# @noble/hashes@1.7.1 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:09:50.000Z
- Files reviewed: 75
- Findings: 3 low severity findings
- Report: https://security.togoder.click/npm/@noble/hashes@1.7.1
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @noble/hashes@1.7.1 on Oct 4, 2026. An AI review of 75 source files produced 3 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] Cryptographic primitive implementation

Finding ID: `NPS-7C1475413D1B`

File: `_blake.js`

This file implements the BLAKE/BLAKE2 hash family. The SIGMA permutation table and BLAKE class contain only standard cryptographic constants and hash compression logic, with no suspicious behavior. All operations are confined to in-memory buffer manipulation and standard Node.js module imports.

### [low] Import-time error throw

Finding ID: `NPS-603E2D06ED6F`

File: `esm/index.js:1`

The root module intentionally throws an error on import to prevent direct root imports, directing users to import submodules instead. This is a deliberate design choice for the @noble/hashes library, not malicious behavior. No data exfiltration, obfuscation, network requests, file system manipulation, or process spawning is present.

### [low] Cryptographic utility code

Finding ID: `NPS-34257F6E7D78`

File: `src/utils.ts`

This is a legitimate cryptographic utility library (noble-hashes) providing hex/byte conversion, byte swapping, and CSPRNG wrappers. No exfiltration, credential harvesting, obfuscation, dynamic code execution, or backdoor patterns found.

