# @noble/hashes@1.4.0 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:02:22.000Z
- Files reviewed: 72
- Findings: 1 low severity finding
- Report: https://security.togoder.click/npm/@noble/hashes@1.4.0
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @noble/hashes@1.4.0 on Oct 4, 2026. An AI review of 72 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] Informational

Finding ID: `NPS-D22ED16B3F41`

File: `esm/index.js:1`

The file contains only a throwing statement and an empty export. It intentionally prevents direct import and directs users to the README. No malicious patterns or dynamic behavior are present, and the thrown error message is static.

## Files reviewed

- `_assert.js` (safe): No malicious patterns detected; the file contains only standard assertion/validation utilities with no I/O, network, process execution, or obfuscation.
- `_blake.js` (safe): The file implements the BLAKE2 hash algorithm with only standard cryptographic operations and no malicious patterns such as data exfiltration, environment harvesting, dynamic code execution, or process spawning.
- `_md.js` (safe): This is a legitimate cryptographic hash implementation (Merkle-Damgard construction base class) with no malicious patterns detected.
- `_u64.js` (safe): No malicious patterns detected; the file implements standard 64-bit arithmetic helpers using BigInt and typed arrays without any network, filesystem, or process-related operations.
- `argon2.js` (safe): No malicious patterns detected; this is a legitimate Argon2 password hashing implementation with no network, filesystem, process, or dynamic code execution behavior.
- `blake2b.js` (safe): This is a legitimate BLAKE2b cryptographic hash implementation with no malicious patterns detected.
- `blake2s.js` (safe): This is a standard BLAKE2s cryptographic hash implementation with no malicious patterns, network activity, file system access, or dynamic code execution.
- `blake3.js` (safe): No malicious patterns detected; the file is a legitimate BLAKE3 hash implementation with no network, file system, process spawning, or dynamic code execution.
- `crypto.js` (safe): No malicious patterns detected; the file is a harmless utility that exports the global crypto object if available.
- `cryptoNode.js` (safe): No malicious patterns detected
- `eskdf.js` (safe): No malicious patterns detected; the code implements a cryptographic key derivation function using standard primitives (scrypt, pbkdf2, hkdf) with no network, filesystem, process, or dynamic code execution.
- `esm/_assert.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_blake.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_md.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_u64.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/argon2.js` (safe): No malicious patterns detected; this is a legitimate Argon2 key derivation function implementation with no data exfiltration, credential harvesting, obfuscation, network, filesystem, or process execution concerns.
- `esm/blake2b.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/blake2s.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/blake3.js` (safe): This is a legitimate BLAKE3 cryptographic hash function implementation from the audited @noble/hashes library, with no malicious patterns detected.
- `esm/crypto.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/cryptoNode.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/eskdf.js` (safe): No malicious patterns detected; the code implements a standard, self-contained KDF library without network, filesystem, process, or dynamic execution behavior.
- `esm/hkdf.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/hmac.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/index.js` (safe): The entry-point stub is intentionally non-functional and contains no malicious code or risky patterns.
- `esm/pbkdf2.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/ripemd160.js` (safe): This is a standard, clean implementation of the RIPEMD-160 hash algorithm with no malicious patterns, network calls, filesystem access, or dynamic code execution.
- `esm/scrypt.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/sha1.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/sha2.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/sha256.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/sha3-addons.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/sha3.js` (safe): No malicious patterns detected
- `esm/sha512.js` (safe): No malicious patterns detected; the code is a standard SHA-512 hash implementation with no network, file system, or dynamic code execution concerns.
- `esm/utils.js` (safe): This file contains standard cryptographic utility functions from the noble-hashes library with no evidence of malicious code, exfiltration, dynamic execution, or suspicious behavior.
- `hkdf.js` (safe): Cleared by Jev triage; no further analysis needed
