Togoder security

npm package security report

ethereum-cryptography npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 2.2.1 Files reviewed 48 Size 43.6 KB Scanned

Summary

Togoder Security scanned the npm package ethereum-cryptography@2.2.1 on Oct 4, 2026. An AI review of 48 source files produced 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
4
low

Findings 4

low

no malicious patterns

NPS-CDA500091C5B

The code is a compatibility layer for the secp256k1 library, providing cryptographic operations. No data exfiltration, credential harvesting, obfuscation, mining, backdoors, suspicious network activity, file system manipulation, process spawning, or dynamic imports were found. Top-level code only defines functions and constants.

esm/secp256k1-compat.js
low

Dynamic module loading

NPS-C5F0C3ABC3D5

The code conditionally loads Node.js's built-in 'crypto' module via module.require when web crypto is unavailable. This is a standard pattern in cross-environment libraries and does not use computed or external input, so it is not malicious.

esm/utils.js:33
low

Module loading based on environment detection

NPS-96896C2C2C3A

The IIFE at module scope inspects globalThis for a 'crypto' object and conditionally binds module.require, potentially loading the Node.js crypto module at import time. This executes top-level code on import that performs environment inspection and conditional module resolution. It is consistent with legitimate cross-platform cryptographic utility libraries (matching @noble/hashes patterns), but such behavior warrants verification that the resolved package is authentic and unmodified.

utils.js:66
low

Dynamic module loading with computed/environment-dependent input

NPS-FD657381E6C5

The code dynamically resolves and loads the 'crypto' module via module.require.bind(module). While this is a common pattern for Node.js/WebCrypto compatibility in the @noble/hashes ecosystem, it constitutes dynamic module loading based on runtime environment detection (globalThis.crypto presence). This pattern could theoretically be abused in a compromised or modified package to load arbitrary modules, though in this specific instance it only loads the legitimate Node.js built-in 'crypto' module.

