Togoder security

npm package security report

ox npm package: is it safe?

No malicious code found.

No issues Version 0.9.6 Files reviewed 331 Size 2.2 MB Scanned

Summary

Togoder Security scanned the npm package ox@0.9.6 on Oct 4, 2026. An AI review of 331 source files produced 2 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
2
low

Findings 2

low

Cryptographic Practice

NPS-247B20285B36

The sign function normalizes the ECDSA 's' value to low-S form. This is correct and secure but differs from some external expectations if callers assume the WebCrypto signature format verbatim.

_cjs/core/WebCryptoP256.js:68
low

weak randomness

NPS-C52ADA31D27E

The uid function uses Math.random() for generating identifiers, which is not cryptographically secure. If these IDs are used for security-sensitive purposes (e.g., session tokens, password reset tokens), they could be predictable. However, this is a common pattern for non-security-related unique IDs and does not indicate malicious intent.

_cjs/core/internal/uid.js:12

Files reviewed

FileVerdictWhat the reviewer saw
_cjs/core/Abi.js safe No malicious patterns detected
_cjs/core/AbiConstructor.js safe No malicious patterns detected; the file is a normal Ethereum ABI constructor codec with no network, filesystem, process, or dynamic code execution behavior.
_cjs/core/AbiError.js safe No malicious patterns detected; the file is a standard Ethereum ABI error encoding/decoding utility with no network, filesystem, process, or dynamic code execution concerns.
_cjs/core/AbiEvent.js safe No malicious patterns detected; the code performs Ethereum ABI event encoding/decoding using standard require statements and no network, filesystem, process, or dynamic execution activities.
_cjs/core/AbiFunction.js safe No malicious patterns detected
_cjs/core/AbiItem.js safe No malicious patterns detected; the code is a standard ABI utility module with no network, filesystem, process execution, or obfuscation concerns.
_cjs/core/AbiParameters.js safe No malicious patterns detected
_cjs/core/AccessList.js safe No malicious patterns detected; the code only performs local validation and transformation of Ethereum access list structures.
_cjs/core/AccountProof.js safe No malicious patterns detected
_cjs/core/Address.js safe No malicious patterns detected; the code is a legitimate Ethereum address utility for validation, checksumming, and comparison.
_cjs/core/AesGcm.js safe No malicious patterns detected
_cjs/core/Authorization.js safe No malicious patterns detected; the file contains only pure data transformation and hashing utilities for EIP-7702 authorization objects.
_cjs/core/Base58.js safe Cleared by Jev triage; no further analysis needed
_cjs/core/Base64.js safe No malicious patterns detected; the code is a straightforward Base64 encoder/decoder with no network, filesystem, credential, or dynamic execution activity.
_cjs/core/BinaryStateTree.js safe No malicious patterns detected; the file implements a binary state tree using BLAKE3 hashing with no network, filesystem, process, or dynamic execution activity.
_cjs/core/Blobs.js safe No malicious patterns detected; the code implements Ethereum EIP-4844 blob/KZG utility functions with no exfiltration, credential harvesting, dynamic execution, or process spawning.
_cjs/core/Block.js safe No malicious patterns detected; the code only performs Ethereum block RPC serialization/deserialization using local hex and transaction utilities.
_cjs/core/BlockOverrides.js safe Cleared by Jev triage; no further analysis needed
_cjs/core/Bloom.js safe No malicious patterns detected; the code implements a standard Ethereum bloom filter check using only in-package modules and no network, filesystem, or dynamic execution capabilities.
_cjs/core/Bls.js safe No malicious patterns detected; code implements BLS signature cryptography using the @noble/curves library without any exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
_cjs/core/BlsPoint.js safe Cleared by Jev triage; no further analysis needed
_cjs/core/Bytes.js safe No malicious patterns detected; the file is a standard utility library for byte/Uint8Array manipulation.
_cjs/core/Caches.js safe No malicious patterns detected
_cjs/core/ContractAddress.js safe The code implements standard Ethereum contract address derivation (CREATE/CREATE2) using well-known cryptographic libraries without any malicious patterns.
_cjs/core/Ed25519.js safe The code is a standard cryptographic utility for Ed25519 key generation, signing, and verification using the well-known @noble/curves library, with no malicious patterns detected.
