Summary
Togoder Security scanned the npm package @noble/hashes@1.7.1 on Oct 4, 2026. An AI review of 75 source files produced 3 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings 3
Cryptographic primitive implementation
NPS-7C1475413D1B
This file implements the BLAKE/BLAKE2 hash family. The SIGMA permutation table and BLAKE class contain only standard cryptographic constants and hash compression logic, with no suspicious behavior. All operations are confined to in-memory buffer manipulation and standard Node.js module imports.
Import-time error throw
NPS-603E2D06ED6F
The root module intentionally throws an error on import to prevent direct root imports, directing users to import submodules instead. This is a deliberate design choice for the @noble/hashes library, not malicious behavior. No data exfiltration, obfuscation, network requests, file system manipulation, or process spawning is present.
Cryptographic utility code
NPS-34257F6E7D78
This is a legitimate cryptographic utility library (noble-hashes) providing hex/byte conversion, byte swapping, and CSPRNG wrappers. No exfiltration, credential harvesting, obfuscation, dynamic code execution, or backdoor patterns found.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| _assert.js | safe | Cleared by Jev triage; no further analysis needed |
| _blake.js | safe | Legitimate cryptographic hash implementation with no malicious patterns detected. |
| _md.js | safe | No malicious patterns detected; the code is a legitimate Merkle-Damgard hash utility implementation with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior. |
| _u64.js | safe | No malicious patterns detected; the file contains only pure 64-bit integer arithmetic helpers with no I/O, network, process, or dynamic code execution. |
| argon2.js | safe | No malicious patterns detected; the code is a straightforward implementation of the Argon2 password hashing algorithm with no network, filesystem, process, or obfuscated behavior. |
| blake1.js | safe | No malicious patterns detected |
| blake2b.js | safe | No malicious patterns detected; the file is a legitimate pure-JS implementation of the BLAKE2b hash function with no network, filesystem, process, credential, or dynamic-code-execution behavior. |
| blake2s.js | safe | The blake2s.js file implements the standard BLAKE2s cryptographic hash algorithm with no malicious patterns, network calls, obfuscation, or suspicious behavior detected. |
| blake3.js | safe | This is a legitimate BLAKE3 cryptographic hash implementation from the audited @noble/hashes library with no malicious patterns detected |
| crypto.js | safe | No malicious patterns detected; the file is a harmless utility that exports the global crypto object if available. |
| cryptoNode.js | safe | No malicious patterns detected; the code simply provides a WebCrypto alias using Node.js built-in crypto module. |
| eskdf.js | safe | No malicious patterns detected; the code is a legitimate cryptographic key derivation function implementation with no network, filesystem, process, or exfiltration activity. |
| esm/_assert.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/_blake.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/_md.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/_u64.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/argon2.js | safe | No malicious patterns detected; this is a legitimate Argon2 cryptographic implementation with only local cryptographic operations and input validation. |
| esm/blake1.js | safe | This is a legitimate implementation of the Blake1 hash algorithm with no malicious patterns, no network or filesystem access, and no dynamic code execution. |
| esm/blake2b.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/blake2s.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/blake3.js | safe | No malicious patterns detected; the code is a standard pure-JavaScript implementation of the BLAKE3 cryptographic hash function with no network, filesystem, process, or dynamic execution behavior. |
| esm/crypto.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/cryptoNode.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/eskdf.js | safe | No malicious patterns detected; the code implements a cryptographic key derivation function with proper input validation and no network, filesystem, or process manipulation. |
| esm/hkdf.js | safe | Cleared by Jev triage; no further analysis needed |
Show 50 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| esm/hmac.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/index.js | safe | The file is a safe root module guard for @noble/hashes that throws an error to enforce submodule imports, with no malicious patterns detected. |
| esm/pbkdf2.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/ripemd160.js | safe | No malicious patterns detected; the file is a standard RIPEMD-160 hash implementation with no external communication, credential access, dynamic execution, or lifecycle hooks. |
| esm/scrypt.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/sha1.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/sha2.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/sha256.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/sha3-addons.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/sha3.js | safe | No malicious patterns detected; the code is a standard SHA-3/Keccak hash implementation with no network, filesystem, process, or dynamic execution activity. |
| esm/sha512.js | safe | No malicious patterns detected; this is a standard SHA-512/384 hash implementation with only cryptographic arithmetic and no network, filesystem, process, or dynamic execution behavior. |
