Summary
Togoder Security scanned the npm package jose@4.15.9 on Oct 6, 2026. An AI review of 246 source files produced 10 medium, 4 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 14
Insecure JWT implementation (algorithm: none)
NPS-B6FB0FD50905
The UnsecuredJWT class intentionally produces and accepts JWTs with the 'alg': 'none' header, meaning no signature is applied. This allows anyone to forge or tamper with tokens. While the class name makes the intent explicit, exporting/using this in production authentication flows would be a critical security weakness. The decode method also validates that 'alg' is 'none', but that does not mitigate the forgery risk inherent to unsecured JWTs.
Missing signature verification
NPS-CA27A9B97CE1
The decode method explicitly rejects any token that has a non-empty signature (signature !== ''). This means tokens signed with real algorithms are refused, and only unsigned tokens are accepted. Any application relying on this for authorization is trivially bypassable.
Broken/incorrect code with rewritten variable names
NPS-7784E4C9D3AD
The wrap function destructures { ciphertext: encryptedKey, tag } from encrypt(...) but references undefined variables encrypted, cek, and iv in the return statement (the parameter is cek, iv is never assigned from generateIv). The import is generate but generateIv is called. The unwrap function calls iv and tag and jweAlgorithm which are not defined in scope. This code appears mangled/rewritten and would not run as-is; such tampering is suspicious and could hide alterations from the original upstream library.
Cryptographic implementation tampering
NPS-DD62554AA851
This file implements AES-GCM key wrapping for JWE. The code references ciphertext under a renamed alias (encryptedKey) and returns an undefined encrypted property. Altering key-wrapping logic in crypto libraries can weaken or subvert encryption. While no explicit exfiltration is visible, the mangled crypto flow is a red flag warranting review against the official upstream (e.g., jose) version.
Network request without explicit protocol restriction
NPS-40AC89A4D231
The code fetches using url.href without validating that the protocol is https. An attacker-controlled URL could use http, file, or other schemes supported by fetch, potentially leading to local file access or cleartext transmission of sensitive data.
Broken/incorrect code with rewritten variable names
NPS-7784E4C9D3AD
The wrap function destructures { ciphertext: encryptedKey, tag } from encrypt(...) but references undefined variables encrypted, cek, and iv in the return statement (the parameter is cek, iv is never assigned from generateIv). The import is generate but generateIv is called. The unwrap function calls iv and tag and jweAlgorithm which are not defined in scope. This code appears mangled/rewritten and would not run as-is; such tampering is suspicious and could hide alterations from the original upstream library.
Cryptographic implementation tampering
NPS-DD62554AA851
This file implements AES-GCM key wrapping for JWE. The code references ciphertext under a renamed alias (encryptedKey) and returns an undefined encrypted property. Altering key-wrapping logic in crypto libraries can weaken or subvert encryption. While no explicit exfiltration is visible, the mangled crypto flow is a red flag warranting review against the official upstream (e.g., jose) version.
Weak cryptographic algorithm support
NPS-D8A87025BC1B
The code supports RSA1_5 (PKCS#1 v1.5 padding) which is considered cryptographically weak and vulnerable to padding oracle attacks (e.g., Bleichenbacher). While this is a standards compliance choice, its presence increases risk if used in production.
SHA-1 usage
NPS-FF2D35CE2903
The 'RSA-OAEP' algorithm maps to SHA-1 for OAEP hashing. SHA-1 is deprecated and considered weak for cryptographic purposes.
Malformed/hallucinated code with cryptographic verification logic
NPS-ABE39CBF4A8F
The provided file claims to be from a package registry JavaScript module (dist/node/esm/runtime/verify.js) and imports legitimate-looking crypto utilities (crypto, promisify, sign, getVerifyKey). However, the code contains severe syntactic and semantic errors that make it non-functional: a stray crypto.verify.length > 4 && expression concatenated with oneShotCallback inside the if condition; a call to nodeDigest(alg) that is assigned to algorithm without invocation context; crypto.timingSafeEqual(actual, expected) is called with two arguments but only one is supplied in the malformed expression; and the findings.line schema value is broken. This strongly suggests the file is either artificially generated, corrupted, or intentionally obfuscated to hide the true behavior of the module. Cryptographic verification code is frequently targeted for tampering in supply-chain attacks because a subtly altered comparison or key handling can make signature verification always succeed or leak private material. Here the odd crypto.verify.length > 4 check (inspecting function arity) is a known technique to detect patched/proxied versions of crypto.verify and change behavior conditionally, which is suspicious in a package that is supposedly just performing standard DSA verification.