Show 306 more files
FileVerdictWhat the reviewer saw
_cjs/core/Ens.js safe No malicious patterns detected; the file implements ENS name normalization and hashing using only local crypto utilities and a standard normalization library.
_cjs/core/Errors.js safe No malicious patterns detected; the file is a standard error class implementation with no network, filesystem, or dynamic execution activity.
_cjs/core/Fee.js safe No malicious patterns detected
_cjs/core/Filter.js safe Cleared by Jev triage; no further analysis needed
_cjs/core/Hash.js safe The code is a simple cryptographic hash utility that delegates to well-known @noble/hashes functions and contains no malicious patterns.
_cjs/core/HdKey.js safe No malicious patterns detected; the code is a thin, standard wrapper around the @scure/bip32 library for HD key derivation.
_cjs/core/Hex.js safe No malicious patterns detected; this is a hexadecimal encoding/decoding utility with no network, filesystem, process, or dynamic code execution activity.
_cjs/core/Json.js safe No malicious patterns detected; the code only provides JSON parsing/stringifying with BigInt support.
_cjs/core/Keystore.js safe This is a legitimate Ethereum keystore encryption/decryption module using standard cryptographic primitives from @noble libraries, with no malicious patterns detected.
_cjs/core/Kzg.js safe No malicious patterns detected
_cjs/core/Log.js safe Cleared by Jev triage; no further analysis needed
_cjs/core/Mnemonic.js safe No malicious patterns detected
_cjs/core/P256.js safe No malicious patterns detected
_cjs/core/PersonalMessage.js safe No malicious patterns detected
_cjs/core/Provider.js safe No malicious patterns detected; the file only defines Ethereum provider error classes and utility functions for wrapping JSON-RPC providers.
_cjs/core/PublicKey.js safe No malicious patterns detected
_cjs/core/Rlp.js safe No malicious patterns detected; the code is a standard RLP encoding/decoding implementation with no exfiltration, credential harvesting, dynamic code execution, or process spawning.
_cjs/core/RpcRequest.js safe No malicious patterns detected; the code only creates JSON-RPC 2.0 request objects with no network, filesystem, process, or dynamic execution behavior.
_cjs/core/RpcResponse.js safe No malicious patterns detected
_cjs/core/RpcSchema.js safe No malicious patterns detected
_cjs/core/RpcTransport.js safe The code implements a standard HTTP-based RPC transport using fetch with timeout and error handling, and contains no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning.
_cjs/core/Secp256k1.js safe No malicious patterns detected; the code is a standard secp256k1 cryptographic wrapper with no exfiltration, obfuscation, or process execution.
_cjs/core/Signature.js safe No malicious patterns detected; the code is a standard Ethereum signature handling utility with no network, filesystem, process, or obfuscation concerns.
_cjs/core/Siwe.js safe No malicious patterns detected; the code is a standard Sign-In with Ethereum (SIWE) message parser and validator with no exfiltration, obfuscation, dynamic execution, or network activity.
_cjs/core/Solidity.js safe The code contains only Solidity type definitions and regex patterns with no malicious behavior.
_cjs/core/StateOverrides.js safe Cleared by Jev triage; no further analysis needed
_cjs/core/Transaction.js safe No malicious patterns detected
_cjs/core/TransactionEnvelope.js safe No malicious patterns detected; the file only defines custom error classes for transaction envelope validation.
_cjs/core/TransactionEnvelopeEip1559.js safe No malicious patterns detected
_cjs/core/TransactionEnvelopeEip2930.js safe No malicious patterns detected; the code is a standard Ethereum EIP-2930 transaction envelope implementation with no network, filesystem, process, or credential access.
_cjs/core/TransactionEnvelopeEip4844.js safe No malicious patterns detected; the file implements standard EIP-4844 transaction serialization/deserialization with no exfiltration, credential access, dynamic code execution, or process spawning.
_cjs/core/TransactionEnvelopeEip7702.js safe This is a legitimate Ethereum EIP-7702 transaction envelope serialization/deserialization module with no malicious patterns detected.
_cjs/core/TransactionEnvelopeLegacy.js safe No malicious patterns detected; the code implements standard Ethereum legacy transaction serialization and formatting with no network, filesystem, or process-related activity.
