# eciesjs@0.4.16 security report (npm)

- Verdict: **No issues** (risk level: safe)
- Scanned: 2026-10-04T16:27:45.000Z
- Files reviewed: 11
- Findings: 1 low severity finding
- Report: https://security.togoder.click/npm/eciesjs
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package eciesjs@0.4.16 on Oct 4, 2026. An AI review of 11 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

## Findings

### [low] Use of AES-256-CBC without authentication

Finding ID: `NPS-AA51AF9F38B8`

File: `dist/utils/symmetric.js:30`

The code supports 'aes-256-cbc' mode which lacks authentication (no AAD/AEAD tag), making it vulnerable to padding oracle attacks. However, this is a documented limitation and not a malicious pattern.

## Files reviewed

- `dist/config.js` (safe): No malicious patterns detected
- `dist/consts.js` (safe): No malicious patterns detected
- `dist/index.js` (safe): No malicious patterns detected in this ECIES encryption library implementation.
- `dist/keys/PrivateKey.js` (safe): The code implements standard elliptic curve private key operations with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or dynamic execution.
- `dist/keys/PublicKey.js` (safe): No malicious patterns detected; the code is a standard cryptographic PublicKey implementation without any suspicious behavior.
- `dist/keys/index.js` (safe): No malicious patterns detected
- `dist/utils/elliptic.js` (safe): No malicious patterns detected; the code is a legitimate elliptic curve cryptography utility with no exfiltration, credential harvesting, obfuscation, or other red flags.
- `dist/utils/hash.js` (safe): No malicious patterns detected; the code only implements standard HKDF-SHA256 key derivation using the trusted @noble/hashes library.
- `dist/utils/hex.js` (safe): No malicious patterns detected; the code performs simple hex decoding using a well-known utility library.
- `dist/utils/index.js` (safe): No malicious patterns detected; the file only contains standard TypeScript helper functions and re-exports utility modules.
- `dist/utils/symmetric.js` (safe): No malicious patterns detected; the code implements standard symmetric encryption using well-known libraries with a documented insecure legacy option.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
