Togoder security

npm package security report

jose@6.1.3 security report

No malicious code found.

No issues Version 6.1.3 Files reviewed 66 Size 143.4 KB Scanned

Summary

Togoder Security scanned the npm package jose@6.1.3 on Oct 4, 2026. An AI review of 66 source files produced 1 low severity finding. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
1
low

Findings 1

low

Cryptographic Implementation

NPS-A4956E6D40D6

The timingSafeEqual function uses HMAC with SHA-256 to compare buffers in a timing-safe manner, but note that HMAC key generation and signing operation may introduce variable timing based on input length. This is a known pattern in JOSE libraries and not considered malicious.

dist/webapi/lib/decrypt.js:6

Files reviewed

FileVerdictWhat the reviewer saw
dist/webapi/index.js safe This is a standard barrel export file for the jose library's Web API entry point, re-exporting cryptographic JWE/JWS/JWT utilities with no malicious patterns detected.
dist/webapi/jwe/compact/decrypt.js safe No malicious patterns detected; the code is a standard JWE compact decryption implementation using internal cryptographic utilities.
dist/webapi/jwe/compact/encrypt.js safe No malicious patterns detected; the code is a straightforward JWE compact encryption wrapper with no network, filesystem, process, or dynamic execution behavior.
dist/webapi/jwe/flattened/decrypt.js safe This is a legitimate JWE flattened decryption implementation from the jose library with no malicious patterns detected.
dist/webapi/jwe/flattened/encrypt.js safe No malicious patterns detected; the code implements standard JWE encryption functionality without any signs of data exfiltration, credential harvesting, obfuscation, or other security concerns.
dist/webapi/jwe/general/decrypt.js safe No malicious patterns detected
dist/webapi/jwe/general/encrypt.js safe No malicious patterns detected; the code implements JWE encryption logic with no exfiltration, credential harvesting, obfuscation, or other security concerns.
dist/webapi/jwk/embedded.js safe This is a legitimate JOSE (JSON Object Signing and Encryption) EmbeddedJWK implementation that extracts and imports a public key from the JWT header; no malicious patterns detected.
dist/webapi/jwk/thumbprint.js safe No malicious patterns detected in the JWK thumbprint calculation code; it performs standard cryptographic digest operations without network, filesystem, or process manipulation.
dist/webapi/jwks/local.js safe No malicious patterns detected; the code is a standard JWKS local key set implementation with no network, filesystem, process, or obfuscation concerns.
dist/webapi/jwks/remote.js safe The code is a legitimate JWKS remote key set implementation for the jose library, with no malicious patterns detected.
dist/webapi/jws/compact/sign.js safe Cleared by Jev triage; no further analysis needed
dist/webapi/jws/compact/verify.js safe No malicious patterns detected; the code is a standard JWS compact verification implementation.
dist/webapi/jws/flattened/sign.js safe This is a standard JWS flattened signing implementation with no malicious patterns, external network calls, credential harvesting, or dynamic code execution.
dist/webapi/jws/flattened/verify.js safe No malicious patterns detected; the code is a standard JWS flattened verification implementation with input validation and no network, filesystem, or dynamic execution activities.
dist/webapi/jws/general/sign.js safe No malicious patterns detected; the code implements standard JWS multi-signature handling without network, filesystem, or dynamic execution risks.
dist/webapi/jws/general/verify.js safe No malicious patterns detected; the code implements standard JWS verification logic with proper input validation and error handling.
dist/webapi/jwt/decrypt.js safe Code performs standard JWT decryption and claim validation with no malicious patterns detected.
dist/webapi/jwt/encrypt.js safe No malicious patterns detected; this is a standard JWT encryption builder with no network, filesystem, process, or dynamic code execution behavior.
dist/webapi/jwt/sign.js safe No malicious patterns detected
dist/webapi/jwt/unsecured.js safe No malicious patterns detected; code implements a standard unsecured JWT (alg=none) that performs only local base64url encoding/decoding and claim validation without any exfiltration, credential access, or dynamic code execution.
dist/webapi/jwt/verify.js safe The JWT verification code contains no malicious patterns; it performs standard cryptographic verification and claim validation without any exfiltration, obfuscation, or dynamic execution.
dist/webapi/key/export.js safe The file only re-exports key conversion functions from internal modules without any network, filesystem, process, or dynamic code execution behavior.
dist/webapi/key/generate_key_pair.js safe This module only generates cryptographic key pairs using the Web Crypto API with strict algorithm validation and no malicious patterns, network calls, or file system access.
dist/webapi/key/generate_secret.js safe No malicious patterns detected; the code performs standard JWK secret generation using WebCrypto APIs.
Show 41 more files
FileVerdictWhat the reviewer saw
dist/webapi/key/import.js safe No malicious patterns detected
dist/webapi/lib/aesgcmkw.js safe The code is a straightforward implementation of AES-GCM key wrapping/unwrapping for JWE, with no malicious patterns, external calls, or obfuscation detected.
dist/webapi/lib/aeskw.js safe No malicious patterns detected; the code is a standard AES-KW key wrapping implementation using Web Crypto API.
dist/webapi/lib/asn1.js safe No malicious patterns detected
dist/webapi/lib/base64.js safe Cleared by Jev triage; no further analysis needed