_cjs/core/TransactionReceipt.js safe No malicious patterns detected
_cjs/core/TransactionRequest.js safe No malicious patterns detected; the code is a straightforward Ethereum transaction request serializer that safely converts numeric fields to hex strings without any exfiltration, code execution, or system access.
_cjs/core/TypedData.js safe No malicious patterns detected; the code is a legitimate EIP-712 typed data implementation for Ethereum with no network, filesystem, process, or dynamic execution behavior.
_cjs/core/ValidatorData.js safe No malicious patterns detected
_cjs/core/Value.js safe No malicious patterns detected
_cjs/core/WebAuthnP256.js safe No malicious patterns detected; the code is a legitimate WebAuthn/P256 utility module with no exfiltration, credential harvesting, obfuscation, or process/network abuse.
_cjs/core/WebCryptoP256.js safe No malicious patterns detected; the code implements standard WebCrypto ECDSA/ECDH operations without exfiltration, process spawning, or dynamic execution.
_cjs/core/Withdrawal.js safe No malicious patterns detected; the code only performs straightforward type conversions for withdrawal data.
_cjs/core/X25519.js safe No malicious patterns detected; the file is a straightforward X25519 wrapper around @noble/curves with no network, filesystem, process, or dynamic code execution activity.
_cjs/core/internal/abi.js safe No malicious patterns detected
_cjs/core/internal/abiConstructor.js safe No malicious patterns detected; the file only contains a CommonJS export marker and a source map comment.
_cjs/core/internal/abiError.js safe No malicious patterns detected
_cjs/core/internal/abiEvent.js safe No malicious patterns detected
_cjs/core/internal/abiFunction.js safe No malicious patterns detected
_cjs/core/internal/abiItem.js safe No malicious patterns detected; the file contains legitimate ABI signature normalization and type validation logic for the viem Ethereum library.
_cjs/core/internal/abiParameters.js safe No malicious patterns detected
_cjs/core/internal/base58.js safe No malicious patterns detected; the file implements standard Base58 encoding without network, filesystem, process, or credential access.
_cjs/core/internal/bytes.js safe Cleared by Jev triage; no further analysis needed
_cjs/core/internal/cursor.js safe No malicious patterns detected; the code implements a binary cursor with bounds checking and recursion limits, and contains no network, filesystem, process execution, or obfuscated activity.
_cjs/core/internal/ens.js safe No malicious patterns detected
_cjs/core/internal/entropy.js safe No malicious patterns detected; the file only defines a simple module-level boolean and setter with no network, filesystem, process, or dynamic code execution activity.
_cjs/core/internal/errors.js safe Cleared by Jev triage; no further analysis needed
_cjs/core/internal/hdKey.js safe No malicious patterns detected; the code is a straightforward adapter that converts a scure HD key object into a local format using pure cryptographic operations with no network, filesystem, or process activity.
_cjs/core/internal/hex.js safe No malicious patterns detected; the code only provides hex string manipulation utilities.
_cjs/core/internal/lru.js safe No malicious patterns detected
_cjs/core/internal/mnemonic/wordlists.js safe No malicious patterns detected
_cjs/core/internal/promise.js safe Cleared by Jev triage; no further analysis needed
_cjs/core/internal/register.js safe No malicious patterns detected
_cjs/core/internal/rpcSchema.js safe This file is a generated TypeScript declaration stub with no executable logic other than the standard CommonJS module marker, and contains no malicious patterns.
_cjs/core/internal/rpcSchemas/eth.js safe No malicious patterns detected
_cjs/core/internal/rpcSchemas/wallet.js safe No malicious patterns detected
_cjs/core/internal/rpcTransport.js safe No malicious patterns detected; the file implements a straightforward JSON-RPC transport wrapper with no obfuscation, network exfiltration, process spawning, or filesystem manipulation.
_cjs/core/internal/types.js safe No malicious patterns detected
_cjs/core/internal/uid.js safe No malicious patterns detected; only a minor use of non-cryptographic randomness for ID generation.
_cjs/core/internal/webauthn.js safe No malicious patterns detected; the code performs standard WebAuthn credential parsing using cryptographic primitives from @noble/curves and the Web Crypto API.
_cjs/core/version.js safe No malicious patterns detected
