Togoder security

npm package security report

@noble/hashes@1.4.0 security report

No malicious code found.

No issues Version 1.4.0 Files reviewed 72 Size 386.7 KB Scanned

Summary

Togoder Security scanned the npm package @noble/hashes@1.4.0 on Oct 4, 2026. An AI review of 72 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
1
low

Findings 1

low

Informational

NPS-D22ED16B3F41

The file contains only a throwing statement and an empty export. It intentionally prevents direct import and directs users to the README. No malicious patterns or dynamic behavior are present, and the thrown error message is static.

esm/index.js:1

Files reviewed

FileVerdictWhat the reviewer saw
_assert.js safe No malicious patterns detected; the file contains only standard assertion/validation utilities with no I/O, network, process execution, or obfuscation.
_blake.js safe The file implements the BLAKE2 hash algorithm with only standard cryptographic operations and no malicious patterns such as data exfiltration, environment harvesting, dynamic code execution, or process spawning.
_md.js safe This is a legitimate cryptographic hash implementation (Merkle-Damgard construction base class) with no malicious patterns detected.
_u64.js safe No malicious patterns detected; the file implements standard 64-bit arithmetic helpers using BigInt and typed arrays without any network, filesystem, or process-related operations.
argon2.js safe No malicious patterns detected; this is a legitimate Argon2 password hashing implementation with no network, filesystem, process, or dynamic code execution behavior.
blake2b.js safe This is a legitimate BLAKE2b cryptographic hash implementation with no malicious patterns detected.
blake2s.js safe This is a standard BLAKE2s cryptographic hash implementation with no malicious patterns, network activity, file system access, or dynamic code execution.
blake3.js safe No malicious patterns detected; the file is a legitimate BLAKE3 hash implementation with no network, file system, process spawning, or dynamic code execution.
crypto.js safe No malicious patterns detected; the file is a harmless utility that exports the global crypto object if available.
cryptoNode.js safe No malicious patterns detected
eskdf.js safe No malicious patterns detected; the code implements a cryptographic key derivation function using standard primitives (scrypt, pbkdf2, hkdf) with no network, filesystem, process, or dynamic code execution.
esm/_assert.js safe Cleared by Jev triage; no further analysis needed
esm/_blake.js safe Cleared by Jev triage; no further analysis needed
esm/_md.js safe Cleared by Jev triage; no further analysis needed
esm/_u64.js safe Cleared by Jev triage; no further analysis needed
esm/argon2.js safe No malicious patterns detected; this is a legitimate Argon2 key derivation function implementation with no data exfiltration, credential harvesting, obfuscation, network, filesystem, or process execution concerns.
esm/blake2b.js safe Cleared by Jev triage; no further analysis needed
esm/blake2s.js safe Cleared by Jev triage; no further analysis needed
esm/blake3.js safe This is a legitimate BLAKE3 cryptographic hash function implementation from the audited @noble/hashes library, with no malicious patterns detected.
esm/crypto.js safe Cleared by Jev triage; no further analysis needed
esm/cryptoNode.js safe Cleared by Jev triage; no further analysis needed
esm/eskdf.js safe No malicious patterns detected; the code implements a standard, self-contained KDF library without network, filesystem, process, or dynamic execution behavior.
esm/hkdf.js safe Cleared by Jev triage; no further analysis needed
esm/hmac.js safe Cleared by Jev triage; no further analysis needed
esm/index.js safe The entry-point stub is intentionally non-functional and contains no malicious code or risky patterns.
Show 47 more files
FileVerdictWhat the reviewer saw
esm/pbkdf2.js safe Cleared by Jev triage; no further analysis needed
esm/ripemd160.js safe This is a standard, clean implementation of the RIPEMD-160 hash algorithm with no malicious patterns, network calls, filesystem access, or dynamic code execution.
esm/scrypt.js safe Cleared by Jev triage; no further analysis needed
esm/sha1.js safe Cleared by Jev triage; no further analysis needed
esm/sha2.js safe Cleared by Jev triage; no further analysis needed
esm/sha256.js safe Cleared by Jev triage; no further analysis needed
esm/sha3-addons.js safe Cleared by Jev triage; no further analysis needed
esm/sha3.js safe No malicious patterns detected
esm/sha512.js safe No malicious patterns detected; the code is a standard SHA-512 hash implementation with no network, file system, or dynamic code execution concerns.
esm/utils.js safe This file contains standard cryptographic utility functions from the noble-hashes library with no evidence of malicious code, exfiltration, dynamic execution, or suspicious behavior.
hkdf.js safe Cleared by Jev triage; no further analysis needed
hmac.js safe No malicious patterns detected; the code is a clean implementation of HMAC (RFC 2104) using standard cryptographic primitives.
