Summary
Togoder Security scanned the npm package ox@0.9.6 on Oct 4, 2026. An AI review of 331 source files produced 2 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings 2
Cryptographic Practice
NPS-247B20285B36
The sign function normalizes the ECDSA 's' value to low-S form. This is correct and secure but differs from some external expectations if callers assume the WebCrypto signature format verbatim.
weak randomness
NPS-C52ADA31D27E
The uid function uses Math.random() for generating identifiers, which is not cryptographically secure. If these IDs are used for security-sensitive purposes (e.g., session tokens, password reset tokens), they could be predictable. However, this is a common pattern for non-security-related unique IDs and does not indicate malicious intent.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| _cjs/core/Abi.js | safe | No malicious patterns detected |
| _cjs/core/AbiConstructor.js | safe | No malicious patterns detected; the file is a normal Ethereum ABI constructor codec with no network, filesystem, process, or dynamic code execution behavior. |
| _cjs/core/AbiError.js | safe | No malicious patterns detected; the file is a standard Ethereum ABI error encoding/decoding utility with no network, filesystem, process, or dynamic code execution concerns. |
| _cjs/core/AbiEvent.js | safe | No malicious patterns detected; the code performs Ethereum ABI event encoding/decoding using standard require statements and no network, filesystem, process, or dynamic execution activities. |
| _cjs/core/AbiFunction.js | safe | No malicious patterns detected |
| _cjs/core/AbiItem.js | safe | No malicious patterns detected; the code is a standard ABI utility module with no network, filesystem, process execution, or obfuscation concerns. |
| _cjs/core/AbiParameters.js | safe | No malicious patterns detected |
| _cjs/core/AccessList.js | safe | No malicious patterns detected; the code only performs local validation and transformation of Ethereum access list structures. |
| _cjs/core/AccountProof.js | safe | No malicious patterns detected |
| _cjs/core/Address.js | safe | No malicious patterns detected; the code is a legitimate Ethereum address utility for validation, checksumming, and comparison. |
| _cjs/core/AesGcm.js | safe | No malicious patterns detected |
| _cjs/core/Authorization.js | safe | No malicious patterns detected; the file contains only pure data transformation and hashing utilities for EIP-7702 authorization objects. |
| _cjs/core/Base58.js | safe | Cleared by Jev triage; no further analysis needed |
| _cjs/core/Base64.js | safe | No malicious patterns detected; the code is a straightforward Base64 encoder/decoder with no network, filesystem, credential, or dynamic execution activity. |
| _cjs/core/BinaryStateTree.js | safe | No malicious patterns detected; the file implements a binary state tree using BLAKE3 hashing with no network, filesystem, process, or dynamic execution activity. |
| _cjs/core/Blobs.js | safe | No malicious patterns detected; the code implements Ethereum EIP-4844 blob/KZG utility functions with no exfiltration, credential harvesting, dynamic execution, or process spawning. |
| _cjs/core/Block.js | safe | No malicious patterns detected; the code only performs Ethereum block RPC serialization/deserialization using local hex and transaction utilities. |
| _cjs/core/BlockOverrides.js | safe | Cleared by Jev triage; no further analysis needed |
| _cjs/core/Bloom.js | safe | No malicious patterns detected; the code implements a standard Ethereum bloom filter check using only in-package modules and no network, filesystem, or dynamic execution capabilities. |
| _cjs/core/Bls.js | safe | No malicious patterns detected; code implements BLS signature cryptography using the @noble/curves library without any exfiltration, credential harvesting, obfuscation, or other suspicious behavior. |
| _cjs/core/BlsPoint.js | safe | Cleared by Jev triage; no further analysis needed |
| _cjs/core/Bytes.js | safe | No malicious patterns detected; the file is a standard utility library for byte/Uint8Array manipulation. |
| _cjs/core/Caches.js | safe | No malicious patterns detected |
| _cjs/core/ContractAddress.js | safe | The code implements standard Ethereum contract address derivation (CREATE/CREATE2) using well-known cryptographic libraries without any malicious patterns. |
| _cjs/core/Ed25519.js | safe | The code is a standard cryptographic utility for Ed25519 key generation, signing, and verification using the well-known @noble/curves library, with no malicious patterns detected. |
Show 306 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| _cjs/core/Ens.js | safe | No malicious patterns detected; the file implements ENS name normalization and hashing using only local crypto utilities and a standard normalization library. |
| _cjs/core/Errors.js | safe | No malicious patterns detected; the file is a standard error class implementation with no network, filesystem, or dynamic execution activity. |
| _cjs/core/Fee.js | safe | No malicious patterns detected |
| _cjs/core/Filter.js | safe | Cleared by Jev triage; no further analysis needed |
| _cjs/core/Hash.js | safe | The code is a simple cryptographic hash utility that delegates to well-known @noble/hashes functions and contains no malicious patterns. |
| _cjs/core/HdKey.js | safe | No malicious patterns detected; the code is a thin, standard wrapper around the @scure/bip32 library for HD key derivation. |
| _cjs/core/Hex.js | safe | No malicious patterns detected; this is a hexadecimal encoding/decoding utility with no network, filesystem, process, or dynamic code execution activity. |