_cjs/erc4337/EntryPoint.js safe No malicious patterns detected; the file only exports standard ERC-4337 EntryPoint ABIs and contract addresses.
_cjs/erc4337/RpcSchema.js safe No malicious patterns detected
_cjs/erc4337/UserOperation.js safe No malicious patterns detected; the code is a legitimate ERC-4337 UserOperation utility library with no network, filesystem, or process manipulation.
_cjs/erc4337/UserOperationGas.js safe The code performs straightforward conversion of ERC-4337 UserOperation gas fields between RPC and internal BigInt representations with no malicious patterns or security concerns.
_cjs/erc4337/UserOperationReceipt.js safe No malicious patterns detected; the code only performs data serialization/deserialization for ERC-4337 user operation receipts.
_cjs/erc4337/index.js safe No malicious patterns detected
_cjs/erc6492/SignatureErc6492.js safe No malicious patterns detected; the file implements ERC-6492 wrapped signature handling with static bytecode, ABI, and validation logic only.
_cjs/erc6492/index.js safe No malicious patterns detected
_cjs/erc8010/SignatureErc8010.js safe No malicious patterns detected
_cjs/erc8010/index.js safe No malicious patterns detected
_cjs/index.docs.js safe No malicious patterns detected; the file only re-exports modules from local index and ERC standard subdirectories with no runtime side effects or suspicious behavior.
_cjs/index.js safe No malicious patterns detected; the file is a standard CommonJS barrel export for the viem Ethereum library.
_cjs/trusted-setups/Paths.js safe No malicious patterns detected
_cjs/trusted-setups/index.js safe No malicious patterns detected
_cjs/trusted-setups/internal/paths.js safe The code simply resolves a file path relative to the module directory using Node.js path utilities, with no malicious patterns detected.
_cjs/version.js safe No malicious patterns detected
_cjs/window/index.js safe The file contains only standard CommonJS module boilerplate with no executable logic or malicious patterns.
_esm/core/Abi.js safe Cleared by Jev triage; no further analysis needed
_esm/core/AbiConstructor.js safe Cleared by Jev triage; no further analysis needed
_esm/core/AbiError.js safe Cleared by Jev triage; no further analysis needed
_esm/core/AbiEvent.js safe Cleared by Jev triage; no further analysis needed
_esm/core/AbiFunction.js safe Cleared by Jev triage; no further analysis needed
_esm/core/AbiItem.js safe Cleared by Jev triage; no further analysis needed
_esm/core/AbiParameters.js safe Cleared by Jev triage; no further analysis needed
_esm/core/AccessList.js safe No malicious patterns detected; the module only contains pure utility functions for Ethereum access list serialization with input validation.
_esm/core/AccountProof.js safe No malicious patterns detected
_esm/core/Address.js safe No malicious patterns detected; the file implements standard Ethereum address validation, checksumming, and ECDSA public key conversion using only internal imports and safe string/byte operations.
_esm/core/AesGcm.js safe No malicious patterns detected; the code implements standard AES-GCM encryption and PBKDF2 key derivation using the Web Crypto API without data exfiltration, dynamic execution, or process spawning.
_esm/core/Authorization.js safe No malicious patterns detected
_esm/core/Base58.js safe Cleared by Jev triage; no further analysis needed
_esm/core/Base64.js safe No malicious patterns detected in the Base64 encoding/decoding utility; it is a standard implementation with no external calls, code execution, or file system access.
_esm/core/BinaryStateTree.js safe Cleared by Jev triage; no further analysis needed
_esm/core/Blobs.js safe Cleared by Jev triage; no further analysis needed
_esm/core/Block.js safe No malicious patterns detected; the code is a straightforward Ethereum block serialization/deserialization utility with no network, filesystem, or process manipulation.
_esm/core/BlockOverrides.js safe Cleared by Jev triage; no further analysis needed
_esm/core/Bloom.js safe Cleared by Jev triage; no further analysis needed
_esm/core/Bls.js safe The code implements BLS12-381 cryptographic operations using the reputable @noble/curves library with no malicious patterns, external calls, or environment access.
_esm/core/BlsPoint.js safe No malicious patterns detected; the code only performs standard BLS point serialization and deserialization using the @noble/curves library.
_esm/core/Bytes.js safe Cleared by Jev triage; no further analysis needed
_esm/core/Caches.js safe Cleared by Jev triage; no further analysis needed