| esm/utils.js | safe | No malicious patterns detected; the code is a standard cryptographic utility library from noble-hashes implementing hex/byte conversion, byte swapping, and CSPRNG access with no exfiltration, obfuscation, or dynamic execution. |
| hkdf.js | safe | Cleared by Jev triage; no further analysis needed |
| hmac.js | safe | No malicious patterns detected; the code implements standard HMAC (RFC 2104) using the @noble/hashes library with no external calls, obfuscation, or suspicious behavior. |
| index.js | safe | No malicious patterns detected; the file only throws an informative error instructing users to import submodules. |
| pbkdf2.js | safe | No malicious patterns detected; this is a standard, well-formed implementation of PBKDF2-HMAC from the audited @noble/hashes library. |
| ripemd160.js | safe | This is a standard, well-known RIPEMD-160 hash implementation with no malicious patterns detected. |
| scrypt.js | safe | This is a legitimate, well-known scrypt KDF implementation from the audited @noble/hashes library with no malicious patterns detected. |
| sha1.js | safe | No malicious patterns detected |
| sha2.js | safe | No malicious patterns detected |
| sha256.js | safe | No malicious patterns detected; this is a standard implementation of SHA-256/SHA-224 hashing algorithms. |
| sha3-addons.js | safe | Cryptographic hash function implementation with no malicious patterns detected |
| sha3.js | safe | No malicious patterns detected; the file implements standard SHA-3/Keccak cryptographic hashing without any suspicious behavior. |
| sha512.js | safe | The code is a clean, standard implementation of the SHA-2 family of hash functions (SHA-512, SHA-384, SHA-512/224, SHA-512/256) with no malicious patterns, external calls, or obfuscation. |
| src/_assert.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/_blake.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/_md.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/_u64.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/argon2.ts | safe | No malicious patterns detected; the code is a legitimate Argon2 KDF implementation with no exfiltration, obfuscation, dynamic execution, or network activity. |
| src/blake1.ts | safe | No malicious patterns detected; the file is a standard implementation of the Blake1 hash family with no network, filesystem, process, or dynamic code execution activity. |
| src/blake2b.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/blake2s.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/blake3.ts | safe | No malicious patterns detected; this is a standard BLAKE3 cryptographic hash implementation using only assertion utilities and cryptographic primitives from the same package. |
| src/crypto.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/cryptoNode.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/eskdf.ts | safe | No malicious patterns detected; the code is a legitimate cryptographic key derivation implementation with no network, filesystem, process execution, or obfuscation concerns. |
| src/hkdf.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/hmac.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/index.ts | safe | No malicious patterns detected; the file only throws an error to enforce submodule imports, which is a legitimate design choice for the @noble/hashes package. |
| src/pbkdf2.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/ripemd160.ts | safe | No malicious patterns detected; this is a standard RIPEMD-160 hash implementation with no network, filesystem, process, or dynamic code execution activity. |
| src/scrypt.ts | safe | No malicious patterns detected in this standard Scrypt KDF implementation. |
| src/sha1.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/sha2.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/sha256.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/sha3-addons.ts | safe | Cleared by Jev triage; no further analysis needed |
| src/sha3.ts | safe | No malicious patterns detected; the code is a standard cryptographic implementation of SHA3/Keccak with no signs of exfiltration, credential harvesting, obfuscation, or other security concerns. |
| src/sha512.ts | safe | No malicious patterns detected |
| src/utils.ts | safe | No malicious patterns detected; the code is a standard cryptographic utility module with no security concerns. |
| utils.js | safe | No malicious patterns detected; the file contains standard cryptographic utility functions from the noble-hashes library with no exfiltration, credential harvesting, obfuscation, or backdoor behavior. |
Affected version ranges
None of the 5 scanned versions of @noble/hashes are flagged high or critical. The latest scanned version, 2.2.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 2.2.0 | Not scanned | 1 | 2.2.0 | |
| 1.8.0 | No issues | 1 | 1.8.0 | |
| 1.7.2 | Not scanned | 1 | 1.7.2 | |
| 1.3.3 โ 1.7.1 | No issues | 4 | >=1.3.3 <=1.7.1 | |
| 1.3.2 | Not scanned | 1 | 1.3.2 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of @noble/hashes
Frequently asked questions
Is @noble/hashes safe to use?
Our AI source review of @noble/hashes@1.7.1 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does @noble/hashes contain malware?
No malware was identified in @noble/hashes@1.7.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @noble/hashes checked?
Togoder Security downloaded the published npm package and had an AI model read its 75 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @noble/hashes together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @noble/hashes@1.7.1, cost nothing.