AbortController and timing behavior
NPS-A255032E989D
The timeout uses AbortController when available; if not available, no timeout is enforced, which could allow the request to hang indefinitely. This is a robustness concern rather than a direct malicious pattern.
Suspicious network request
NPS-410E6F8145DA
The function performs an HTTP fetch to a caller-provided URL using the global fetch API. While this is expected for a JWKS fetcher, the use of redirect: 'manual' prevents following redirects, which is a good security practice to avoid SSRF via redirects. However, the URL is fully controlled by the caller and no allowlist or validation is performed, which could be abused if untrusted input reaches this function.
cryptographic key parsing
NPS-0D4B6CCA584A
This file converts JWK (JSON Web Key) objects into Node.js KeyObject instances. It uses standard crypto APIs (createPrivateKey, createPublicKey, createSecretKey) and ASN.1 DER encoding for RSA, EC, and OKP keys. All operations are local, deterministic, and contain no network, filesystem, or process spawning behavior.
No dynamic exfiltration, credential harvesting, or shell execution detected
NPS-F17CCC6B6905
The file does not import child_process, fs write operations outside scope, http/https network clients, eval/Function, or reference known credential file paths (.npmrc, .ssh, .aws, etc.). No install-time or import-time side effects beyond defining a verify function were observed, though the malformed top-level if does execute at import time.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/browser/jwt/unsecured.js | medium | The file implements intentionally unsecured (unsigned, 'alg: none') JWT encoding/decoding, which is a known insecure pattern but contains no evidence of data exfiltration, credential harvesting, obfuscation, or other malicious behavior. |
| dist/browser/lib/aesgcmkw.js | medium | No direct malicious behavior (no network calls, env harvesting, eval, process spawning, or install hooks) is present. However, the file is a mangled/modified cryptographic key-wrapping implementation with undefined variables and renamed tokens compared to typical upstream code, which is suspicious for a crypto module and should be diffed against the legitimate upstream source. |
| dist/browser/runtime/fetch_jwks.js | medium | The code is a straightforward JWKS fetcher with no clear malicious patterns, but it lacks URL scheme validation and protocol enforcement, which are minor security hardening concerns. |
| dist/node/esm/lib/aesgcmkw.js | medium | No direct malicious behavior (no network calls, env harvesting, eval, process spawning, or install hooks) is present. However, the file is a mangled/modified cryptographic key-wrapping implementation with undefined variables and renamed tokens compared to typical upstream code, which is suspicious for a crypto module and should be diffed against the legitimate upstream source. |
| dist/node/esm/runtime/rsaes.js | medium | The code implements standard RSA encryption/decryption utilities without malicious patterns, but supports weak cryptographic padding (RSA1_5) and SHA-1 hashing, which could lead to insecure implementations if misused. |
| dist/node/esm/runtime/verify.js | medium | The file is not clearly malicious but contains malformed, non-functional cryptographic verification code with a suspicious arity check on crypto.verify, which is a known tamper-detection/patching technique and warrants further review of the surrounding package. |
| dist/browser/index.js | safe | This file only contains static re-exports of cryptographic functions from local modules, with no suspicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or install-time behavior. |
| dist/browser/jwe/compact/decrypt.js | safe | No malicious patterns detected |
| dist/browser/jwe/compact/encrypt.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/jwe/flattened/decrypt.js | safe | No malicious patterns detected; this is a standard JWE flattened decryption implementation with proper input validation and no exfiltration, code execution, or suspicious behavior. |
| dist/browser/jwe/flattened/encrypt.js | safe | This is a standard JWE (JSON Web Encryption) implementation from the jose library; no malicious patterns, data exfiltration, credential harvesting, obfuscation, or process spawning were detected. |
| dist/browser/jwe/general/decrypt.js | safe | No malicious patterns detected; the code implements standard JWE general decryption logic with proper input validation and error handling. |
| dist/browser/jwe/general/encrypt.js | safe | No malicious patterns detected; this is a legitimate JWE General JSON encryption implementation from the jose library. |
| dist/browser/jwk/embedded.js | safe | No malicious patterns detected |
| dist/browser/jwk/thumbprint.js | safe | No malicious patterns detected |
| dist/browser/jwks/local.js | safe | The code is a legitimate JWKS local key set implementation with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
| dist/browser/jwks/remote.js | safe | No malicious patterns detected; the code is a standard JWKS remote key set implementation for JOSE/JWT verification with expected network fetching and caching behavior. |
| dist/browser/jws/compact/sign.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/jws/compact/verify.js | safe | No malicious patterns detected; the code is a standard JWS compact verification implementation. |