_esm/core/ContractAddress.js safe The file is a legitimate Ethereum contract address implementation using CREATE and CREATE2 computation with no malicious patterns detected.
_esm/core/Ed25519.js safe No malicious patterns detected; the code is a straightforward wrapper around @noble/curves Ed25519 utilities with no data exfiltration, credential harvesting, obfuscation, or other red flags.
_esm/core/Ens.js safe Cleared by Jev triage; no further analysis needed
_esm/core/Errors.js safe Cleared by Jev triage; no further analysis needed
_esm/core/Fee.js safe The file contains only an empty export and a source map reference, with no executable or suspicious code.
_esm/core/Filter.js safe Cleared by Jev triage; no further analysis needed
_esm/core/Hash.js safe Cleared by Jev triage; no further analysis needed
_esm/core/HdKey.js safe No malicious patterns detected in the HD key utility module; it only wraps @scure/bip32 for BIP-32 key derivation.
_esm/core/Hex.js safe No malicious patterns detected; the file contains standard hex encoding/decoding utilities with no network, filesystem, process, or dynamic code execution.
_esm/core/Json.js safe Cleared by Jev triage; no further analysis needed
_esm/core/Keystore.js safe The file implements standard Ethereum keystore encryption/decryption using well-known cryptographic libraries with no malicious patterns, exfiltration, or dynamic code execution.
_esm/core/Kzg.js safe Cleared by Jev triage; no further analysis needed
_esm/core/Log.js safe No malicious patterns detected
_esm/core/Mnemonic.js safe No malicious patterns detected; the file provides standard BIP39 mnemonic generation, validation, and HD key derivation using the audited @scure/bip39 library.
_esm/core/P256.js safe No malicious patterns detected; the code is a standard cryptographic utility module for P256 ECDSA operations with no data exfiltration, credential harvesting, obfuscation, or suspicious behavior.
_esm/core/PersonalMessage.js safe The code is a clean implementation of ERC-191 personal message encoding and hashing with no malicious patterns.
_esm/core/Provider.js safe No malicious patterns detected; the file defines EIP-1193 provider error classes, an event emitter factory, and error parsing logic without any data exfiltration, credential harvesting, obfuscation, or code execution risks.
_esm/core/PublicKey.js safe No malicious patterns detected; this is a legitimate elliptic curve public key utility module with no network, filesystem, process, or dynamic code execution concerns.
_esm/core/Rlp.js safe The RLP encoding/decoding module contains only pure data transformation logic with no network, filesystem, process, or dynamic code execution patterns.
_esm/core/RpcRequest.js safe Cleared by Jev triage; no further analysis needed
_esm/core/RpcResponse.js safe Cleared by Jev triage; no further analysis needed
_esm/core/RpcSchema.js safe No malicious patterns detected
_esm/core/RpcTransport.js safe No malicious patterns detected; the code is a standard HTTP JSON-RPC transport implementation with no data exfiltration, credential harvesting, obfuscation, process spawning, or other suspicious behavior.
_esm/core/Secp256k1.js safe No malicious patterns detected; the code is a legitimate secp256k1 cryptographic utility module with no data exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
_esm/core/Signature.js safe No malicious patterns detected; the code is a standard Ethereum signature serialization/deserialization utility using secp256k1 with no network, filesystem, process, or dynamic code execution.
_esm/core/Siwe.js safe No malicious patterns detected; the code implements EIP-4361 (Sign-In with Ethereum) message creation, parsing, and validation with no network, filesystem, process, or dynamic execution behavior.
_esm/core/Solidity.js safe Cleared by Jev triage; no further analysis needed
_esm/core/StateOverrides.js safe Cleared by Jev triage; no further analysis needed
_esm/core/Transaction.js safe No malicious patterns detected; the file only performs Ethereum transaction serialization/deserialization and type conversions.
_esm/core/TransactionEnvelope.js safe No malicious patterns detected; the code only defines error classes for Ethereum transaction validation with no network, filesystem, or dynamic execution behavior.
_esm/core/TransactionEnvelopeEip1559.js safe No malicious patterns detected; the code is a standard EIP-1559 transaction envelope implementation with only local cryptographic and serialization logic.
_esm/core/TransactionEnvelopeEip2930.js safe No malicious patterns detected; the code is a standard EIP-2930 transaction envelope implementation with no network, filesystem, process, or credential access.
