# @noble/hashes@1.7.0 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:20:31.000Z
- Files reviewed: 72
- Findings: 1 low severity finding
- Report: https://security.togoder.click/npm/@noble/hashes@1.7.0
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @noble/hashes@1.7.0 on Oct 4, 2026. An AI review of 72 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] legitimate_crypto_utility

Finding ID: `NPS-18D171915ECA`

File: `esm/utils.js`

This is the noble-hashes utility module. All functions (hex/byte conversion, byte swapping, randomBytes) are standard cryptographic helpers. randomBytes uses crypto.getRandomValues or node crypto.randomBytes, not exfiltration. No network, filesystem, process spawning, eval, or dynamic import abuse present.

## Files reviewed

- `_assert.js` (safe): Cleared by Jev triage; no further analysis needed
- `_blake.js` (safe): This is a standard implementation of the BLAKE hash function from the audited @noble/hashes library, with no malicious patterns detected.
- `_md.js` (safe): Cleared by Jev triage; no further analysis needed
- `_u64.js` (safe): No malicious patterns detected; the file contains only pure 64-bit integer arithmetic helper functions with no network, filesystem, process, or dynamic code execution logic.
- `argon2.js` (safe): No malicious patterns detected
- `blake2b.js` (safe): No malicious patterns detected
- `blake2s.js` (safe): No malicious patterns detected; the code is a standard implementation of the BLAKE2s cryptographic hash function.
- `blake3.js` (safe): This is a clean implementation of the BLAKE3 cryptographic hash function with no malicious patterns or security concerns detected.
- `crypto.js` (safe): No malicious patterns detected; the file is a harmless utility that exports the global crypto object if available.
- `cryptoNode.js` (safe): No malicious patterns detected
- `eskdf.js` (safe): No malicious patterns detected; the code is a legitimate exported key derivation function implementation with only standard cryptographic imports and no exfiltration, dynamic code execution, or suspicious network activity.
- `esm/_assert.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_blake.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_md.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_u64.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/argon2.js` (safe): No malicious patterns detected; this is a legitimate Argon2 password hashing implementation from the @noble/hashes library with no network, filesystem, process, or dynamic code execution activity.
- `esm/blake2b.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/blake2s.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/blake3.js` (safe): The file is a legitimate BLAKE3 cryptographic hash implementation with no malicious patterns such as data exfiltration, credential harvesting, obfuscated payloads, or network/process activity.
- `esm/crypto.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/cryptoNode.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/eskdf.js` (safe): No malicious patterns detected; the code is a legitimate cryptographic key derivation utility using standard primitives (scrypt, PBKDF2, HKDF) without any data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
- `esm/hkdf.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/hmac.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/index.js` (safe): No malicious patterns detected
- `esm/pbkdf2.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/ripemd160.js` (safe): No malicious patterns detected; the code is a standard RIPEMD-160 hash implementation with no exfiltration, obfuscation, or system interaction.
- `esm/scrypt.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/sha1.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/sha2.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/sha256.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/sha3-addons.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/sha3.js` (safe): This is a legitimate SHA-3/Keccak cryptographic hash implementation with no malicious patterns, network access, file system manipulation, or code execution.
- `esm/sha512.js` (safe): This is a legitimate implementation of the SHA-2 family of hash functions (SHA-512, SHA-384, SHA-512/224, SHA-512/256) with no malicious code, network activity, or suspicious patterns.
- `esm/utils.js` (safe): No malicious patterns detected; code is a standard cryptographic utility library.
- `hkdf.js` (safe): Cleared by Jev triage; no further analysis needed
- `hmac.js` (safe): This is a standard HMAC implementation from the noble-hashes library with no malicious patterns, network access, file system manipulation, or obfuscation.
- `index.js` (safe): No malicious patterns detected; the file only throws an error directing users to import submodules.