- `hmac.js` (safe): No malicious patterns detected; the code is a clean implementation of HMAC (RFC 2104) using standard cryptographic primitives.
- `index.js` (safe): No malicious patterns detected; the file intentionally throws an error to prevent direct import, which is a legitimate design pattern for this package.
- `pbkdf2.js` (safe): This is a legitimate implementation of the PBKDF2 key derivation function from the @noble/hashes library, with no malicious patterns detected.
- `ripemd160.js` (safe): This is a clean implementation of the RIPEMD-160 hash algorithm with no malicious patterns detected.
- `scrypt.js` (safe): The scrypt.js file is a legitimate implementation of the Scrypt key derivation function from RFC 7914, with no malicious patterns, exfiltration, obfuscation, or unauthorized system interactions detected.
- `sha1.js` (safe): No malicious patterns detected
- `sha2.js` (safe): No malicious patterns detected; this is a simple re-export module for SHA-2 hash functions.
- `sha256.js` (safe): No malicious patterns detected in the SHA-256/SHA-224 hashing implementation.
- `sha3-addons.js` (safe): No malicious patterns detected; the file implements standard SHA-3 addon cryptographic primitives without network, filesystem, process, or dynamic code execution.
- `sha3.js` (safe): No malicious patterns detected; the file is a legitimate SHA-3/Keccak cryptographic implementation with no exfiltration, credential access, dynamic code execution, or process spawning.
- `sha512.js` (safe): No malicious patterns detected; this is a standard implementation of the SHA-512 family of hash functions.
- `src/_assert.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/_blake.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/_md.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/_u64.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/argon2.ts` (safe): This is a legitimate implementation of the Argon2 password hashing algorithm (RFC 9106) with no malicious patterns, external network calls, file system access, or code execution detected.
- `src/blake2b.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/blake2s.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/blake3.ts` (safe): Implementation of BLAKE3 cryptographic hash function with no malicious patterns, network activity, or process execution.
- `src/crypto.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/cryptoNode.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/eskdf.ts` (safe): No malicious patterns detected; the code is a legitimate key derivation function implementation with no network, filesystem, process, or obfuscated code activity.
- `src/hkdf.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/hmac.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/index.ts` (safe): No malicious patterns detected
- `src/pbkdf2.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/ripemd160.ts` (safe): This is a standard, well-formed RIPEMD-160 hash implementation with no malicious patterns detected.
- `src/scrypt.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/sha1.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/sha2.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/sha256.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/sha3-addons.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/sha3.ts` (safe): No malicious patterns detected; the code is a standard SHA-3/Keccak cryptographic implementation without any exfiltration, obfuscation, or backdoor behavior.
- `src/sha512.ts` (safe): No malicious patterns detected in this standard SHA-512 hash implementation; it contains only cryptographic constants and hash computation logic with no network, file system, process, or dynamic execution activity.
- `src/utils.ts` (safe): No malicious patterns detected; the code is a standard cryptographic utility library from the noble-hashes package with no exfiltration, credential harvesting, obfuscation, or backdoor behavior.
- `utils.js` (safe): This is the legitimate noble-hashes utility module with standard hashing helpers and no malicious patterns detected.

## Version ranges

None of the 5 scanned versions of @noble/hashes are flagged high or critical. The latest scanned version, 2.2.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 2.2.0 (`2.2.0`): not scanned
- 1.8.0 (`1.8.0`): clean
- 1.7.2 (`1.7.2`): not scanned
- 1.3.3 – 1.7.1 (`>=1.3.3 <=1.7.1`): clean
- 1.3.2 (`1.3.2`): not scanned

## Scanned versions

- [1.8.0](https://security.togoder.click/npm/@noble/hashes@1.8.0): safe, 2026-10-04T16:03:08.000Z
- [1.7.1](https://security.togoder.click/npm/@noble/hashes@1.7.1): safe, 2026-10-04T16:09:50.000Z
- [1.7.0](https://security.togoder.click/npm/@noble/hashes@1.7.0): safe, 2026-10-04T16:20:31.000Z
- [1.4.0](https://security.togoder.click/npm/@noble/hashes@1.4.0): safe, 2026-10-04T16:02:22.000Z
- [1.3.3](https://security.togoder.click/npm/@noble/hashes@1.3.3): safe, 2026-10-04T21:27:29.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