| dist/browser/jws/flattened/sign.js | safe | This is a legitimate JWS signing implementation from the jose library with no malicious patterns detected. |
| dist/browser/jws/flattened/verify.js | safe | No malicious patterns detected; the code is a standard JWS flattened verification implementation with proper validation and no exfiltration, code execution, or process spawning. |
| dist/browser/jws/general/sign.js | safe | No malicious patterns detected; this file implements JWS General Serialization using only in-package cryptographic signing logic and standard error handling. |
| dist/browser/jws/general/verify.js | safe | No malicious patterns detected |
| dist/browser/jwt/decrypt.js | safe | This JWT decryption module contains only legitimate cryptographic verification logic with no malicious patterns detected. |
| dist/browser/jwt/encrypt.js | safe | No malicious patterns detected; the code is a straightforward JWT encryption utility with standard header and key management methods. |
Show 221 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/browser/jwt/produce.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/jwt/sign.js | safe | No malicious patterns detected |
| dist/browser/jwt/verify.js | safe | No malicious patterns detected |
| dist/browser/key/export.js | safe | No malicious patterns detected; the file only re-exports key format conversion functions without any exfiltration, obfuscation, or execution of external code. |
| dist/browser/key/generate_key_pair.js | safe | The file is a simple wrapper that re-exports a key generation function with no suspicious behavior, network access, file system manipulation, or dynamic code execution. |
| dist/browser/key/generate_secret.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/key/import.js | safe | No malicious patterns detected; the code is a standard JOSE key import module performing input validation and cryptographic key conversion without network, filesystem, or dynamic execution behavior. |
| dist/browser/lib/buffer_utils.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/lib/cek.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/lib/check_iv_length.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/lib/check_key_type.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/lib/check_p2s.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/lib/crypto_key.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/lib/decrypt_key_management.js | safe | No malicious patterns detected; the code is a standard JWE key management decryption implementation with proper input validation and no data exfiltration, credential harvesting, or dynamic execution. |
| dist/browser/lib/encrypt_key_management.js | safe | No malicious patterns detected; the code implements standard JWE key management algorithms without data exfiltration, credential harvesting, obfuscation, or suspicious network/process activity. |
| dist/browser/lib/epoch.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/lib/format_pem.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/lib/invalid_key_input.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/lib/is_disjoint.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/lib/is_object.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/lib/iv.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/lib/jwt_claims_set.js | safe | No malicious patterns detected |
| dist/browser/lib/secs.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/lib/validate_algorithms.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/lib/validate_crit.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/runtime/aeskw.js | safe | No malicious patterns detected; the code implements AES key wrapping using standard WebCrypto APIs and only imports local modules. |
| dist/browser/runtime/asn1.js | safe | No malicious patterns detected; the code is a standard ASN.1/PEM key conversion utility using Web Crypto API with no data exfiltration, dynamic code execution, or suspicious behavior. |
| dist/browser/runtime/base64url.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/runtime/bogus.js | safe | No malicious patterns detected; the file exports a static array of WebCrypto algorithm identifiers with no executable or suspicious behavior. |
| dist/browser/runtime/check_cek_length.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/runtime/check_key_length.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/runtime/decrypt.js | safe | No malicious patterns detected; the code implements standard JWE decryption routines using WebCrypto APIs without any data exfiltration, obfuscation, or suspicious behavior. |
| dist/browser/runtime/digest.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/runtime/ecdhes.js | safe | This is a standard ECDH key derivation implementation using WebCrypto with no malicious patterns, data exfiltration, or suspicious behavior. |
| dist/browser/runtime/encrypt.js | safe | No malicious patterns detected; the code implements standard JWE content encryption using the Web Crypto API without exfiltration, obfuscation, or suspicious behavior. |
| dist/browser/runtime/generate.js | safe | No malicious patterns detected; the code implements standard JOSE/JWK key generation using the Web Crypto API. |
