Togoder security

npm package security report

@noble/hashes@1.7.1 security report

No malicious code found.

No issues Version 1.7.1 Files reviewed 75 Size 489.7 KB Scanned

Summary

Togoder Security scanned the npm package @noble/hashes@1.7.1 on Oct 4, 2026. An AI review of 75 source files produced 3 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
3
low

Findings 3

low

Cryptographic primitive implementation

NPS-7C1475413D1B

This file implements the BLAKE/BLAKE2 hash family. The SIGMA permutation table and BLAKE class contain only standard cryptographic constants and hash compression logic, with no suspicious behavior. All operations are confined to in-memory buffer manipulation and standard Node.js module imports.

_blake.js
low

Import-time error throw

NPS-603E2D06ED6F

The root module intentionally throws an error on import to prevent direct root imports, directing users to import submodules instead. This is a deliberate design choice for the @noble/hashes library, not malicious behavior. No data exfiltration, obfuscation, network requests, file system manipulation, or process spawning is present.

esm/index.js:1
low

Cryptographic utility code

NPS-34257F6E7D78

This is a legitimate cryptographic utility library (noble-hashes) providing hex/byte conversion, byte swapping, and CSPRNG wrappers. No exfiltration, credential harvesting, obfuscation, dynamic code execution, or backdoor patterns found.