## Files reviewed

- `_assert.js` (safe): Cleared by Jev triage; no further analysis needed
- `_blake.js` (safe): Legitimate cryptographic hash implementation with no malicious patterns detected.
- `_md.js` (safe): No malicious patterns detected; the code is a legitimate Merkle-Damgard hash utility implementation with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior.
- `_u64.js` (safe): No malicious patterns detected; the file contains only pure 64-bit integer arithmetic helpers with no I/O, network, process, or dynamic code execution.
- `argon2.js` (safe): No malicious patterns detected; the code is a straightforward implementation of the Argon2 password hashing algorithm with no network, filesystem, process, or obfuscated behavior.
- `blake1.js` (safe): No malicious patterns detected
- `blake2b.js` (safe): No malicious patterns detected; the file is a legitimate pure-JS implementation of the BLAKE2b hash function with no network, filesystem, process, credential, or dynamic-code-execution behavior.
- `blake2s.js` (safe): The blake2s.js file implements the standard BLAKE2s cryptographic hash algorithm with no malicious patterns, network calls, obfuscation, or suspicious behavior detected.
- `blake3.js` (safe): This is a legitimate BLAKE3 cryptographic hash implementation from the audited @noble/hashes library with no malicious patterns detected
- `crypto.js` (safe): No malicious patterns detected; the file is a harmless utility that exports the global crypto object if available.
- `cryptoNode.js` (safe): No malicious patterns detected; the code simply provides a WebCrypto alias using Node.js built-in crypto module.
- `eskdf.js` (safe): No malicious patterns detected; the code is a legitimate cryptographic key derivation function implementation with no network, filesystem, process, or exfiltration activity.
- `esm/_assert.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_blake.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_md.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/_u64.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/argon2.js` (safe): No malicious patterns detected; this is a legitimate Argon2 cryptographic implementation with only local cryptographic operations and input validation.
- `esm/blake1.js` (safe): This is a legitimate implementation of the Blake1 hash algorithm with no malicious patterns, no network or filesystem access, and no dynamic code execution.
- `esm/blake2b.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/blake2s.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/blake3.js` (safe): No malicious patterns detected; the code is a standard pure-JavaScript implementation of the BLAKE3 cryptographic hash function with no network, filesystem, process, or dynamic execution behavior.
- `esm/crypto.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/cryptoNode.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/eskdf.js` (safe): No malicious patterns detected; the code implements a cryptographic key derivation function with proper input validation and no network, filesystem, or process manipulation.
- `esm/hkdf.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/hmac.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/index.js` (safe): The file is a safe root module guard for @noble/hashes that throws an error to enforce submodule imports, with no malicious patterns detected.
- `esm/pbkdf2.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/ripemd160.js` (safe): No malicious patterns detected; the file is a standard RIPEMD-160 hash implementation with no external communication, credential access, dynamic execution, or lifecycle hooks.
- `esm/scrypt.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/sha1.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/sha2.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/sha256.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/sha3-addons.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/sha3.js` (safe): No malicious patterns detected; the code is a standard SHA-3/Keccak hash implementation with no network, filesystem, process, or dynamic execution activity.
- `esm/sha512.js` (safe): No malicious patterns detected; this is a standard SHA-512/384 hash implementation with only cryptographic arithmetic and no network, filesystem, process, or dynamic execution behavior.
- `esm/utils.js` (safe): No malicious patterns detected; the code is a standard cryptographic utility library from noble-hashes implementing hex/byte conversion, byte swapping, and CSPRNG access with no exfiltration, obfuscation, or dynamic execution.
- `hkdf.js` (safe): Cleared by Jev triage; no further analysis needed
- `hmac.js` (safe): No malicious patterns detected; the code implements standard HMAC (RFC 2104) using the @noble/hashes library with no external calls, obfuscation, or suspicious behavior.
- `index.js` (safe): No malicious patterns detected; the file only throws an informative error instructing users to import submodules.
- `pbkdf2.js` (safe): No malicious patterns detected; this is a standard, well-formed implementation of PBKDF2-HMAC from the audited @noble/hashes library.
- `ripemd160.js` (safe): This is a standard, well-known RIPEMD-160 hash implementation with no malicious patterns detected.
- `scrypt.js` (safe): This is a legitimate, well-known scrypt KDF implementation from the audited @noble/hashes library with no malicious patterns detected.
- `sha1.js` (safe): No malicious patterns detected
- `sha2.js` (safe): No malicious patterns detected
- `sha256.js` (safe): No malicious patterns detected; this is a standard implementation of SHA-256/SHA-224 hashing algorithms.
- `sha3-addons.js` (safe): Cryptographic hash function implementation with no malicious patterns detected
- `sha3.js` (safe): No malicious patterns detected; the file implements standard SHA-3/Keccak cryptographic hashing without any suspicious behavior.
- `sha512.js` (safe): The code is a clean, standard implementation of the SHA-2 family of hash functions (SHA-512, SHA-384, SHA-512/224, SHA-512/256) with no malicious patterns, external calls, or obfuscation.
- `src/_assert.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/_blake.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/_md.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/_u64.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/argon2.ts` (safe): No malicious patterns detected; the code is a legitimate Argon2 KDF implementation with no exfiltration, obfuscation, dynamic execution, or network activity.
- `src/blake1.ts` (safe): No malicious patterns detected; the file is a standard implementation of the Blake1 hash family with no network, filesystem, process, or dynamic code execution activity.
- `src/blake2b.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/blake2s.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/blake3.ts` (safe): No malicious patterns detected; this is a standard BLAKE3 cryptographic hash implementation using only assertion utilities and cryptographic primitives from the same package.
- `src/crypto.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/cryptoNode.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/eskdf.ts` (safe): No malicious patterns detected; the code is a legitimate cryptographic key derivation implementation with no network, filesystem, process execution, or obfuscation concerns.
- `src/hkdf.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/hmac.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/index.ts` (safe): No malicious patterns detected; the file only throws an error to enforce submodule imports, which is a legitimate design choice for the @noble/hashes package.
- `src/pbkdf2.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/ripemd160.ts` (safe): No malicious patterns detected; this is a standard RIPEMD-160 hash implementation with no network, filesystem, process, or dynamic code execution activity.
- `src/scrypt.ts` (safe): No malicious patterns detected in this standard Scrypt KDF implementation.
- `src/sha1.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/sha2.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/sha256.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/sha3-addons.ts` (safe): Cleared by Jev triage; no further analysis needed
- `src/sha3.ts` (safe): No malicious patterns detected; the code is a standard cryptographic implementation of SHA3/Keccak with no signs of exfiltration, credential harvesting, obfuscation, or other security concerns.
- `src/sha512.ts` (safe): No malicious patterns detected
- `src/utils.ts` (safe): No malicious patterns detected; the code is a standard cryptographic utility module with no security concerns.
- `utils.js` (safe): No malicious patterns detected; the file contains standard cryptographic utility functions from the noble-hashes library with no exfiltration, credential harvesting, obfuscation, or backdoor behavior.

## Version ranges

None of the 5 scanned versions of @noble/hashes are flagged high or critical. The latest scanned version, 2.2.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 2.2.0 (`2.2.0`): not scanned
- 1.8.0 (`1.8.0`): clean
- 1.7.2 (`1.7.2`): not scanned
- 1.3.3 – 1.7.1 (`>=1.3.3 <=1.7.1`): clean
- 1.3.2 (`1.3.2`): not scanned

## Scanned versions

- [1.8.0](https://security.togoder.click/npm/@noble/hashes@1.8.0): safe, 2026-10-04T16:03:08.000Z
- [1.7.1](https://security.togoder.click/npm/@noble/hashes@1.7.1): safe, 2026-10-04T16:09:50.000Z
- [1.7.0](https://security.togoder.click/npm/@noble/hashes@1.7.0): safe, 2026-10-04T16:20:31.000Z
- [1.4.0](https://security.togoder.click/npm/@noble/hashes@1.4.0): safe, 2026-10-04T16:02:22.000Z
- [1.3.3](https://security.togoder.click/npm/@noble/hashes@1.3.3): safe, 2026-10-04T21:27:29.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