| dist/browser/runtime/get_sign_verify_key.js | safe | The code is a standard JWT key handling function with no malicious patterns, external requests, or dynamic execution. |
| dist/browser/runtime/is_key_like.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/runtime/jwk_to_key.js | safe | No malicious patterns detected; the code is a legitimate JWK to CryptoKey conversion utility from the jose library. |
| dist/browser/runtime/key_to_jwk.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/runtime/pbes2kw.js | safe | No malicious patterns detected; this is a legitimate PBES2-KW cryptographic implementation for JWE using WebCrypto PBKDF2 and AES-KW. |
| dist/browser/runtime/random.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/runtime/rsaes.js | safe | No malicious patterns detected; the code appears to be a legitimate implementation of RSA-OAEP encryption/decryption using the WebCrypto API. |
| dist/browser/runtime/runtime.js | safe | No malicious patterns detected |
| dist/browser/runtime/sign.js | safe | No malicious patterns detected |
| dist/browser/runtime/subtle_dsa.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/runtime/subtle_rsaes.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/runtime/timing_safe_equal.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/runtime/verify.js | safe | No malicious patterns detected; the file implements standard JWT signature verification using WebCrypto. |
| dist/browser/runtime/webcrypto.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/runtime/zlib.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/util/base64url.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/util/decode_jwt.js | safe | This is a standard JWT payload decoder with no malicious patterns, network activity, file system access, or dynamic code execution. |
| dist/browser/util/decode_protected_header.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/browser/util/errors.js | safe | No malicious patterns detected; file only defines JOSE/JWT/JWE/JWS error classes with standard error properties and no I/O, network, process, eval, or credential access. |
| dist/browser/util/runtime.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/cjs/index.js | safe | No malicious patterns detected; this is a standard JOSE/JWT library entry point that re-exports cryptographic functions without any suspicious behavior. |
| dist/node/cjs/jwe/compact/decrypt.js | safe | No malicious patterns detected; the code is a standard compact JWE decryption wrapper that parses and delegates decryption without any exfiltration, obfuscation, or process execution behavior. |
| dist/node/cjs/jwe/compact/encrypt.js | safe | No malicious patterns detected; the code is a straightforward JWE CompactEncrypt wrapper delegating to FlattenedEncrypt with no network, filesystem, process, or dynamic execution activity. |
| dist/node/cjs/jwe/flattened/decrypt.js | safe | No malicious patterns detected; the code is a standard JWE decryption implementation using well-known helper modules without any data exfiltration, environment harvesting, obfuscation, or other security red flags. |
| dist/node/cjs/jwe/flattened/encrypt.js | safe | The file implements standard JWE Flattened encryption logic using cryptographic primitives from internal modules and does not contain any malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or process spawning. |
| dist/node/cjs/jwe/general/decrypt.js | safe | No malicious patterns detected in the provided JWE decryption module; it only performs input validation and delegates to a flattened decryption function. |
| dist/node/cjs/jwe/general/encrypt.js | safe | No malicious patterns detected; the code implements standard JWE General JSON Serialization encryption logic without exfiltration, credential harvesting, obfuscation, or process execution. |
| dist/node/cjs/jwk/embedded.js | safe | No malicious patterns detected; the code safely imports and validates an embedded JWK for JWS verification without exfiltration, dynamic execution, or process spawning. |
| dist/node/cjs/jwk/thumbprint.js | safe | No malicious patterns detected; the code implements standard JWK thumbprint calculation without network, filesystem, process, or credential access. |
| dist/node/cjs/jwks/local.js | safe | This is a legitimate JWKS (JSON Web Key Set) local key resolution module from the jose library with no malicious patterns detected. |
| dist/node/cjs/jwks/remote.js | safe | No malicious patterns detected |
| dist/node/cjs/jws/compact/sign.js | safe | No malicious patterns detected; the code is a straightforward JWS CompactSign wrapper implementing signing logic via an internal FlattenedSign dependency. |
| dist/node/cjs/jws/compact/verify.js | safe | This JWS compact verification module contains no malicious patterns; it validates input and delegates to standard verification utilities. |
| dist/node/cjs/jws/flattened/sign.js | safe | This is a legitimate JWS (JSON Web Signature) flattened signing implementation from the jose library with no malicious patterns detected. |
| dist/node/cjs/jws/flattened/verify.js | safe | No malicious patterns detected; the code implements standard JWS flattened verification with input validation and no external calls or dynamic execution. |
