# ethereum-cryptography@2.2.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:29:52.000Z
- Files reviewed: 48
- Findings: 4 low severity findings
- Report: https://security.togoder.click/npm/ethereum-cryptography
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package ethereum-cryptography@2.2.1 on Oct 4, 2026. An AI review of 48 source files produced 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] no malicious patterns

Finding ID: `NPS-CDA500091C5B`

File: `esm/secp256k1-compat.js`

The code is a compatibility layer for the secp256k1 library, providing cryptographic operations. No data exfiltration, credential harvesting, obfuscation, mining, backdoors, suspicious network activity, file system manipulation, process spawning, or dynamic imports were found. Top-level code only defines functions and constants.

### [low] Dynamic module loading

Finding ID: `NPS-C5F0C3ABC3D5`

File: `esm/utils.js:33`

The code conditionally loads Node.js's built-in 'crypto' module via module.require when web crypto is unavailable. This is a standard pattern in cross-environment libraries and does not use computed or external input, so it is not malicious.

### [low] Module loading based on environment detection

Finding ID: `NPS-96896C2C2C3A`

File: `utils.js:66`

The IIFE at module scope inspects globalThis for a 'crypto' object and conditionally binds module.require, potentially loading the Node.js crypto module at import time. This executes top-level code on import that performs environment inspection and conditional module resolution. It is consistent with legitimate cross-platform cryptographic utility libraries (matching @noble/hashes patterns), but such behavior warrants verification that the resolved package is authentic and unmodified.

### [low] Dynamic module loading with computed/environment-dependent input

Finding ID: `NPS-FD657381E6C5`

File: `utils.js:76`

The code dynamically resolves and loads the 'crypto' module via module.require.bind(module). While this is a common pattern for Node.js/WebCrypto compatibility in the @noble/hashes ecosystem, it constitutes dynamic module loading based on runtime environment detection (globalThis.crypto presence). This pattern could theoretically be abused in a compromised or modified package to load arbitrary modules, though in this specific instance it only loads the legitimate Node.js built-in 'crypto' module.

## Files reviewed

- `utils.js` (medium): The code appears to be a legitimate cryptographic utility module from the @noble/hashes ecosystem (likely @ethereumjs/util), with minor dynamic module loading patterns that are common and benign but technically fall into a caution category.
- `aes.js` (safe): The aes.js file is a straightforward AES encryption/decryption utility using the @noble/hashes crypto module and does not contain any malicious patterns, network requests, or data exfiltration.
- `bip39/index.js` (safe): No malicious patterns detected; the file is a simple re-export of functions from the @scure/bip39 package with no suspicious behavior.
- `bip39/wordlists/czech.js` (safe): This is a simple re-export module for the Czech BIP39 wordlist from @scure/bip39 with no malicious patterns, network activity, or dynamic code execution.
- `bip39/wordlists/english.js` (safe): The file is a simple re-export module with no malicious patterns, side effects, or suspicious behavior.
- `bip39/wordlists/french.js` (safe): The file is a simple re-export of a wordlist from @scure/bip39 with no malicious patterns, network calls, dynamic execution, or install-time side effects.
- `bip39/wordlists/italian.js` (safe): No malicious patterns detected; the file is a simple re-export wrapper for the @scure/bip39 Italian wordlist.
- `bip39/wordlists/japanese.js` (safe): No malicious patterns detected; the file is a simple re-export of a BIP39 Japanese wordlist from @scure/bip39.
- `bip39/wordlists/korean.js` (safe): No malicious patterns detected
- `bip39/wordlists/simplified-chinese.js` (safe): No malicious patterns detected; the file is a simple re-export of a wordlist from the @scure/bip39 package with no dynamic execution, network, or filesystem activity.
- `bip39/wordlists/spanish.js` (safe): No malicious patterns detected; this is a simple re-export shim for the @scure/bip39 Spanish wordlist.
- `bip39/wordlists/traditional-chinese.js` (safe): No malicious patterns detected; the file is a simple re-export module for a BIP39 Traditional Chinese wordlist with no executable payloads or suspicious behavior.
- `blake2b.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/aes.js` (safe): No malicious patterns detected; the code is a legitimate AES encryption/decryption implementation using standard cryptographic primitives.
- `esm/bip39/index.js` (safe): No malicious patterns detected; the file simply re-exports standard BIP39 mnemonic functions from the @scure/bip39 package without any suspicious behavior.
- `esm/bip39/wordlists/czech.js` (safe): No malicious patterns detected
- `esm/bip39/wordlists/english.js` (safe): No malicious patterns detected
- `esm/bip39/wordlists/french.js` (safe): The file is a simple re-export of a wordlist from the @scure/bip39 package with no malicious patterns detected.
- `esm/bip39/wordlists/italian.js` (safe): No malicious patterns detected
- `esm/bip39/wordlists/japanese.js` (safe): No malicious patterns detected
- `esm/bip39/wordlists/korean.js` (safe): No malicious patterns detected; the file is a simple ESM re-export of a static BIP39 Korean wordlist.
- `esm/bip39/wordlists/simplified-chinese.js` (safe): No malicious patterns detected
- `esm/bip39/wordlists/spanish.js` (safe): No malicious patterns detected; the file is a simple re-export of a BIP39 Spanish wordlist from a trusted package.
- `esm/bip39/wordlists/traditional-chinese.js` (safe): No malicious patterns detected; the file is a simple re-export of a standard BIP39 wordlist.
- `esm/blake2b.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/hdkey.js` (safe): This file is a simple re-export of the @scure/bip32 library and contains no malicious patterns.
- `esm/index.js` (safe): No malicious patterns detected; the file is a harmless entry-point stub that throws an error directing users to the README.
- `esm/keccak.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/pbkdf2.js` (safe): No malicious patterns detected
- `esm/random.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/ripemd160.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/scrypt.js` (safe): The file is a thin wrapper around @noble/hashes/scrypt that validates input bytes and delegates to well-known cryptographic implementations, with no malicious patterns detected.
- `esm/secp256k1-compat.js` (safe): No malicious patterns detected; the code is a legitimate cryptographic compatibility layer.
- `esm/secp256k1.js` (safe): No malicious patterns detected
- `esm/sha256.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/sha512.js` (safe): Cleared by Jev triage; no further analysis needed
- `esm/utils.js` (safe): No malicious patterns detected; the code is a benign cryptographic utility module with a safe conditional require of Node's built-in crypto.
- `hdkey.js` (safe): No malicious patterns detected; the file is a simple re-export wrapper around @scure/bip32 with no exfiltration, obfuscation, or side effects.
- `index.js` (safe): No malicious patterns detected; the file is a harmless entry-point stub that throws an error directing users to the README.
- `keccak.js` (safe): No malicious patterns detected
- `pbkdf2.js` (safe): No malicious patterns detected; the code is a straightforward PBKDF2 wrapper around @noble/hashes with proper input validation and no suspicious behavior.
- `random.js` (safe): No malicious patterns detected
- `ripemd160.js` (safe): Cleared by Jev triage; no further analysis needed
- `scrypt.js` (safe): No malicious patterns detected
- `secp256k1-compat.js` (safe): No malicious patterns detected
- `secp256k1.js` (safe): No malicious patterns detected
- `sha256.js` (safe): No malicious patterns detected
- `sha512.js` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