_esm/core/TransactionEnvelopeEip4844.js safe No malicious patterns detected
_esm/core/TransactionEnvelopeEip7702.js safe No malicious patterns detected
_esm/core/TransactionEnvelopeLegacy.js safe No malicious patterns detected; the file implements Ethereum legacy transaction serialization/deserialization logic without external data exfiltration, code execution, or suspicious behavior.
_esm/core/TransactionReceipt.js safe No malicious patterns detected; the code is a pure data transformation module for Ethereum transaction receipts with no network, filesystem, or dynamic execution behavior.
_esm/core/TransactionRequest.js safe No malicious patterns detected; the code is a straightforward utility that converts Ethereum transaction request objects to RPC format using hex encoding and authorization list conversion.
_esm/core/TypedData.js safe No malicious patterns detected; the file implements standard EIP-712 typed data hashing and validation with no network, filesystem, process, or dynamic code execution activity.
_esm/core/ValidatorData.js safe No malicious patterns detected; the file only implements ERC-191 validator data encoding and hashing using local imports.
_esm/core/Value.js safe Cleared by Jev triage; no further analysis needed
_esm/core/WebAuthnP256.js safe No malicious patterns detected; the code is a standard WebAuthn P256 implementation with no exfiltration, credential harvesting, obfuscation, or suspicious runtime behavior.
_esm/core/WebCryptoP256.js safe No malicious patterns detected
_esm/core/Withdrawal.js safe No malicious patterns detected
_esm/core/X25519.js safe The code implements X25519 cryptographic utilities using the reputable @noble/curves library with no malicious patterns, network activity, or suspicious behavior.
_esm/core/internal/abi.js safe Cleared by Jev triage; no further analysis needed
_esm/core/internal/abiConstructor.js safe The file contains only an empty export and a source map comment; no executable or malicious code is present.
_esm/core/internal/abiError.js safe No malicious patterns detected
_esm/core/internal/abiEvent.js safe The file contains only an empty export statement and a source map reference, with no executable code or malicious patterns.
_esm/core/internal/abiFunction.js safe No malicious patterns detected
_esm/core/internal/abiItem.js safe No malicious patterns detected; the code is legitimate ABI signature normalization and type checking logic.
_esm/core/internal/abiParameters.js safe This is a legitimate ABI parameter encoding/decoding module for Ethereum (likely viem) with no malicious patterns, external calls, or security concerns.
_esm/core/internal/base58.js safe No malicious patterns detected
_esm/core/internal/bytes.js safe Cleared by Jev triage; no further analysis needed
_esm/core/internal/cursor.js safe No malicious patterns detected; the code is a well-structured binary cursor utility with only defensive error handling and no network, filesystem, process, or dynamic execution activity.
_esm/core/internal/ens.js safe Cleared by Jev triage; no further analysis needed
_esm/core/internal/entropy.js safe Cleared by Jev triage; no further analysis needed
_esm/core/internal/errors.js safe Cleared by Jev triage; no further analysis needed
_esm/core/internal/hdKey.js safe No malicious patterns detected
_esm/core/internal/hex.js safe Cleared by Jev triage; no further analysis needed
_esm/core/internal/lru.js safe No malicious patterns detected; the code is a standard LRU cache implementation with no network, filesystem, process, environment, or obfuscated behavior.
_esm/core/internal/mnemonic/wordlists.js safe No malicious patterns detected; the file only re-exports standard BIP39 wordlists from the @scure/bip39 package.
_esm/core/internal/promise.js safe Cleared by Jev triage; no further analysis needed
_esm/core/internal/register.js safe No malicious patterns detected
_esm/core/internal/rpcSchema.js safe No malicious patterns detected; the file contains only an empty export and a source map reference.
_esm/core/internal/rpcSchemas/eth.js safe No malicious patterns detected
_esm/core/internal/rpcSchemas/wallet.js safe The file contains only an empty export statement and a source map reference, with no executable or suspicious code.
_esm/core/internal/rpcTransport.js safe No malicious patterns detected; the file implements a simple RPC transport wrapper with no network, filesystem, process, or dynamic execution concerns.