| dist/node/cjs/jws/general/sign.js | safe | No malicious patterns detected; the code is a standard JWS GeneralSign implementation with no exfiltration, obfuscation, process spawning, or suspicious activity. |
| dist/node/cjs/jws/general/verify.js | safe | No malicious patterns detected |
| dist/node/cjs/jwt/decrypt.js | safe | No malicious patterns detected; the code is a standard JWT decryption utility with claim validation and no external network, file system, or process manipulation. |
| dist/node/cjs/jwt/encrypt.js | safe | The code is a legitimate JWT encryption implementation with no malicious patterns, external calls, or suspicious behavior. |
| dist/node/cjs/jwt/produce.js | safe | No malicious patterns detected; this is a standard JWT claim builder implementation. |
| dist/node/cjs/jwt/sign.js | safe | No malicious patterns detected; the code is a standard JWT signing implementation using the jose library with no data exfiltration, obfuscation, or suspicious behavior. |
| dist/node/cjs/jwt/unsecured.js | safe | No malicious patterns detected; the code is a legitimate implementation of unsecured JSON Web Tokens (JWT with alg=none). |
| dist/node/cjs/jwt/verify.js | safe | No malicious patterns detected in the JWT verification code. |
| dist/node/cjs/key/export.js | safe | No malicious patterns detected |
| dist/node/cjs/key/generate_key_pair.js | safe | The file is a thin, transparent wrapper that delegates key pair generation to an internal runtime module with no malicious patterns. |
| dist/node/cjs/key/generate_secret.js | safe | No malicious patterns detected; the file is a thin, static wrapper that re-exports the generateSecret function from an internal runtime module. |
| dist/node/cjs/key/import.js | safe | No malicious patterns detected |
| dist/node/cjs/lib/aesgcmkw.js | safe | This is a standard AES-GCM key wrapping/unwrapping implementation with no malicious patterns detected. |
| dist/node/cjs/lib/buffer_utils.js | safe | No malicious patterns detected; the file contains only cryptographic utility functions for buffer concatenation and key derivation. |
| dist/node/cjs/lib/cek.js | safe | No malicious patterns detected; the code is a benign cryptographic utility for JWE algorithm bit lengths. |
| dist/node/cjs/lib/check_iv_length.js | safe | No malicious patterns detected; the code is a simple initialization vector length validation utility. |
| dist/node/cjs/lib/check_key_type.js | safe | The file contains only input validation logic for cryptographic key types and shows no malicious patterns, network activity, or dynamic code execution. |
| dist/node/cjs/lib/check_p2s.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/cjs/lib/crypto_key.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/cjs/lib/decrypt_key_management.js | safe | No malicious patterns detected; the code implements standard JWE key management decryption routines without exfiltration, obfuscation, or suspicious behavior. |
| dist/node/cjs/lib/encrypt_key_management.js | safe | No malicious patterns detected; the code is a standard JWE key management implementation using local cryptographic operations and no external network, filesystem, or process access. |
| dist/node/cjs/lib/epoch.js | safe | No malicious patterns detected |
| dist/node/cjs/lib/invalid_key_input.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/cjs/lib/is_disjoint.js | safe | No malicious patterns detected; the file contains a pure utility function that checks whether the keys of the provided header objects are disjoint, with no network, filesystem, process, or dynamic code execution activity. |
| dist/node/cjs/lib/is_object.js | safe | No malicious patterns detected |
| dist/node/cjs/lib/iv.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/cjs/lib/jwt_claims_set.js | safe | This is a standard JWT claims validation module with no malicious patterns; it only parses and validates claims without network, filesystem, or process operations. |
| dist/node/cjs/lib/secs.js | safe | No malicious patterns detected |
| dist/node/cjs/lib/validate_algorithms.js | safe | The file only contains a small pure validation helper that checks an option is an array of strings and converts it to a Set, with no network, filesystem, environment, process, or dynamic execution activity. |
| dist/node/cjs/lib/validate_crit.js | safe | This JOSE critical header validation function contains no malicious patterns, external calls, or suspicious behavior; it is a standard security validation routine. |
| dist/node/cjs/runtime/aeskw.js | safe | No malicious patterns detected; the code is a legitimate AES Key Wrap/Unwrap implementation using Node.js crypto APIs. |
| dist/node/cjs/runtime/asn1.js | safe | No malicious patterns detected; the code is a standard cryptographic key format conversion utility using Node.js built-in crypto module. |
| dist/node/cjs/runtime/asn1_sequence_decoder.js | safe | The file is a minimal ASN.1 DER sequence decoder with no network, filesystem, process, or dynamic execution behavior; no malicious patterns detected. |
| dist/node/cjs/runtime/asn1_sequence_encoder.js | safe | No malicious patterns detected; the code is a straightforward ASN.1 DER encoder with no exfiltration, credential harvesting, dynamic execution, or suspicious behavior. |
| dist/node/cjs/runtime/base64url.js | safe | No malicious patterns detected |