| _cjs/core/Json.js | safe | No malicious patterns detected; the code only provides JSON parsing/stringifying with BigInt support. |
| _cjs/core/Keystore.js | safe | This is a legitimate Ethereum keystore encryption/decryption module using standard cryptographic primitives from @noble libraries, with no malicious patterns detected. |
| _cjs/core/Kzg.js | safe | No malicious patterns detected |
| _cjs/core/Log.js | safe | Cleared by Jev triage; no further analysis needed |
| _cjs/core/Mnemonic.js | safe | No malicious patterns detected |
| _cjs/core/P256.js | safe | No malicious patterns detected |
| _cjs/core/PersonalMessage.js | safe | No malicious patterns detected |
| _cjs/core/Provider.js | safe | No malicious patterns detected; the file only defines Ethereum provider error classes and utility functions for wrapping JSON-RPC providers. |
| _cjs/core/PublicKey.js | safe | No malicious patterns detected |
| _cjs/core/Rlp.js | safe | No malicious patterns detected; the code is a standard RLP encoding/decoding implementation with no exfiltration, credential harvesting, dynamic code execution, or process spawning. |
| _cjs/core/RpcRequest.js | safe | No malicious patterns detected; the code only creates JSON-RPC 2.0 request objects with no network, filesystem, process, or dynamic execution behavior. |
| _cjs/core/RpcResponse.js | safe | No malicious patterns detected |
| _cjs/core/RpcSchema.js | safe | No malicious patterns detected |
| _cjs/core/RpcTransport.js | safe | The code implements a standard HTTP-based RPC transport using fetch with timeout and error handling, and contains no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning. |
| _cjs/core/Secp256k1.js | safe | No malicious patterns detected; the code is a standard secp256k1 cryptographic wrapper with no exfiltration, obfuscation, or process execution. |
| _cjs/core/Signature.js | safe | No malicious patterns detected; the code is a standard Ethereum signature handling utility with no network, filesystem, process, or obfuscation concerns. |
| _cjs/core/Siwe.js | safe | No malicious patterns detected; the code is a standard Sign-In with Ethereum (SIWE) message parser and validator with no exfiltration, obfuscation, dynamic execution, or network activity. |
| _cjs/core/Solidity.js | safe | The code contains only Solidity type definitions and regex patterns with no malicious behavior. |
| _cjs/core/StateOverrides.js | safe | Cleared by Jev triage; no further analysis needed |
| _cjs/core/Transaction.js | safe | No malicious patterns detected |
| _cjs/core/TransactionEnvelope.js | safe | No malicious patterns detected; the file only defines custom error classes for transaction envelope validation. |
| _cjs/core/TransactionEnvelopeEip1559.js | safe | No malicious patterns detected |
| _cjs/core/TransactionEnvelopeEip2930.js | safe | No malicious patterns detected; the code is a standard Ethereum EIP-2930 transaction envelope implementation with no network, filesystem, process, or credential access. |
| _cjs/core/TransactionEnvelopeEip4844.js | safe | No malicious patterns detected; the file implements standard EIP-4844 transaction serialization/deserialization with no exfiltration, credential access, dynamic code execution, or process spawning. |
| _cjs/core/TransactionEnvelopeEip7702.js | safe | This is a legitimate Ethereum EIP-7702 transaction envelope serialization/deserialization module with no malicious patterns detected. |
| _cjs/core/TransactionEnvelopeLegacy.js | safe | No malicious patterns detected; the code implements standard Ethereum legacy transaction serialization and formatting with no network, filesystem, or process-related activity. |
| _cjs/core/TransactionReceipt.js | safe | No malicious patterns detected |
| _cjs/core/TransactionRequest.js | safe | No malicious patterns detected; the code is a straightforward Ethereum transaction request serializer that safely converts numeric fields to hex strings without any exfiltration, code execution, or system access. |
| _cjs/core/TypedData.js | safe | No malicious patterns detected; the code is a legitimate EIP-712 typed data implementation for Ethereum with no network, filesystem, process, or dynamic execution behavior. |
| _cjs/core/ValidatorData.js | safe | No malicious patterns detected |
| _cjs/core/Value.js | safe | No malicious patterns detected |
| _cjs/core/WebAuthnP256.js | safe | No malicious patterns detected; the code is a legitimate WebAuthn/P256 utility module with no exfiltration, credential harvesting, obfuscation, or process/network abuse. |
| _cjs/core/WebCryptoP256.js | safe | No malicious patterns detected; the code implements standard WebCrypto ECDSA/ECDH operations without exfiltration, process spawning, or dynamic execution. |
| _cjs/core/Withdrawal.js | safe | No malicious patterns detected; the code only performs straightforward type conversions for withdrawal data. |
| _cjs/core/X25519.js | safe | No malicious patterns detected; the file is a straightforward X25519 wrapper around @noble/curves with no network, filesystem, process, or dynamic code execution activity. |
| _cjs/core/internal/abi.js | safe | No malicious patterns detected |
| _cjs/core/internal/abiConstructor.js | safe | No malicious patterns detected; the file only contains a CommonJS export marker and a source map comment. |
| _cjs/core/internal/abiError.js | safe | No malicious patterns detected |
| _cjs/core/internal/abiEvent.js | safe | No malicious patterns detected |
| _cjs/core/internal/abiFunction.js | safe | No malicious patterns detected |