dist/webapi/lib/buffer_utils.js safe Cleared by Jev triage; no further analysis needed
dist/webapi/lib/cek.js safe Cleared by Jev triage; no further analysis needed
dist/webapi/lib/check_cek_length.js safe Cleared by Jev triage; no further analysis needed
dist/webapi/lib/check_iv_length.js safe Cleared by Jev triage; no further analysis needed
dist/webapi/lib/check_key_length.js safe Cleared by Jev triage; no further analysis needed
dist/webapi/lib/check_key_type.js safe Cleared by Jev triage; no further analysis needed
dist/webapi/lib/crypto_key.js safe Cleared by Jev triage; no further analysis needed
dist/webapi/lib/decrypt.js safe No malicious patterns detected; the code implements standard JWE decryption using Web Crypto API with proper error handling and timing-safe comparison.
dist/webapi/lib/decrypt_key_management.js safe No malicious patterns detected; this is a standard JWE key management decryption module with proper input validation and no exfiltration, dynamic execution, or suspicious behavior.
dist/webapi/lib/digest.js safe Cleared by Jev triage; no further analysis needed
dist/webapi/lib/ecdhes.js safe The code implements standard ECDH key derivation with Concat KDF using only Web Crypto APIs and local utilities, with no malicious patterns detected.
dist/webapi/lib/encrypt.js safe This is legitimate JWE encryption code from a JOSE library with no malicious patterns, exfiltration, or dynamic code execution.
dist/webapi/lib/encrypt_key_management.js safe No malicious patterns detected
dist/webapi/lib/get_sign_verify_key.js safe No malicious patterns detected; the code only performs standard HMAC key import and signature key validation.
dist/webapi/lib/invalid_key_input.js safe Cleared by Jev triage; no further analysis needed
dist/webapi/lib/is_disjoint.js safe Cleared by Jev triage; no further analysis needed
dist/webapi/lib/is_jwk.js safe No malicious patterns detected
dist/webapi/lib/is_key_like.js safe Cleared by Jev triage; no further analysis needed
dist/webapi/lib/is_object.js safe Cleared by Jev triage; no further analysis needed
dist/webapi/lib/iv.js safe Cleared by Jev triage; no further analysis needed
dist/webapi/lib/jwk_to_key.js safe No malicious patterns detected; the code performs standard JWK to WebCrypto key conversion without network, filesystem, process, or dynamic execution behavior.
dist/webapi/lib/jwt_claims_set.js safe No malicious patterns detected; the file implements standard JWT claim validation and building logic without any exfiltration, obfuscation, process spawning, or filesystem access.
dist/webapi/lib/key_to_jwk.js safe No malicious patterns detected; the code performs standard key-to-JWK conversion without exfiltration, obfuscation, or suspicious behavior.
dist/webapi/lib/normalize_key.js safe No malicious patterns detected; the code is a standard JOSE key normalization utility for converting JWK/KeyObject/CryptoKey inputs into CryptoKey objects.
dist/webapi/lib/pbes2kw.js safe No malicious patterns detected; the code implements standard PBES2 key derivation and AES key wrapping using Web Crypto APIs without external communication or suspicious behavior.
dist/webapi/lib/private_symbols.js safe Cleared by Jev triage; no further analysis needed
dist/webapi/lib/rsaes.js safe Cleared by Jev triage; no further analysis needed
dist/webapi/lib/sign.js safe No malicious patterns detected; the code implements standard Web Crypto signing using imported helper functions without any exfiltration, obfuscation, or suspicious behavior.
dist/webapi/lib/subtle_dsa.js safe Cleared by Jev triage; no further analysis needed
dist/webapi/lib/validate_algorithms.js safe Cleared by Jev triage; no further analysis needed
dist/webapi/lib/validate_crit.js safe Cleared by Jev triage; no further analysis needed
dist/webapi/lib/verify.js safe No malicious patterns detected; the code is a standard cryptographic signature verification function using the WebCrypto API with no suspicious behavior.
dist/webapi/util/base64url.js safe Cleared by Jev triage; no further analysis needed
dist/webapi/util/decode_jwt.js safe The decodeJwt function performs standard JWT payload decoding and validation without any malicious patterns, network activity, credential access, or dynamic code execution.
dist/webapi/util/decode_protected_header.js safe The file contains legitimate JWT protected header decoding logic with no malicious patterns such as exfiltration, dynamic code execution, or process spawning.
dist/webapi/util/errors.js safe Cleared by Jev triage; no further analysis needed

Affected version ranges

None of the 2 scanned versions of jose are flagged high or critical. The latest scanned version, 6.2.12, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

4.15.96.2.12
VersionsVerdictCountRangeTop findings
6.2.1 โ€“ 6.2.12 Not scanned 2 >=6.2.1 <=6.2.12
6.1.3 No issues 1 6.1.3
5.10.0 Not scanned 1 5.10.0
4.15.9 Needs review 1 4.15.9 Insecure JWT implementation (algorithm: none); Missing signature verification

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of jose

VersionVerdictFilesScanned
6.1.3 No issues 66 Oct 4, 2026
4.15.9 Needs review 246 Oct 6, 2026

Frequently asked questions

Is jose safe to use?

Our AI source review of jose@6.1.3 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does jose contain malware?

No malware was identified in jose@6.1.3 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was jose checked?

Togoder Security downloaded the published npm package and had an AI model read its 66 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan jose together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in jose@6.1.3, cost nothing.

Related security reports