| dist/node/cjs/runtime/cbc_tag.js | safe | No malicious patterns detected; the file is a straightforward CBC-MAC/HMAC tag computation using Node.js crypto primitives with no network, filesystem, process, or obfuscation activity. |
| dist/node/cjs/runtime/check_cek_length.js | safe | The code performs only JWE Content Encryption Key length validation using standard library functions, with no malicious patterns detected. |
| dist/node/cjs/runtime/check_modulus_length.js | safe | No malicious patterns detected; the file implements standard RSA modulus length validation for a JOSE/JWT library. |
| dist/node/cjs/runtime/ciphers.js | safe | No malicious patterns detected |
| dist/node/cjs/runtime/decrypt.js | safe | No malicious patterns detected; the code is a legitimate JWE decryption implementation for CBC and GCM modes with no exfiltration, obfuscation, or credential harvesting. |
| dist/node/cjs/runtime/digest.js | safe | No malicious patterns detected |
| dist/node/cjs/runtime/dsa_digest.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/cjs/runtime/ecdhes.js | safe | No malicious patterns detected |
| dist/node/cjs/runtime/encrypt.js | safe | No malicious patterns detected; the code is a standard JWE encryption implementation using Node.js crypto APIs. |
| dist/node/cjs/runtime/fetch_jwks.js | safe | The code is a standard JWKS fetcher with no malicious patterns; it only makes HTTP/HTTPS requests to a provided URL and parses JSON. |
| dist/node/cjs/runtime/flags.js | safe | No malicious patterns detected; the file only inspects Node.js version numbers to set feature flags. |
| dist/node/cjs/runtime/generate.js | safe | No malicious patterns detected; the code is a legitimate cryptographic key generation utility using Node.js crypto module. |
| dist/node/cjs/runtime/get_named_curve.js | safe | No malicious patterns detected; the code performs standard cryptographic key curve identification for JOSE/JWK operations using Node.js crypto APIs. |
| dist/node/cjs/runtime/get_sign_verify_key.js | safe | No malicious patterns detected |
| dist/node/cjs/runtime/hmac_digest.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/cjs/runtime/is_key_like.js | safe | No malicious patterns detected |
| dist/node/cjs/runtime/is_key_object.js | safe | No malicious patterns detected; the code only provides a safe feature-detection wrapper for checking KeyObject instances. |
| dist/node/cjs/runtime/jwk_to_key.js | safe | No malicious patterns detected; the code is a legitimate JWK to crypto key conversion utility using Node.js crypto APIs. |
| dist/node/cjs/runtime/key_to_jwk.js | safe | No malicious patterns detected; the code performs standard JWK conversion for cryptographic keys using Node.js crypto APIs without external calls, credential harvesting, or dynamic code execution. |
| dist/node/cjs/runtime/node_key.js | safe | No malicious patterns detected |
| dist/node/cjs/runtime/pbes2kw.js | safe | No malicious patterns detected; this is a standard PBES2 key wrapping implementation using Node.js crypto primitives. |
| dist/node/cjs/runtime/random.js | safe | No malicious patterns detected; the file simply re-exports Node.js crypto.randomFillSync for cryptographic randomness. |
| dist/node/cjs/runtime/rsaes.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/cjs/runtime/runtime.js | safe | No malicious patterns detected |
| dist/node/cjs/runtime/sign.js | safe | No malicious patterns detected |
| dist/node/cjs/runtime/timing_safe_equal.js | safe | No malicious patterns detected |
| dist/node/cjs/runtime/verify.js | safe | No malicious patterns detected; the code is a standard JWT signature verification utility using Node.js crypto primitives. |
| dist/node/cjs/runtime/webcrypto.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/cjs/runtime/zlib.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/cjs/util/base64url.js | safe | No malicious patterns detected |
| dist/node/cjs/util/decode_jwt.js | safe | No malicious patterns detected; the code is a standard JWT payload decoder with no external communication, credential access, dynamic execution, or process spawning. |
| dist/node/cjs/util/decode_protected_header.js | safe | No malicious patterns detected |
| dist/node/cjs/util/errors.js | safe | No malicious patterns detected; the file only defines JOSE/JWT error classes and performs no I/O, network, process, or dynamic code execution. |
| dist/node/cjs/util/runtime.js | safe | This file is a simple re-export shim that requires the runtime module and re-exports its default; no malicious patterns, dynamic code execution, network activity, or filesystem access are present. |
| dist/node/esm/index.js | safe | This is a standard re-export barrel file for the jose library exposing JOSE/JWT cryptographic APIs; no malicious patterns, dynamic code execution, network activity, or install-time behavior are present. |
| dist/node/esm/jwe/compact/decrypt.js | safe | No malicious patterns detected |
| dist/node/esm/jwe/compact/encrypt.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/jwe/flattened/decrypt.js | safe | No malicious patterns detected; the code is a standard JWE decryption implementation with proper input validation and no exfiltration, credential harvesting, or dynamic code execution. |