_esm/core/internal/types.js safe No malicious patterns detected
_esm/core/internal/uid.js safe No malicious patterns detected
_esm/core/internal/webauthn.js safe The code performs legitimate WebAuthn P-256 public key parsing and ASN.1 signature normalization without any malicious patterns such as exfiltration, obfuscation, or unauthorized system access.
_esm/core/version.js safe Cleared by Jev triage; no further analysis needed
_esm/erc4337/EntryPoint.js safe No malicious patterns detected
_esm/erc4337/RpcSchema.js safe No malicious patterns detected; the file contains only an empty export statement and a source map reference.
_esm/erc4337/UserOperation.js safe No malicious patterns detected; the file contains only ERC-4337 UserOperation utility functions for encoding, hashing, and converting user operations.
_esm/erc4337/UserOperationGas.js safe Cleared by Jev triage; no further analysis needed
_esm/erc4337/UserOperationReceipt.js safe Cleared by Jev triage; no further analysis needed
_esm/erc4337/index.js safe No malicious patterns detected
_esm/erc6492/SignatureErc6492.js safe No malicious patterns detected; the file implements standard ERC-6492 signature parsing and validation logic without any signs of data exfiltration, credential harvesting, obfuscation, or unauthorized system interaction.
_esm/erc6492/index.js safe No malicious patterns detected; file only re-exports an ERC-6492 signature utility module with inline documentation.
_esm/erc8010/SignatureErc8010.js safe The code implements ERC-8010 wrapped signature parsing and validation using only internal cryptographic utilities and ABI encoding with no network, file system, process, or dynamic execution behavior.
_esm/erc8010/index.js safe No malicious patterns detected; the file is a simple re-export module for ERC-8010 signature utilities with only documentation comments.
_esm/index.docs.js safe No malicious patterns detected
_esm/trusted-setups/Paths.js safe Cleared by Jev triage; no further analysis needed
_esm/trusted-setups/index.js safe Cleared by Jev triage; no further analysis needed
_esm/trusted-setups/internal/paths.js safe Cleared by Jev triage; no further analysis needed
_esm/version.js safe Cleared by Jev triage; no further analysis needed
_esm/window/index.js safe No malicious patterns detected
core/Abi.ts safe Cleared by Jev triage; no further analysis needed
core/AbiConstructor.ts safe No malicious patterns detected; the code implements ABI encoding/decoding utilities with no network, filesystem, process execution, or obfuscation concerns.
core/AbiError.ts safe No malicious patterns detected; this is a standard ABI error encoding/decoding utility with no network, filesystem, process, or dynamic execution behavior.
core/AbiEvent.ts safe No malicious patterns detected in this ABI event encoding/decoding module for the 'ox' library.
core/AbiFunction.ts safe No malicious patterns detected; this is a legitimate ABI encoding/decoding utility with only standard type-level and pure-function operations.
core/AbiItem.ts safe Cleared by Jev triage; no further analysis needed
core/AbiParameters.ts safe Cleared by Jev triage; no further analysis needed
core/AccessList.ts safe No malicious patterns detected
core/AccountProof.ts safe Cleared by Jev triage; no further analysis needed
core/Address.ts safe No malicious patterns detected; the file contains standard Ethereum address validation, checksum, and conversion utilities with no data exfiltration, code execution, or network/file system access.
core/AesGcm.ts safe No malicious patterns detected; the code is a straightforward AES-GCM encryption/decryption utility using the Web Crypto API with PBKDF2 key derivation.
core/Authorization.ts safe No malicious patterns detected in the Authorization.ts file; it contains only legitimate EIP-7702 authorization encoding/decoding utilities.
core/Base58.ts safe Cleared by Jev triage; no further analysis needed
core/Base64.ts safe No malicious patterns detected; the code is a clean implementation of Base64 encoding/decoding with no network, filesystem, or dynamic code execution.
core/BinaryStateTree.ts safe No malicious patterns detected; the code is a legitimate Binary State Tree implementation using Blake3 hashing with no network, filesystem, or process interactions.
core/Blobs.ts safe The code is a standard implementation of EIP-4844 blob utilities using KZG commitments and versioned hashes with no malicious patterns detected.
core/Block.ts safe No malicious patterns detected; the file contains only type definitions and pure data transformation functions for Ethereum block objects with no network, filesystem, process execution, or obfuscation.