| _cjs/core/internal/abiItem.js | safe | No malicious patterns detected; the file contains legitimate ABI signature normalization and type validation logic for the viem Ethereum library. |
| _cjs/core/internal/abiParameters.js | safe | No malicious patterns detected |
| _cjs/core/internal/base58.js | safe | No malicious patterns detected; the file implements standard Base58 encoding without network, filesystem, process, or credential access. |
| _cjs/core/internal/bytes.js | safe | Cleared by Jev triage; no further analysis needed |
| _cjs/core/internal/cursor.js | safe | No malicious patterns detected; the code implements a binary cursor with bounds checking and recursion limits, and contains no network, filesystem, process execution, or obfuscated activity. |
| _cjs/core/internal/ens.js | safe | No malicious patterns detected |
| _cjs/core/internal/entropy.js | safe | No malicious patterns detected; the file only defines a simple module-level boolean and setter with no network, filesystem, process, or dynamic code execution activity. |
| _cjs/core/internal/errors.js | safe | Cleared by Jev triage; no further analysis needed |
| _cjs/core/internal/hdKey.js | safe | No malicious patterns detected; the code is a straightforward adapter that converts a scure HD key object into a local format using pure cryptographic operations with no network, filesystem, or process activity. |
| _cjs/core/internal/hex.js | safe | No malicious patterns detected; the code only provides hex string manipulation utilities. |
| _cjs/core/internal/lru.js | safe | No malicious patterns detected |
| _cjs/core/internal/mnemonic/wordlists.js | safe | No malicious patterns detected |
| _cjs/core/internal/promise.js | safe | Cleared by Jev triage; no further analysis needed |
| _cjs/core/internal/register.js | safe | No malicious patterns detected |
| _cjs/core/internal/rpcSchema.js | safe | This file is a generated TypeScript declaration stub with no executable logic other than the standard CommonJS module marker, and contains no malicious patterns. |
| _cjs/core/internal/rpcSchemas/eth.js | safe | No malicious patterns detected |
| _cjs/core/internal/rpcSchemas/wallet.js | safe | No malicious patterns detected |
| _cjs/core/internal/rpcTransport.js | safe | No malicious patterns detected; the file implements a straightforward JSON-RPC transport wrapper with no obfuscation, network exfiltration, process spawning, or filesystem manipulation. |
| _cjs/core/internal/types.js | safe | No malicious patterns detected |
| _cjs/core/internal/uid.js | safe | No malicious patterns detected; only a minor use of non-cryptographic randomness for ID generation. |
| _cjs/core/internal/webauthn.js | safe | No malicious patterns detected; the code performs standard WebAuthn credential parsing using cryptographic primitives from @noble/curves and the Web Crypto API. |
| _cjs/core/version.js | safe | No malicious patterns detected |
| _cjs/erc4337/EntryPoint.js | safe | No malicious patterns detected; the file only exports standard ERC-4337 EntryPoint ABIs and contract addresses. |
| _cjs/erc4337/RpcSchema.js | safe | No malicious patterns detected |
| _cjs/erc4337/UserOperation.js | safe | No malicious patterns detected; the code is a legitimate ERC-4337 UserOperation utility library with no network, filesystem, or process manipulation. |
| _cjs/erc4337/UserOperationGas.js | safe | The code performs straightforward conversion of ERC-4337 UserOperation gas fields between RPC and internal BigInt representations with no malicious patterns or security concerns. |
| _cjs/erc4337/UserOperationReceipt.js | safe | No malicious patterns detected; the code only performs data serialization/deserialization for ERC-4337 user operation receipts. |
| _cjs/erc4337/index.js | safe | No malicious patterns detected |
| _cjs/erc6492/SignatureErc6492.js | safe | No malicious patterns detected; the file implements ERC-6492 wrapped signature handling with static bytecode, ABI, and validation logic only. |
| _cjs/erc6492/index.js | safe | No malicious patterns detected |
| _cjs/erc8010/SignatureErc8010.js | safe | No malicious patterns detected |
| _cjs/erc8010/index.js | safe | No malicious patterns detected |
| _cjs/index.docs.js | safe | No malicious patterns detected; the file only re-exports modules from local index and ERC standard subdirectories with no runtime side effects or suspicious behavior. |
| _cjs/index.js | safe | No malicious patterns detected; the file is a standard CommonJS barrel export for the viem Ethereum library. |
| _cjs/trusted-setups/Paths.js | safe | No malicious patterns detected |
| _cjs/trusted-setups/index.js | safe | No malicious patterns detected |
| _cjs/trusted-setups/internal/paths.js | safe | The code simply resolves a file path relative to the module directory using Node.js path utilities, with no malicious patterns detected. |
| _cjs/version.js | safe | No malicious patterns detected |
| _cjs/window/index.js | safe | The file contains only standard CommonJS module boilerplate with no executable logic or malicious patterns. |
| _esm/core/Abi.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/AbiConstructor.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/AbiError.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/AbiEvent.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/AbiFunction.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/AbiItem.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/AbiParameters.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/AccessList.js | safe | No malicious patterns detected; the module only contains pure utility functions for Ethereum access list serialization with input validation. |