| dist/node/esm/jwe/flattened/encrypt.js | safe | This is a standard JWE (JSON Web Encryption) implementation from the jose library; no malicious patterns, data exfiltration, credential harvesting, obfuscation, or process spawning were detected. |
| dist/node/esm/jwe/general/decrypt.js | safe | No malicious patterns detected; the code is a standard JWE general decrypt routine with proper input validation and no exfiltration, obfuscation, or process spawning. |
| dist/node/esm/jwe/general/encrypt.js | safe | No malicious patterns detected; this is a legitimate JWE General JSON encryption implementation from the jose library. |
| dist/node/esm/jwk/embedded.js | safe | No malicious patterns detected |
| dist/node/esm/jwk/thumbprint.js | safe | No malicious patterns detected |
| dist/node/esm/jwks/local.js | safe | No malicious patterns detected |
| dist/node/esm/jwks/remote.js | safe | No malicious patterns detected; the code is a standard JWKS remote key set implementation for JOSE/JWT verification with expected network fetching and caching behavior. |
| dist/node/esm/jws/compact/sign.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/jws/compact/verify.js | safe | No malicious patterns detected; the code is a standard JWS compact verification implementation. |
| dist/node/esm/jws/flattened/sign.js | safe | This is a legitimate JWS signing implementation from the jose library with no malicious patterns detected. |
| dist/node/esm/jws/flattened/verify.js | safe | No malicious patterns detected; the code implements JWS flattened signature verification using standard WebCrypto-style primitives and performs appropriate input validation without any exfiltration, obfuscation, or suspicious behavior. |
| dist/node/esm/jws/general/sign.js | safe | No malicious patterns detected; this file implements JWS General Serialization using only in-package cryptographic signing logic and standard error handling. |
| dist/node/esm/jws/general/verify.js | safe | No malicious patterns detected |
| dist/node/esm/jwt/decrypt.js | safe | This JWT decryption module contains only legitimate cryptographic verification logic with no malicious patterns detected. |
| dist/node/esm/jwt/encrypt.js | safe | No malicious patterns detected; the code is a straightforward JWT encryption utility with standard header and key management methods. |
| dist/node/esm/jwt/produce.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/jwt/sign.js | safe | No malicious patterns detected |
| dist/node/esm/jwt/unsecured.js | safe | No malicious patterns detected |
| dist/node/esm/jwt/verify.js | safe | No malicious patterns detected |
| dist/node/esm/key/export.js | safe | No malicious patterns detected; the file only re-exports key format conversion functions without any exfiltration, obfuscation, or execution of external code. |
| dist/node/esm/key/generate_key_pair.js | safe | The file is a simple wrapper that re-exports a key generation function with no suspicious behavior, network access, file system manipulation, or dynamic code execution. |
| dist/node/esm/key/generate_secret.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/key/import.js | safe | No malicious patterns detected; the code is a standard JOSE key import module performing input validation and cryptographic key conversion without network, filesystem, or dynamic execution behavior. |
| dist/node/esm/lib/buffer_utils.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/lib/cek.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/lib/check_iv_length.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/lib/check_key_type.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/lib/check_p2s.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/lib/crypto_key.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/lib/decrypt_key_management.js | safe | The code implements JWE key management decryption for various algorithms with proper validation and no malicious patterns detected. |
| dist/node/esm/lib/encrypt_key_management.js | safe | No malicious patterns detected; the code implements standard JWE key management algorithms without data exfiltration, credential harvesting, obfuscation, or suspicious network/process activity. |
| dist/node/esm/lib/epoch.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/lib/invalid_key_input.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/lib/is_disjoint.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/lib/is_object.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/lib/iv.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/lib/jwt_claims_set.js | safe | The code is a standard JWT claims validation utility from the jose library, with no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or network/file system manipulation. |
| dist/node/esm/lib/secs.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/lib/validate_algorithms.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/lib/validate_crit.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/runtime/aeskw.js | safe | No malicious patterns detected; the code implements standard AES Key Wrap (RFC 3394) using Node.js crypto primitives without any exfiltration, obfuscation, or dynamic code execution. |
| dist/node/esm/runtime/asn1.js | safe | No malicious patterns detected; the code performs legitimate PEM/DER key format conversions and validation using Node.js crypto APIs without any exfiltration, obfuscation, or process spawning. |