- `pbkdf2.js` (safe): This is a legitimate PBKDF2-HMAC key derivation implementation from the well-known @noble/hashes library with no malicious patterns detected.
- `ripemd160.js` (safe): No malicious patterns detected
- `scrypt.js` (safe): No malicious patterns detected; the code is a standard RFC 7914 scrypt implementation with no network, filesystem, or process manipulation.
- `sha1.js` (safe): This is a standard, well-implemented SHA-1 hash function with no malicious patterns, external calls, or suspicious behavior.
- `sha2.js` (safe): No malicious patterns detected; the file is a benign re-export module for SHA-2 hash functions.
- `sha256.js` (safe): No malicious patterns detected
- `sha3-addons.js` (safe): This is a legitimate cryptographic implementation of SHA3 addons (cSHAKE, KMAC, TupleHash, ParallelHash, KangarooTwelve, KeccakPRG) with no malicious patterns, no network calls, no file system access, and no dynamic code execution.
- `sha3.js` (safe): This is a legitimate implementation of SHA-3 and Keccak hash functions with no malicious patterns detected.
- `sha512.js` (safe): No malicious patterns detected; the file is a standard cryptographic SHA-512/384/512-224/512-256 implementation with no network, filesystem, process, or dynamic execution behavior.
- `src/_assert.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/_blake.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/_md.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/_u64.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/argon2.ts` (safe): No malicious patterns detected; the code is a standard Argon2 password-hashing implementation with no network, filesystem, process, or dynamic-execution activity.
- `src/blake2b.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/blake2s.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/blake3.ts` (safe): No malicious patterns detected; the code is a legitimate BLAKE3 cryptographic hash implementation with no network, filesystem, process, or dynamic execution concerns.
- `src/crypto.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/cryptoNode.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/eskdf.ts` (safe): No malicious patterns detected; the file implements a standard ESKDF utility with no data exfiltration, credential harvesting, obfuscation, mining, backdoors, lifecycle hooks, suspicious network calls, filesystem manipulation, or process spawning.
- `src/hkdf.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/hmac.ts` (safe): No malicious patterns detected; this is a standard HMAC implementation from @noble/hashes with no network, filesystem, process, or obfuscated code.
- `src/index.ts` (safe): No malicious patterns detected
- `src/pbkdf2.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/ripemd160.ts` (safe): The code is a standard, self-contained implementation of the RIPEMD-160 hash algorithm with no malicious patterns, network activity, file system access, or dynamic code execution.
- `src/scrypt.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/sha1.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/sha2.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/sha256.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/sha3-addons.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/sha3.ts` (safe): No malicious patterns detected; the file is a standard, well-known implementation of SHA-3/Keccak hashing from the audited @noble/hashes library.
- `src/sha512.ts` (safe): This is a clean, standard implementation of the SHA-512/384/512-224/512-256 hash algorithms with no malicious patterns, network calls, credential access, or dynamic code execution.
- `src/utils.ts` (safe): Cleared by Jev triage; no further analysis needed
- `utils.js` (safe): No malicious patterns detected; the code is a legitimate cryptographic utility library (noble-hashes) with standard hex/byte conversion, hashing wrappers, and secure random byte generation.

## Version ranges

None of the 5 scanned versions of @noble/hashes are flagged high or critical. The latest scanned version, 2.2.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 2.2.0 (`2.2.0`): not scanned
- 1.8.0 (`1.8.0`): clean
- 1.7.2 (`1.7.2`): not scanned
- 1.3.3 – 1.7.1 (`>=1.3.3 <=1.7.1`): clean
- 1.3.2 (`1.3.2`): not scanned

## Scanned versions

- [1.8.0](https://security.togoder.click/npm/@noble/hashes@1.8.0): safe, 2026-10-04T16:03:08.000Z
- [1.7.1](https://security.togoder.click/npm/@noble/hashes@1.7.1): safe, 2026-10-04T16:09:50.000Z
- [1.7.0](https://security.togoder.click/npm/@noble/hashes@1.7.0): safe, 2026-10-04T16:20:31.000Z
- [1.4.0](https://security.togoder.click/npm/@noble/hashes@1.4.0): safe, 2026-10-04T16:02:22.000Z
- [1.3.3](https://security.togoder.click/npm/@noble/hashes@1.3.3): safe, 2026-10-04T21:27:29.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