| _esm/core/AccountProof.js | safe | No malicious patterns detected |
| _esm/core/Address.js | safe | No malicious patterns detected; the file implements standard Ethereum address validation, checksumming, and ECDSA public key conversion using only internal imports and safe string/byte operations. |
| _esm/core/AesGcm.js | safe | No malicious patterns detected; the code implements standard AES-GCM encryption and PBKDF2 key derivation using the Web Crypto API without data exfiltration, dynamic execution, or process spawning. |
| _esm/core/Authorization.js | safe | No malicious patterns detected |
| _esm/core/Base58.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/Base64.js | safe | No malicious patterns detected in the Base64 encoding/decoding utility; it is a standard implementation with no external calls, code execution, or file system access. |
| _esm/core/BinaryStateTree.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/Blobs.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/Block.js | safe | No malicious patterns detected; the code is a straightforward Ethereum block serialization/deserialization utility with no network, filesystem, or process manipulation. |
| _esm/core/BlockOverrides.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/Bloom.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/Bls.js | safe | The code implements BLS12-381 cryptographic operations using the reputable @noble/curves library with no malicious patterns, external calls, or environment access. |
| _esm/core/BlsPoint.js | safe | No malicious patterns detected; the code only performs standard BLS point serialization and deserialization using the @noble/curves library. |
| _esm/core/Bytes.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/Caches.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/ContractAddress.js | safe | The file is a legitimate Ethereum contract address implementation using CREATE and CREATE2 computation with no malicious patterns detected. |
| _esm/core/Ed25519.js | safe | No malicious patterns detected; the code is a straightforward wrapper around @noble/curves Ed25519 utilities with no data exfiltration, credential harvesting, obfuscation, or other red flags. |
| _esm/core/Ens.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/Errors.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/Fee.js | safe | The file contains only an empty export and a source map reference, with no executable or suspicious code. |
| _esm/core/Filter.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/Hash.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/HdKey.js | safe | No malicious patterns detected in the HD key utility module; it only wraps @scure/bip32 for BIP-32 key derivation. |
| _esm/core/Hex.js | safe | No malicious patterns detected; the file contains standard hex encoding/decoding utilities with no network, filesystem, process, or dynamic code execution. |
| _esm/core/Json.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/Keystore.js | safe | The file implements standard Ethereum keystore encryption/decryption using well-known cryptographic libraries with no malicious patterns, exfiltration, or dynamic code execution. |
| _esm/core/Kzg.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/Log.js | safe | No malicious patterns detected |
| _esm/core/Mnemonic.js | safe | No malicious patterns detected; the file provides standard BIP39 mnemonic generation, validation, and HD key derivation using the audited @scure/bip39 library. |
| _esm/core/P256.js | safe | No malicious patterns detected; the code is a standard cryptographic utility module for P256 ECDSA operations with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior. |
| _esm/core/PersonalMessage.js | safe | The code is a clean implementation of ERC-191 personal message encoding and hashing with no malicious patterns. |
| _esm/core/Provider.js | safe | No malicious patterns detected; the file defines EIP-1193 provider error classes, an event emitter factory, and error parsing logic without any data exfiltration, credential harvesting, obfuscation, or code execution risks. |
| _esm/core/PublicKey.js | safe | No malicious patterns detected; this is a legitimate elliptic curve public key utility module with no network, filesystem, process, or dynamic code execution concerns. |
| _esm/core/Rlp.js | safe | The RLP encoding/decoding module contains only pure data transformation logic with no network, filesystem, process, or dynamic code execution patterns. |
| _esm/core/RpcRequest.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/RpcResponse.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/RpcSchema.js | safe | No malicious patterns detected |
| _esm/core/RpcTransport.js | safe | No malicious patterns detected; the code is a standard HTTP JSON-RPC transport implementation with no data exfiltration, credential harvesting, obfuscation, process spawning, or other suspicious behavior. |
| _esm/core/Secp256k1.js | safe | No malicious patterns detected; the code is a legitimate secp256k1 cryptographic utility module with no data exfiltration, credential harvesting, obfuscation, or other suspicious behavior. |
| _esm/core/Signature.js | safe | No malicious patterns detected; the code is a standard Ethereum signature serialization/deserialization utility using secp256k1 with no network, filesystem, process, or dynamic code execution. |
| _esm/core/Siwe.js | safe | No malicious patterns detected; the code implements EIP-4361 (Sign-In with Ethereum) message creation, parsing, and validation with no network, filesystem, process, or dynamic execution behavior. |