src/utils.ts

Files reviewed

FileVerdictWhat the reviewer saw
_assert.js safe Cleared by Jev triage; no further analysis needed
_blake.js safe Legitimate cryptographic hash implementation with no malicious patterns detected.
_md.js safe No malicious patterns detected; the code is a legitimate Merkle-Damgard hash utility implementation with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior.
_u64.js safe No malicious patterns detected; the file contains only pure 64-bit integer arithmetic helpers with no I/O, network, process, or dynamic code execution.
argon2.js safe No malicious patterns detected; the code is a straightforward implementation of the Argon2 password hashing algorithm with no network, filesystem, process, or obfuscated behavior.
blake1.js safe No malicious patterns detected
blake2b.js safe No malicious patterns detected; the file is a legitimate pure-JS implementation of the BLAKE2b hash function with no network, filesystem, process, credential, or dynamic-code-execution behavior.
blake2s.js safe The blake2s.js file implements the standard BLAKE2s cryptographic hash algorithm with no malicious patterns, network calls, obfuscation, or suspicious behavior detected.
blake3.js safe This is a legitimate BLAKE3 cryptographic hash implementation from the audited @noble/hashes library with no malicious patterns detected
crypto.js safe No malicious patterns detected; the file is a harmless utility that exports the global crypto object if available.
cryptoNode.js safe No malicious patterns detected; the code simply provides a WebCrypto alias using Node.js built-in crypto module.
eskdf.js safe No malicious patterns detected; the code is a legitimate cryptographic key derivation function implementation with no network, filesystem, process, or exfiltration activity.
esm/_assert.js safe Cleared by Jev triage; no further analysis needed
esm/_blake.js safe Cleared by Jev triage; no further analysis needed
esm/_md.js safe Cleared by Jev triage; no further analysis needed
esm/_u64.js safe Cleared by Jev triage; no further analysis needed
esm/argon2.js safe No malicious patterns detected; this is a legitimate Argon2 cryptographic implementation with only local cryptographic operations and input validation.
esm/blake1.js safe This is a legitimate implementation of the Blake1 hash algorithm with no malicious patterns, no network or filesystem access, and no dynamic code execution.
esm/blake2b.js safe Cleared by Jev triage; no further analysis needed
esm/blake2s.js safe Cleared by Jev triage; no further analysis needed
esm/blake3.js safe No malicious patterns detected; the code is a standard pure-JavaScript implementation of the BLAKE3 cryptographic hash function with no network, filesystem, process, or dynamic execution behavior.
esm/crypto.js safe Cleared by Jev triage; no further analysis needed
esm/cryptoNode.js safe Cleared by Jev triage; no further analysis needed
esm/eskdf.js safe No malicious patterns detected; the code implements a cryptographic key derivation function with proper input validation and no network, filesystem, or process manipulation.
esm/hkdf.js safe Cleared by Jev triage; no further analysis needed
Show 50 more files
FileVerdictWhat the reviewer saw
esm/hmac.js safe Cleared by Jev triage; no further analysis needed
esm/index.js safe The file is a safe root module guard for @noble/hashes that throws an error to enforce submodule imports, with no malicious patterns detected.
esm/pbkdf2.js safe Cleared by Jev triage; no further analysis needed
esm/ripemd160.js safe No malicious patterns detected; the file is a standard RIPEMD-160 hash implementation with no external communication, credential access, dynamic execution, or lifecycle hooks.
esm/scrypt.js safe Cleared by Jev triage; no further analysis needed
esm/sha1.js safe Cleared by Jev triage; no further analysis needed
esm/sha2.js safe Cleared by Jev triage; no further analysis needed
esm/sha256.js safe Cleared by Jev triage; no further analysis needed
esm/sha3-addons.js safe Cleared by Jev triage; no further analysis needed
esm/sha3.js safe No malicious patterns detected; the code is a standard SHA-3/Keccak hash implementation with no network, filesystem, process, or dynamic execution activity.
esm/sha512.js safe No malicious patterns detected; this is a standard SHA-512/384 hash implementation with only cryptographic arithmetic and no network, filesystem, process, or dynamic execution behavior.
esm/utils.js safe No malicious patterns detected; the code is a standard cryptographic utility library from noble-hashes implementing hex/byte conversion, byte swapping, and CSPRNG access with no exfiltration, obfuscation, or dynamic execution.
hkdf.js safe Cleared by Jev triage; no further analysis needed
hmac.js safe No malicious patterns detected; the code implements standard HMAC (RFC 2104) using the @noble/hashes library with no external calls, obfuscation, or suspicious behavior.
index.js safe No malicious patterns detected; the file only throws an informative error instructing users to import submodules.
pbkdf2.js safe No malicious patterns detected; this is a standard, well-formed implementation of PBKDF2-HMAC from the audited @noble/hashes library.
ripemd160.js safe This is a standard, well-known RIPEMD-160 hash implementation with no malicious patterns detected.
scrypt.js safe This is a legitimate, well-known scrypt KDF implementation from the audited @noble/hashes library with no malicious patterns detected.
sha1.js safe No malicious patterns detected
sha2.js safe No malicious patterns detected
sha256.js safe No malicious patterns detected; this is a standard implementation of SHA-256/SHA-224 hashing algorithms.
sha3-addons.js safe Cryptographic hash function implementation with no malicious patterns detected
sha3.js safe No malicious patterns detected; the file implements standard SHA-3/Keccak cryptographic hashing without any suspicious behavior.
sha512.js safe The code is a clean, standard implementation of the SHA-2 family of hash functions (SHA-512, SHA-384, SHA-512/224, SHA-512/256) with no malicious patterns, external calls, or obfuscation.
src/_assert.ts safe Cleared by Jev triage; no further analysis needed
src/_blake.ts safe Cleared by Jev triage; no further analysis needed
src/_md.ts safe Cleared by Jev triage; no further analysis needed
src/_u64.ts safe Cleared by Jev triage; no further analysis needed
src/argon2.ts safe No malicious patterns detected; the code is a legitimate Argon2 KDF implementation with no exfiltration, obfuscation, dynamic execution, or network activity.
src/blake1.ts safe No malicious patterns detected; the file is a standard implementation of the Blake1 hash family with no network, filesystem, process, or dynamic code execution activity.
src/blake2b.ts safe Cleared by Jev triage; no further analysis needed
src/blake2s.ts safe Cleared by Jev triage; no further analysis needed
src/blake3.ts safe No malicious patterns detected; this is a standard BLAKE3 cryptographic hash implementation using only assertion utilities and cryptographic primitives from the same package.
src/crypto.ts safe Cleared by Jev triage; no further analysis needed
src/cryptoNode.ts safe Cleared by Jev triage; no further analysis needed
src/eskdf.ts safe No malicious patterns detected; the code is a legitimate cryptographic key derivation implementation with no network, filesystem, process execution, or obfuscation concerns.
src/hkdf.ts safe Cleared by Jev triage; no further analysis needed
src/hmac.ts safe Cleared by Jev triage; no further analysis needed
src/index.ts safe No malicious patterns detected; the file only throws an error to enforce submodule imports, which is a legitimate design choice for the @noble/hashes package.
src/pbkdf2.ts safe Cleared by Jev triage; no further analysis needed
src/ripemd160.ts safe No malicious patterns detected; this is a standard RIPEMD-160 hash implementation with no network, filesystem, process, or dynamic code execution activity.
src/scrypt.ts safe No malicious patterns detected in this standard Scrypt KDF implementation.
src/sha1.ts safe Cleared by Jev triage; no further analysis needed
src/sha2.ts safe Cleared by Jev triage; no further analysis needed
src/sha256.ts safe Cleared by Jev triage; no further analysis needed
src/sha3-addons.ts safe Cleared by Jev triage; no further analysis needed
src/sha3.ts safe No malicious patterns detected; the code is a standard cryptographic implementation of SHA3/Keccak with no signs of exfiltration, credential harvesting, obfuscation, or other security concerns.
src/sha512.ts safe No malicious patterns detected
src/utils.ts safe No malicious patterns detected; the code is a standard cryptographic utility module with no security concerns.
utils.js safe No malicious patterns detected; the file contains standard cryptographic utility functions from the noble-hashes library with no exfiltration, credential harvesting, obfuscation, or backdoor behavior.

Affected version ranges

None of the 5 scanned versions of @noble/hashes are flagged high or critical. The latest scanned version, 2.2.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

1.3.22.2.0
VersionsVerdictCountRangeTop findings
2.2.0 Not scanned 1 2.2.0
1.8.0 No issues 1 1.8.0
1.7.2 Not scanned 1 1.7.2
1.3.3 โ€“ 1.7.1 No issues 4 >=1.3.3 <=1.7.1
1.3.2 Not scanned 1 1.3.2

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of @noble/hashes

VersionVerdictFilesScanned
1.8.0 No issues 81 Oct 4, 2026
1.7.1 No issues 75 Oct 4, 2026
1.7.0 No issues 72 Oct 4, 2026
1.4.0 No issues 72 Oct 4, 2026
1.3.3 No issues 72 Oct 4, 2026

Frequently asked questions

Is @noble/hashes safe to use?

Our AI source review of @noble/hashes@1.7.1 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does @noble/hashes contain malware?

No malware was identified in @noble/hashes@1.7.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was @noble/hashes checked?

Togoder Security downloaded the published npm package and had an AI model read its 75 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan @noble/hashes together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @noble/hashes@1.7.1, cost nothing.

Related security reports