from the @noble/hashes library.
- `src/sha512.ts` (safe): No malicious patterns detected; this is a standard SHA-512/384/224/256 hash implementation from the audited @noble/hashes library.
- `src/utils.ts` (safe): No malicious patterns detected; this is a legitimate utility module from the noble-hashes cryptography library with standard byte/hex conversion, hashing helpers, and secure RNG usage.
- `utils.js` (safe): No malicious patterns detected; the code is a standard cryptographic utility library (noble-hashes) with no exfiltration, obfuscation, or suspicious behavior.

## Version ranges

None of the 5 scanned versions of @noble/hashes are flagged high or critical. The latest scanned version, 2.2.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 2.2.0 (`2.2.0`): not scanned
- 1.8.0 (`1.8.0`): clean
- 1.7.2 (`1.7.2`): not scanned
- 1.3.3 – 1.7.1 (`>=1.3.3 <=1.7.1`): clean
- 1.3.2 (`1.3.2`): not scanned

## Scanned versions

- [1.8.0](https://security.togoder.click/npm/@noble/hashes@1.8.0): safe, 2026-10-04T16:03:08.000Z
- [1.7.1](https://security.togoder.click/npm/@noble/hashes@1.7.1): safe, 2026-10-04T16:09:50.000Z
- [1.7.0](https://security.togoder.click/npm/@noble/hashes@1.7.0): safe, 2026-10-04T16:20:31.000Z
- [1.4.0](https://security.togoder.click/npm/@noble/hashes@1.4.0): safe, 2026-10-04T16:02:22.000Z
- [1.3.3](https://security.togoder.click/npm/@noble/hashes@1.3.3): safe, 2026-10-04T21:27:29.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