| _esm/core/Solidity.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/StateOverrides.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/Transaction.js | safe | No malicious patterns detected; the file only performs Ethereum transaction serialization/deserialization and type conversions. |
| _esm/core/TransactionEnvelope.js | safe | No malicious patterns detected; the code only defines error classes for Ethereum transaction validation with no network, filesystem, or dynamic execution behavior. |
| _esm/core/TransactionEnvelopeEip1559.js | safe | No malicious patterns detected; the code is a standard EIP-1559 transaction envelope implementation with only local cryptographic and serialization logic. |
| _esm/core/TransactionEnvelopeEip2930.js | safe | No malicious patterns detected; the code is a standard EIP-2930 transaction envelope implementation with no network, filesystem, process, or credential access. |
| _esm/core/TransactionEnvelopeEip4844.js | safe | No malicious patterns detected |
| _esm/core/TransactionEnvelopeEip7702.js | safe | No malicious patterns detected |
| _esm/core/TransactionEnvelopeLegacy.js | safe | No malicious patterns detected; the file implements Ethereum legacy transaction serialization/deserialization logic without external data exfiltration, code execution, or suspicious behavior. |
| _esm/core/TransactionReceipt.js | safe | No malicious patterns detected; the code is a pure data transformation module for Ethereum transaction receipts with no network, filesystem, or dynamic execution behavior. |
| _esm/core/TransactionRequest.js | safe | No malicious patterns detected; the code is a straightforward utility that converts Ethereum transaction request objects to RPC format using hex encoding and authorization list conversion. |
| _esm/core/TypedData.js | safe | No malicious patterns detected; the file implements standard EIP-712 typed data hashing and validation with no network, filesystem, process, or dynamic code execution activity. |
| _esm/core/ValidatorData.js | safe | No malicious patterns detected; the file only implements ERC-191 validator data encoding and hashing using local imports. |
| _esm/core/Value.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/WebAuthnP256.js | safe | No malicious patterns detected; the code is a standard WebAuthn P256 implementation with no exfiltration, credential harvesting, obfuscation, or suspicious runtime behavior. |
| _esm/core/WebCryptoP256.js | safe | No malicious patterns detected |
| _esm/core/Withdrawal.js | safe | No malicious patterns detected |
| _esm/core/X25519.js | safe | The code implements X25519 cryptographic utilities using the reputable @noble/curves library with no malicious patterns, network activity, or suspicious behavior. |
| _esm/core/internal/abi.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/internal/abiConstructor.js | safe | The file contains only an empty export and a source map comment; no executable or malicious code is present. |
| _esm/core/internal/abiError.js | safe | No malicious patterns detected |
| _esm/core/internal/abiEvent.js | safe | The file contains only an empty export statement and a source map reference, with no executable code or malicious patterns. |
| _esm/core/internal/abiFunction.js | safe | No malicious patterns detected |
| _esm/core/internal/abiItem.js | safe | No malicious patterns detected; the code is legitimate ABI signature normalization and type checking logic. |
| _esm/core/internal/abiParameters.js | safe | This is a legitimate ABI parameter encoding/decoding module for Ethereum (likely viem) with no malicious patterns, external calls, or security concerns. |
| _esm/core/internal/base58.js | safe | No malicious patterns detected |
| _esm/core/internal/bytes.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/internal/cursor.js | safe | No malicious patterns detected; the code is a well-structured binary cursor utility with only defensive error handling and no network, filesystem, process, or dynamic execution activity. |
| _esm/core/internal/ens.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/internal/entropy.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/internal/errors.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/internal/hdKey.js | safe | No malicious patterns detected |
| _esm/core/internal/hex.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/internal/lru.js | safe | No malicious patterns detected; the code is a standard LRU cache implementation with no network, filesystem, process, environment, or obfuscated behavior. |
| _esm/core/internal/mnemonic/wordlists.js | safe | No malicious patterns detected; the file only re-exports standard BIP39 wordlists from the @scure/bip39 package. |
| _esm/core/internal/promise.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/internal/register.js | safe | No malicious patterns detected |
| _esm/core/internal/rpcSchema.js | safe | No malicious patterns detected; the file contains only an empty export and a source map reference. |
| _esm/core/internal/rpcSchemas/eth.js | safe | No malicious patterns detected |
| _esm/core/internal/rpcSchemas/wallet.js | safe | The file contains only an empty export statement and a source map reference, with no executable or suspicious code. |
| _esm/core/internal/rpcTransport.js | safe | No malicious patterns detected; the file implements a simple RPC transport wrapper with no network, filesystem, process, or dynamic execution concerns. |
| _esm/core/internal/types.js | safe | No malicious patterns detected |
| _esm/core/internal/uid.js | safe | No malicious patterns detected |