index.js safe No malicious patterns detected; the file intentionally throws an error to prevent direct import, which is a legitimate design pattern for this package.
pbkdf2.js safe This is a legitimate implementation of the PBKDF2 key derivation function from the @noble/hashes library, with no malicious patterns detected.
ripemd160.js safe This is a clean implementation of the RIPEMD-160 hash algorithm with no malicious patterns detected.
scrypt.js safe The scrypt.js file is a legitimate implementation of the Scrypt key derivation function from RFC 7914, with no malicious patterns, exfiltration, obfuscation, or unauthorized system interactions detected.
sha1.js safe No malicious patterns detected
sha2.js safe No malicious patterns detected; this is a simple re-export module for SHA-2 hash functions.
sha256.js safe No malicious patterns detected in the SHA-256/SHA-224 hashing implementation.
sha3-addons.js safe No malicious patterns detected; the file implements standard SHA-3 addon cryptographic primitives without network, filesystem, process, or dynamic code execution.
sha3.js safe No malicious patterns detected; the file is a legitimate SHA-3/Keccak cryptographic implementation with no exfiltration, credential access, dynamic code execution, or process spawning.
sha512.js safe No malicious patterns detected; this is a standard implementation of the SHA-512 family of hash functions.
src/_assert.ts safe Cleared by Jev triage; no further analysis needed
src/_blake.ts safe Cleared by Jev triage; no further analysis needed
src/_md.ts safe Cleared by Jev triage; no further analysis needed
src/_u64.ts safe Cleared by Jev triage; no further analysis needed
src/argon2.ts safe This is a legitimate implementation of the Argon2 password hashing algorithm (RFC 9106) with no malicious patterns, external network calls, file system access, or code execution detected.
src/blake2b.ts safe Cleared by Jev triage; no further analysis needed
src/blake2s.ts safe Cleared by Jev triage; no further analysis needed
src/blake3.ts safe Implementation of BLAKE3 cryptographic hash function with no malicious patterns, network activity, or process execution.
src/crypto.ts safe Cleared by Jev triage; no further analysis needed
src/cryptoNode.ts safe Cleared by Jev triage; no further analysis needed
src/eskdf.ts safe No malicious patterns detected; the code is a legitimate key derivation function implementation with no network, filesystem, process, or obfuscated code activity.
src/hkdf.ts safe Cleared by Jev triage; no further analysis needed
src/hmac.ts safe Cleared by Jev triage; no further analysis needed
src/index.ts safe No malicious patterns detected
src/pbkdf2.ts safe Cleared by Jev triage; no further analysis needed
src/ripemd160.ts safe This is a standard, well-formed RIPEMD-160 hash implementation with no malicious patterns detected.
src/scrypt.ts safe Cleared by Jev triage; no further analysis needed
src/sha1.ts safe Cleared by Jev triage; no further analysis needed
src/sha2.ts safe Cleared by Jev triage; no further analysis needed
src/sha256.ts safe Cleared by Jev triage; no further analysis needed
src/sha3-addons.ts safe Cleared by Jev triage; no further analysis needed
src/sha3.ts safe No malicious patterns detected; the code is a standard SHA-3/Keccak cryptographic implementation without any exfiltration, obfuscation, or backdoor behavior.
src/sha512.ts safe No malicious patterns detected in this standard SHA-512 hash implementation; it contains only cryptographic constants and hash computation logic with no network, file system, process, or dynamic execution activity.
src/utils.ts safe No malicious patterns detected; the code is a standard cryptographic utility library from the noble-hashes package with no exfiltration, credential harvesting, obfuscation, or backdoor behavior.
utils.js safe This is the legitimate noble-hashes utility module with standard hashing helpers and no malicious patterns detected.

Affected version ranges

None of the 5 scanned versions of @noble/hashes are flagged high or critical. The latest scanned version, 2.2.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

1.3.22.2.0
VersionsVerdictCountRangeTop findings
2.2.0 Not scanned 1 2.2.0
1.8.0 No issues 1 1.8.0
1.7.2 Not scanned 1 1.7.2
1.3.3 โ€“ 1.7.1 No issues 4 >=1.3.3 <=1.7.1
1.3.2 Not scanned 1 1.3.2

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of @noble/hashes

VersionVerdictFilesScanned
1.8.0 No issues 81 Oct 4, 2026
1.7.1 No issues 75 Oct 4, 2026
1.7.0 No issues 72 Oct 4, 2026
1.4.0 No issues 72 Oct 4, 2026
1.3.3 No issues 72 Oct 4, 2026

Frequently asked questions

Is @noble/hashes safe to use?

Our AI source review of @noble/hashes@1.4.0 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does @noble/hashes contain malware?

No malware was identified in @noble/hashes@1.4.0 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @noble/hashes checked?

Togoder Security downloaded the published npm package and had an AI model read its 72 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @noble/hashes together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @noble/hashes@1.4.0, cost nothing.

Related security reports