utils.js:76

Files reviewed

FileVerdictWhat the reviewer saw
utils.js medium The code appears to be a legitimate cryptographic utility module from the @noble/hashes ecosystem (likely @ethereumjs/util), with minor dynamic module loading patterns that are common and benign but technically fall into a caution category.
aes.js safe The aes.js file is a straightforward AES encryption/decryption utility using the @noble/hashes crypto module and does not contain any malicious patterns, network requests, or data exfiltration.
bip39/index.js safe No malicious patterns detected; the file is a simple re-export of functions from the @scure/bip39 package with no suspicious behavior.
bip39/wordlists/czech.js safe This is a simple re-export module for the Czech BIP39 wordlist from @scure/bip39 with no malicious patterns, network activity, or dynamic code execution.
bip39/wordlists/english.js safe The file is a simple re-export module with no malicious patterns, side effects, or suspicious behavior.
bip39/wordlists/french.js safe The file is a simple re-export of a wordlist from @scure/bip39 with no malicious patterns, network calls, dynamic execution, or install-time side effects.
bip39/wordlists/italian.js safe No malicious patterns detected; the file is a simple re-export wrapper for the @scure/bip39 Italian wordlist.
bip39/wordlists/japanese.js safe No malicious patterns detected; the file is a simple re-export of a BIP39 Japanese wordlist from @scure/bip39.
bip39/wordlists/korean.js safe No malicious patterns detected
bip39/wordlists/simplified-chinese.js safe No malicious patterns detected; the file is a simple re-export of a wordlist from the @scure/bip39 package with no dynamic execution, network, or filesystem activity.
bip39/wordlists/spanish.js safe No malicious patterns detected; this is a simple re-export shim for the @scure/bip39 Spanish wordlist.
bip39/wordlists/traditional-chinese.js safe No malicious patterns detected; the file is a simple re-export module for a BIP39 Traditional Chinese wordlist with no executable payloads or suspicious behavior.
blake2b.js safe Cleared by Jev triage; no further analysis needed
esm/aes.js safe No malicious patterns detected; the code is a legitimate AES encryption/decryption implementation using standard cryptographic primitives.
esm/bip39/index.js safe No malicious patterns detected; the file simply re-exports standard BIP39 mnemonic functions from the @scure/bip39 package without any suspicious behavior.
esm/bip39/wordlists/czech.js safe No malicious patterns detected
esm/bip39/wordlists/english.js safe No malicious patterns detected
esm/bip39/wordlists/french.js safe The file is a simple re-export of a wordlist from the @scure/bip39 package with no malicious patterns detected.
esm/bip39/wordlists/italian.js safe No malicious patterns detected
esm/bip39/wordlists/japanese.js safe No malicious patterns detected
esm/bip39/wordlists/korean.js safe No malicious patterns detected; the file is a simple ESM re-export of a static BIP39 Korean wordlist.
esm/bip39/wordlists/simplified-chinese.js safe No malicious patterns detected
esm/bip39/wordlists/spanish.js safe No malicious patterns detected; the file is a simple re-export of a BIP39 Spanish wordlist from a trusted package.
esm/bip39/wordlists/traditional-chinese.js safe No malicious patterns detected; the file is a simple re-export of a standard BIP39 wordlist.
esm/blake2b.js safe Cleared by Jev triage; no further analysis needed
Show 23 more files
FileVerdictWhat the reviewer saw
esm/hdkey.js safe This file is a simple re-export of the @scure/bip32 library and contains no malicious patterns.
esm/index.js safe No malicious patterns detected; the file is a harmless entry-point stub that throws an error directing users to the README.
esm/keccak.js safe Cleared by Jev triage; no further analysis needed
esm/pbkdf2.js safe No malicious patterns detected
esm/random.js safe Cleared by Jev triage; no further analysis needed
esm/ripemd160.js safe Cleared by Jev triage; no further analysis needed
esm/scrypt.js safe The file is a thin wrapper around @noble/hashes/scrypt that validates input bytes and delegates to well-known cryptographic implementations, with no malicious patterns detected.
esm/secp256k1-compat.js safe No malicious patterns detected; the code is a legitimate cryptographic compatibility layer.
esm/secp256k1.js safe No malicious patterns detected
esm/sha256.js safe Cleared by Jev triage; no further analysis needed
esm/sha512.js safe Cleared by Jev triage; no further analysis needed
esm/utils.js safe No malicious patterns detected; the code is a benign cryptographic utility module with a safe conditional require of Node's built-in crypto.
hdkey.js safe No malicious patterns detected; the file is a simple re-export wrapper around @scure/bip32 with no exfiltration, obfuscation, or side effects.
index.js safe No malicious patterns detected; the file is a harmless entry-point stub that throws an error directing users to the README.
keccak.js safe No malicious patterns detected
pbkdf2.js safe No malicious patterns detected; the code is a straightforward PBKDF2 wrapper around @noble/hashes with proper input validation and no suspicious behavior.
random.js safe No malicious patterns detected
ripemd160.js safe Cleared by Jev triage; no further analysis needed
scrypt.js safe No malicious patterns detected
secp256k1-compat.js safe No malicious patterns detected
secp256k1.js safe No malicious patterns detected
sha256.js safe No malicious patterns detected
sha512.js safe Cleared by Jev triage; no further analysis needed

Scanned versions of ethereum-cryptography

VersionVerdictFilesScanned
2.2.1 Needs review 48 Oct 4, 2026

Frequently asked questions

Is ethereum-cryptography safe to use?

No confirmed malware was found in ethereum-cryptography@2.2.1, but the review flagged 4 low severity findings for risky patterns worth checking before you rely on it.

Does ethereum-cryptography contain malware?

No malware was identified in ethereum-cryptography@2.2.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was ethereum-cryptography checked?

Togoder Security downloaded the published npm package and had an AI model read its 48 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan ethereum-cryptography together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in ethereum-cryptography@2.2.1, cost nothing.

Related security reports