| _esm/core/internal/webauthn.js | safe | The code performs legitimate WebAuthn P-256 public key parsing and ASN.1 signature normalization without any malicious patterns such as exfiltration, obfuscation, or unauthorized system access. |
| _esm/core/version.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/erc4337/EntryPoint.js | safe | No malicious patterns detected |
| _esm/erc4337/RpcSchema.js | safe | No malicious patterns detected; the file contains only an empty export statement and a source map reference. |
| _esm/erc4337/UserOperation.js | safe | No malicious patterns detected; the file contains only ERC-4337 UserOperation utility functions for encoding, hashing, and converting user operations. |
| _esm/erc4337/UserOperationGas.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/erc4337/UserOperationReceipt.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/erc4337/index.js | safe | No malicious patterns detected |
| _esm/erc6492/SignatureErc6492.js | safe | No malicious patterns detected; the file implements standard ERC-6492 signature parsing and validation logic without any signs of data exfiltration, credential harvesting, obfuscation, or unauthorized system interaction. |
| _esm/erc6492/index.js | safe | No malicious patterns detected; file only re-exports an ERC-6492 signature utility module with inline documentation. |
| _esm/erc8010/SignatureErc8010.js | safe | The code implements ERC-8010 wrapped signature parsing and validation using only internal cryptographic utilities and ABI encoding with no network, file system, process, or dynamic execution behavior. |
| _esm/erc8010/index.js | safe | No malicious patterns detected; the file is a simple re-export module for ERC-8010 signature utilities with only documentation comments. |
| _esm/index.docs.js | safe | No malicious patterns detected |
| _esm/trusted-setups/Paths.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/trusted-setups/index.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/trusted-setups/internal/paths.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/version.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/window/index.js | safe | No malicious patterns detected |
| core/Abi.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/AbiConstructor.ts | safe | No malicious patterns detected; the code implements ABI encoding/decoding utilities with no network, filesystem, process execution, or obfuscation concerns. |
| core/AbiError.ts | safe | No malicious patterns detected; this is a standard ABI error encoding/decoding utility with no network, filesystem, process, or dynamic execution behavior. |
| core/AbiEvent.ts | safe | No malicious patterns detected in this ABI event encoding/decoding module for the 'ox' library. |
| core/AbiFunction.ts | safe | No malicious patterns detected; this is a legitimate ABI encoding/decoding utility with only standard type-level and pure-function operations. |
| core/AbiItem.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/AbiParameters.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/AccessList.ts | safe | No malicious patterns detected |
| core/AccountProof.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/Address.ts | safe | No malicious patterns detected; the file contains standard Ethereum address validation, checksum, and conversion utilities with no data exfiltration, code execution, or network/file system access. |
| core/AesGcm.ts | safe | No malicious patterns detected; the code is a straightforward AES-GCM encryption/decryption utility using the Web Crypto API with PBKDF2 key derivation. |
| core/Authorization.ts | safe | No malicious patterns detected in the Authorization.ts file; it contains only legitimate EIP-7702 authorization encoding/decoding utilities. |
| core/Base58.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/Base64.ts | safe | No malicious patterns detected; the code is a clean implementation of Base64 encoding/decoding with no network, filesystem, or dynamic code execution. |
| core/BinaryStateTree.ts | safe | No malicious patterns detected; the code is a legitimate Binary State Tree implementation using Blake3 hashing with no network, filesystem, or process interactions. |
| core/Blobs.ts | safe | The code is a standard implementation of EIP-4844 blob utilities using KZG commitments and versioned hashes with no malicious patterns detected. |
| core/Block.ts | safe | No malicious patterns detected; the file contains only type definitions and pure data transformation functions for Ethereum block objects with no network, filesystem, process execution, or obfuscation. |
| core/BlockOverrides.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/Bloom.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/Bls.ts | safe | No malicious patterns detected; the code is a legitimate BLS12-381 cryptographic utility library that only performs local cryptographic operations without network, filesystem, or process interactions. |
| core/BlsPoint.ts | safe | No malicious patterns detected; the code is a legitimate BLS point conversion utility using @noble/curves. |
| core/Bytes.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/Caches.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/ContractAddress.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/Ed25519.ts | safe | No malicious patterns detected; the file is a straightforward wrapper around @noble/curves Ed25519 utilities with no data exfiltration, credential harvesting, dynamic code execution, or install-time behavior. |
