Summary
Togoder Security scanned the npm package ethereum-cryptography@2.2.1 on Oct 4, 2026. An AI review of 48 source files produced 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 4
no malicious patterns
NPS-CDA500091C5B
The code is a compatibility layer for the secp256k1 library, providing cryptographic operations. No data exfiltration, credential harvesting, obfuscation, mining, backdoors, suspicious network activity, file system manipulation, process spawning, or dynamic imports were found. Top-level code only defines functions and constants.
Dynamic module loading
NPS-C5F0C3ABC3D5
The code conditionally loads Node.js's built-in 'crypto' module via module.require when web crypto is unavailable. This is a standard pattern in cross-environment libraries and does not use computed or external input, so it is not malicious.
Module loading based on environment detection
NPS-96896C2C2C3A
The IIFE at module scope inspects globalThis for a 'crypto' object and conditionally binds module.require, potentially loading the Node.js crypto module at import time. This executes top-level code on import that performs environment inspection and conditional module resolution. It is consistent with legitimate cross-platform cryptographic utility libraries (matching @noble/hashes patterns), but such behavior warrants verification that the resolved package is authentic and unmodified.
Dynamic module loading with computed/environment-dependent input
NPS-FD657381E6C5
The code dynamically resolves and loads the 'crypto' module via module.require.bind(module). While this is a common pattern for Node.js/WebCrypto compatibility in the @noble/hashes ecosystem, it constitutes dynamic module loading based on runtime environment detection (globalThis.crypto presence). This pattern could theoretically be abused in a compromised or modified package to load arbitrary modules, though in this specific instance it only loads the legitimate Node.js built-in 'crypto' module.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| utils.js | medium | The code appears to be a legitimate cryptographic utility module from the @noble/hashes ecosystem (likely @ethereumjs/util), with minor dynamic module loading patterns that are common and benign but technically fall into a caution category. |
| aes.js | safe | The aes.js file is a straightforward AES encryption/decryption utility using the @noble/hashes crypto module and does not contain any malicious patterns, network requests, or data exfiltration. |
| bip39/index.js | safe | No malicious patterns detected; the file is a simple re-export of functions from the @scure/bip39 package with no suspicious behavior. |
| bip39/wordlists/czech.js | safe | This is a simple re-export module for the Czech BIP39 wordlist from @scure/bip39 with no malicious patterns, network activity, or dynamic code execution. |
| bip39/wordlists/english.js | safe | The file is a simple re-export module with no malicious patterns, side effects, or suspicious behavior. |
| bip39/wordlists/french.js | safe | The file is a simple re-export of a wordlist from @scure/bip39 with no malicious patterns, network calls, dynamic execution, or install-time side effects. |
| bip39/wordlists/italian.js | safe | No malicious patterns detected; the file is a simple re-export wrapper for the @scure/bip39 Italian wordlist. |
| bip39/wordlists/japanese.js | safe | No malicious patterns detected; the file is a simple re-export of a BIP39 Japanese wordlist from @scure/bip39. |
| bip39/wordlists/korean.js | safe | No malicious patterns detected |
| bip39/wordlists/simplified-chinese.js | safe | No malicious patterns detected; the file is a simple re-export of a wordlist from the @scure/bip39 package with no dynamic execution, network, or filesystem activity. |
| bip39/wordlists/spanish.js | safe | No malicious patterns detected; this is a simple re-export shim for the @scure/bip39 Spanish wordlist. |
| bip39/wordlists/traditional-chinese.js | safe | No malicious patterns detected; the file is a simple re-export module for a BIP39 Traditional Chinese wordlist with no executable payloads or suspicious behavior. |
| blake2b.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/aes.js | safe | No malicious patterns detected; the code is a legitimate AES encryption/decryption implementation using standard cryptographic primitives. |
| esm/bip39/index.js | safe | No malicious patterns detected; the file simply re-exports standard BIP39 mnemonic functions from the @scure/bip39 package without any suspicious behavior. |
| esm/bip39/wordlists/czech.js | safe | No malicious patterns detected |
| esm/bip39/wordlists/english.js | safe | No malicious patterns detected |
| esm/bip39/wordlists/french.js | safe | The file is a simple re-export of a wordlist from the @scure/bip39 package with no malicious patterns detected. |
| esm/bip39/wordlists/italian.js | safe | No malicious patterns detected |
| esm/bip39/wordlists/japanese.js | safe | No malicious patterns detected |
| esm/bip39/wordlists/korean.js | safe | No malicious patterns detected; the file is a simple ESM re-export of a static BIP39 Korean wordlist. |
| esm/bip39/wordlists/simplified-chinese.js | safe | No malicious patterns detected |
| esm/bip39/wordlists/spanish.js | safe | No malicious patterns detected; the file is a simple re-export of a BIP39 Spanish wordlist from a trusted package. |
| esm/bip39/wordlists/traditional-chinese.js | safe | No malicious patterns detected; the file is a simple re-export of a standard BIP39 wordlist. |
| esm/blake2b.js | safe | Cleared by Jev triage; no further analysis needed |
Show 23 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| esm/hdkey.js | safe | This file is a simple re-export of the @scure/bip32 library and contains no malicious patterns. |
| esm/index.js | safe | No malicious patterns detected; the file is a harmless entry-point stub that throws an error directing users to the README. |
| esm/keccak.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/pbkdf2.js | safe | No malicious patterns detected |
| esm/random.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/ripemd160.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/scrypt.js | safe | The file is a thin wrapper around @noble/hashes/scrypt that validates input bytes and delegates to well-known cryptographic implementations, with no malicious patterns detected. |
| esm/secp256k1-compat.js | safe | No malicious patterns detected; the code is a legitimate cryptographic compatibility layer. |
| esm/secp256k1.js | safe | No malicious patterns detected |
| esm/sha256.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/sha512.js | safe | Cleared by Jev triage; no further analysis needed |
| esm/utils.js | safe | No malicious patterns detected; the code is a benign cryptographic utility module with a safe conditional require of Node's built-in crypto. |
| hdkey.js | safe | No malicious patterns detected; the file is a simple re-export wrapper around @scure/bip32 with no exfiltration, obfuscation, or side effects. |
| index.js | safe | No malicious patterns detected; the file is a harmless entry-point stub that throws an error directing users to the README. |
| keccak.js | safe | No malicious patterns detected |
| pbkdf2.js | safe | No malicious patterns detected; the code is a straightforward PBKDF2 wrapper around @noble/hashes with proper input validation and no suspicious behavior. |
| random.js | safe | No malicious patterns detected |
| ripemd160.js | safe | Cleared by Jev triage; no further analysis needed |
| scrypt.js | safe | No malicious patterns detected |
| secp256k1-compat.js | safe | No malicious patterns detected |
| secp256k1.js | safe | No malicious patterns detected |
| sha256.js | safe | No malicious patterns detected |
| sha512.js | safe | Cleared by Jev triage; no further analysis needed |
Scanned versions of ethereum-cryptography
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 2.2.1 | Needs review | 48 | Oct 4, 2026 |
Frequently asked questions
Is ethereum-cryptography safe to use?
No confirmed malware was found in ethereum-cryptography@2.2.1, but the review flagged 4 low severity findings for risky patterns worth checking before you rely on it.
Does ethereum-cryptography contain malware?
No malware was identified in ethereum-cryptography@2.2.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was ethereum-cryptography checked?
Togoder Security downloaded the published npm package and had an AI model read its 48 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan ethereum-cryptography together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in ethereum-cryptography@2.2.1, cost nothing.