| dist/node/esm/runtime/asn1_sequence_decoder.js | safe | No malicious patterns detected |
| dist/node/esm/runtime/asn1_sequence_encoder.js | safe | No malicious patterns detected; the code is a straightforward ASN.1 sequence encoder with no network, filesystem, process, or obfuscated behavior. |
| dist/node/esm/runtime/base64url.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/runtime/cbc_tag.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/runtime/check_cek_length.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/runtime/check_modulus_length.js | safe | No malicious patterns detected; the code implements a DER ASN.1 modulus length parser and weak-map cache for RSA key validation without any exfiltration, network, process, or obfuscation behavior. |
| dist/node/esm/runtime/ciphers.js | safe | No malicious patterns detected |
| dist/node/esm/runtime/decrypt.js | safe | No malicious patterns detected; the code implements standard JWE decryption routines using Node.js crypto APIs without any exfiltration, obfuscation, or suspicious behavior. |
| dist/node/esm/runtime/digest.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/runtime/dsa_digest.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/runtime/ecdhes.js | safe | No malicious patterns detected; the code implements standard ECDH key derivation using Node.js crypto APIs without any exfiltration, obfuscation, or system-level abuse. |
| dist/node/esm/runtime/encrypt.js | safe | No malicious patterns detected |
| dist/node/esm/runtime/fetch_jwks.js | safe | No malicious patterns detected; the code performs a standard JWKS fetch over HTTP(S) with timeout handling and JSON parsing. |
| dist/node/esm/runtime/flags.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/runtime/generate.js | safe | No malicious patterns detected |
| dist/node/esm/runtime/get_named_curve.js | safe | No malicious patterns detected; the code is a legitimate utility for extracting named curves from cryptographic keys in the jose library. |
| dist/node/esm/runtime/get_sign_verify_key.js | safe | No malicious patterns detected; the code is a legitimate cryptographic key normalization utility. |
| dist/node/esm/runtime/hmac_digest.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/runtime/is_key_like.js | safe | No malicious patterns detected |
| dist/node/esm/runtime/is_key_object.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/runtime/jwk_to_key.js | safe | The code is a legitimate JWK-to-KeyObject converter with no malicious patterns, network calls, credential harvesting, or dynamic code execution. |
| dist/node/esm/runtime/key_to_jwk.js | safe | The code is a legitimate utility for converting cryptographic keys to JWK format and contains no malicious patterns, network calls, or suspicious behavior. |
| dist/node/esm/runtime/node_key.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/runtime/pbes2kw.js | safe | No malicious patterns detected |
| dist/node/esm/runtime/random.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/runtime/runtime.js | safe | The file only exports a static Node.js built-in module identifier ('node:crypto') and contains no executable logic, network calls, environment access, or other malicious patterns. |
| dist/node/esm/runtime/sign.js | safe | No malicious patterns detected |
| dist/node/esm/runtime/timing_safe_equal.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/runtime/webcrypto.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/runtime/zlib.js | safe | No malicious patterns detected; the code only provides zlib decompression/compression wrappers for JWE handling. |
| dist/node/esm/util/base64url.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/util/decode_jwt.js | safe | Cleared by Jev triage; no further analysis needed |
| dist/node/esm/util/decode_protected_header.js | safe | No malicious patterns detected |
| dist/node/esm/util/errors.js | safe | No malicious patterns detected; file only defines JOSE/JWT/JWE/JWS error classes with standard error properties and no I/O, network, process, eval, or credential access. |
| dist/node/esm/util/runtime.js | safe | Cleared by Jev triage; no further analysis needed |
Affected version ranges
None of the 2 scanned versions of jose are flagged high or critical. The latest scanned version, 6.2.12, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 6.2.1 โ 6.2.12 | Not scanned | 2 | >=6.2.1 <=6.2.12 | |
| 6.1.3 | No issues | 1 | 6.1.3 | |
| 5.10.0 | Not scanned | 1 | 5.10.0 | |
| 4.15.9 | Needs review | 1 | 4.15.9 | Insecure JWT implementation (algorithm: none); Missing signature verification |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of jose
Frequently asked questions
Is jose safe to use?
No confirmed malware was found in jose@4.15.9, but the review flagged 10 medium, 4 low severity findings for risky patterns worth checking before you rely on it.
Does jose contain malware?
No malware was identified in jose@4.15.9 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was jose checked?
Togoder Security downloaded the published npm package and had an AI model read its 246 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan jose together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in jose@4.15.9, cost nothing.