| core/Ens.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/Errors.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/Fee.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/Filter.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/Hash.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/HdKey.ts | safe | No malicious patterns detected; the code is a standard HD key utility wrapper around @scure/bip32. |
| core/Hex.ts | safe | This Hex utility module contains only pure encoding/decoding functions with no network, filesystem, process execution, or obfuscated code patterns. |
| core/Json.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/Keystore.ts | safe | This is a legitimate Ethereum keystore implementation using standard cryptographic primitives with no malicious patterns detected. |
| core/Kzg.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/Log.ts | safe | No malicious patterns detected; the file contains only type definitions and pure data transformation functions for Ethereum log objects with no network, filesystem, process, or dynamic code execution behavior. |
| core/Mnemonic.ts | safe | No malicious patterns detected; the code is a straightforward BIP39 mnemonic and HD key utility library with no exfiltration, dynamic execution, or suspicious behavior. |
| core/P256.ts | safe | No malicious patterns detected; the code is a standard cryptographic wrapper around @noble/curves for P256 ECDSA operations without any exfiltration, obfuscation, or process execution. |
| core/PersonalMessage.ts | safe | No malicious patterns detected; the code implements ERC-191 personal message encoding and hashing using only local cryptographic utilities. |
| core/Provider.ts | safe | No malicious patterns detected |
| core/PublicKey.ts | safe | No malicious patterns detected; this is a standard elliptic curve public key utility module for the ox library with pure parsing, validation, and serialization logic. |
| core/Rlp.ts | safe | No malicious patterns detected; the file implements standard RLP encoding/decoding with no network, filesystem, process, or dynamic code execution concerns. |
| core/RpcRequest.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/RpcResponse.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/RpcSchema.ts | safe | This file is a purely type-level TypeScript RPC schema definition with no runtime logic, network calls, filesystem access, or malicious patterns. |
| core/RpcTransport.ts | safe | No malicious patterns detected; the file implements a standard HTTP JSON-RPC transport client with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior. |
| core/Secp256k1.ts | safe | No malicious patterns detected; the code is a standard secp256k1 cryptographic utility library with no exfiltration, obfuscation, or suspicious behavior. |
| core/Signature.ts | safe | No malicious patterns detected; this is a legitimate ECDSA signature utility module with standard cryptographic operations and no network, filesystem, or process-spawning code. |
| core/Siwe.ts | safe | No malicious patterns detected; the code implements EIP-4361 SIWE message creation, parsing, and validation with standard input validation and no network, filesystem, or process activity. |
| core/Solidity.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/StateOverrides.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/Transaction.ts | safe | No malicious patterns detected; the code only provides pure type definitions and conversion helpers for Ethereum transactions with no network, filesystem, process, or dynamic code execution activity. |
| core/TransactionEnvelope.ts | safe | No malicious patterns detected |
| core/TransactionEnvelopeEip1559.ts | safe | No malicious patterns detected; the file is a legitimate EIP-1559 transaction envelope implementation with no data exfiltration, credential harvesting, obfuscated code, or any other suspicious behavior. |
| core/TransactionEnvelopeEip2930.ts | safe | No malicious patterns detected |
| core/TransactionEnvelopeEip4844.ts | safe | No malicious patterns detected: the file implements EIP-4844 transaction handling with no network, filesystem, process, or dynamic code execution concerns. |
| core/TransactionEnvelopeEip7702.ts | safe | No malicious patterns detected |
| core/TransactionEnvelopeLegacy.ts | safe | This is a legitimate Ethereum legacy transaction envelope implementation with no malicious patterns, exfiltration, dynamic code execution, or suspicious behavior. |
| core/TransactionReceipt.ts | safe | No malicious patterns detected; the file contains only type definitions and data conversion utilities for Ethereum transaction receipts with no network, filesystem, process, or dynamic code execution activity. |
| core/TransactionRequest.ts | safe | No malicious patterns detected |
| core/TypedData.ts | safe | No malicious patterns detected; the code implements standard EIP-712 typed data hashing/encoding without any exfiltration, dynamic execution, or process spawning. |
| core/ValidatorData.ts | safe | No malicious patterns detected |
| core/Value.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/WebAuthnP256.ts | safe | No malicious patterns detected; this is a legitimate WebAuthn P256 library implementation from the 'ox' package. |
| core/WebCryptoP256.ts | safe | No malicious patterns detected; the code is a legitimate WebCrypto P-256 ECDSA/ECDH wrapper with no exfiltration, obfuscation, or suspicious behavior. |
| core/Withdrawal.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/X25519.ts | safe | No malicious patterns detected |
| core/internal/abi.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/abiConstructor.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/abiError.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/abiEvent.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/abiFunction.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/abiItem.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/abiParameters.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/base58.ts | safe | The code implements standard Base58 encoding with no network, filesystem, process, or dynamic execution capabilities, and contains no malicious patterns. |
| core/internal/bytes.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/cursor.ts | safe | No malicious patterns detected; the code is a well-structured binary cursor utility with no network, filesystem, process, or dynamic execution activity. |
| core/internal/ens.ts | safe | No malicious patterns detected; the code implements ENS DNS packet encoding and labelhash wrapping/unwrapping without external calls, dynamic execution, or filesystem access. |
| core/internal/entropy.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/errors.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/hdKey.ts | safe | No malicious patterns detected; the code is a straightforward adapter for HD key derivation with no network, filesystem, process, or dynamic execution activity. |
| core/internal/hex.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/lru.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/mnemonic/wordlists.ts | safe | This file only re-exports standard BIP39 wordlists from the @scure/bip39 package and contains no malicious patterns. |
| core/internal/promise.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/register.ts | safe | No malicious patterns detected |
| core/internal/rpcSchema.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/rpcSchemas/eth.ts | safe | This file contains only TypeScript type definitions for Ethereum JSON-RPC methods with no executable code, network calls, filesystem access, or other malicious patterns. |
| core/internal/rpcSchemas/wallet.ts | safe | No malicious patterns detected; the file only contains TypeScript type definitions for Ethereum wallet JSON-RPC methods with no runtime code, network calls, file access, or dynamic execution. |
| core/internal/rpcTransport.ts | safe | No malicious patterns detected; the code defines a standard JSON-RPC transport wrapper without any exfiltration, dynamic execution, filesystem, or process-spawning behavior. |
| core/internal/types.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/uid.ts | safe | The code is a simple UID generator using Math.random and does not contain any malicious patterns or security concerns. |
| core/internal/webauthn.ts | safe | No malicious patterns detected; the file contains only WebAuthn type definitions and cryptographic parsing utilities with no data exfiltration, credential harvesting, obfuscation, or network/file/process manipulation. |
| core/version.ts | safe | Cleared by Jev triage; no further analysis needed |
| erc4337/EntryPoint.ts | safe | No malicious patterns detected |
| erc4337/RpcSchema.ts | safe | No malicious patterns detected |
| erc4337/UserOperation.ts | safe | This file is a legitimate ERC-4337 UserOperation TypeScript module containing only type definitions, encoding/decoding helpers for user operations, and no network, filesystem, process, or dynamic code execution patterns. |
| erc4337/UserOperationGas.ts | safe | Cleared by Jev triage; no further analysis needed |
| erc4337/UserOperationReceipt.ts | safe | Cleared by Jev triage; no further analysis needed |
| erc4337/index.ts | safe | This file contains only static ES module re-exports of ERC-4337 utility modules with no executable code, network activity, file system access, or other malicious patterns. |
| erc6492/SignatureErc6492.ts | safe | The code implements ERC-6492 signature wrapping/unwrapping and validation using only standard ABI encoding/decoding and hex utilities, with no network, filesystem, process, or dynamic execution behavior. |
| erc6492/index.ts | safe | No malicious patterns detected |
| erc8010/SignatureErc8010.ts | safe | Code implements ERC-8010 signature wrapping/unwrapping with only standard cryptographic and ABI operations, no malicious patterns detected. |
| erc8010/index.ts | safe | No malicious patterns detected in the ERC-8010 signature utility wrapper file. |
| index.docs.ts | safe | The file only contains standard re-export statements for documentation generation, with no malicious patterns detected. |
| trusted-setups/Paths.ts | safe | Cleared by Jev triage; no further analysis needed |
| trusted-setups/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| trusted-setups/internal/paths.ts | safe | Cleared by Jev triage; no further analysis needed |
| version.ts | safe | Cleared by Jev triage; no further analysis needed |
| window/index.ts | safe | No malicious patterns detected |
Affected version ranges
None of the 4 scanned versions of ox are flagged high or critical. The latest scanned version, 0.14.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 0.9.17 – 0.14.0 | Not scanned | 2 | >=0.9.17 <=0.14.0 | |
| 0.6.7 – 0.9.6 | No issues | 4 | >=0.6.7 <=0.9.6 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of ox
Frequently asked questions
Is ox safe to use?
Our AI source review of ox@0.9.6 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does ox contain malware?
No malware was identified in ox@0.9.6 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was ox checked?
Togoder Security downloaded the published npm package and had an AI model read its 331 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan ox together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in ox@0.9.6, cost nothing.