core/BlockOverrides.ts safe Cleared by Jev triage; no further analysis needed
core/Bloom.ts safe Cleared by Jev triage; no further analysis needed
core/Bls.ts safe No malicious patterns detected; the code is a legitimate BLS12-381 cryptographic utility library that only performs local cryptographic operations without network, filesystem, or process interactions.
core/BlsPoint.ts safe No malicious patterns detected; the code is a legitimate BLS point conversion utility using @noble/curves.
core/Bytes.ts safe Cleared by Jev triage; no further analysis needed
core/Caches.ts safe Cleared by Jev triage; no further analysis needed
core/ContractAddress.ts safe Cleared by Jev triage; no further analysis needed
core/Ed25519.ts safe No malicious patterns detected; the file is a straightforward wrapper around @noble/curves Ed25519 utilities with no data exfiltration, credential harvesting, dynamic code execution, or install-time behavior.
core/Ens.ts safe Cleared by Jev triage; no further analysis needed
core/Errors.ts safe Cleared by Jev triage; no further analysis needed
core/Fee.ts safe Cleared by Jev triage; no further analysis needed
core/Filter.ts safe Cleared by Jev triage; no further analysis needed
core/Hash.ts safe Cleared by Jev triage; no further analysis needed
core/HdKey.ts safe No malicious patterns detected; the code is a standard HD key utility wrapper around @scure/bip32.
core/Hex.ts safe This Hex utility module contains only pure encoding/decoding functions with no network, filesystem, process execution, or obfuscated code patterns.
core/Json.ts safe Cleared by Jev triage; no further analysis needed
core/Keystore.ts safe This is a legitimate Ethereum keystore implementation using standard cryptographic primitives with no malicious patterns detected.
core/Kzg.ts safe Cleared by Jev triage; no further analysis needed
core/Log.ts safe No malicious patterns detected; the file contains only type definitions and pure data transformation functions for Ethereum log objects with no network, filesystem, process, or dynamic code execution behavior.
core/Mnemonic.ts safe No malicious patterns detected; the code is a straightforward BIP39 mnemonic and HD key utility library with no exfiltration, dynamic execution, or suspicious behavior.
core/P256.ts safe No malicious patterns detected; the code is a standard cryptographic wrapper around @noble/curves for P256 ECDSA operations without any exfiltration, obfuscation, or process execution.
core/PersonalMessage.ts safe No malicious patterns detected; the code implements ERC-191 personal message encoding and hashing using only local cryptographic utilities.
core/Provider.ts safe No malicious patterns detected
core/PublicKey.ts safe No malicious patterns detected; this is a standard elliptic curve public key utility module for the ox library with pure parsing, validation, and serialization logic.
core/Rlp.ts safe No malicious patterns detected; the file implements standard RLP encoding/decoding with no network, filesystem, process, or dynamic code execution concerns.
core/RpcRequest.ts safe Cleared by Jev triage; no further analysis needed
core/RpcResponse.ts safe Cleared by Jev triage; no further analysis needed
core/RpcSchema.ts safe This file is a purely type-level TypeScript RPC schema definition with no runtime logic, network calls, filesystem access, or malicious patterns.
core/RpcTransport.ts safe No malicious patterns detected; the file implements a standard HTTP JSON-RPC transport client with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior.
core/Secp256k1.ts safe No malicious patterns detected; the code is a standard secp256k1 cryptographic utility library with no exfiltration, obfuscation, or suspicious behavior.
core/Signature.ts safe No malicious patterns detected; this is a legitimate ECDSA signature utility module with standard cryptographic operations and no network, filesystem, or process-spawning code.
core/Siwe.ts safe No malicious patterns detected; the code implements EIP-4361 SIWE message creation, parsing, and validation with standard input validation and no network, filesystem, or process activity.
core/Solidity.ts safe Cleared by Jev triage; no further analysis needed
core/StateOverrides.ts safe Cleared by Jev triage; no further analysis needed
core/Transaction.ts safe No malicious patterns detected; the code only provides pure type definitions and conversion helpers for Ethereum transactions with no network, filesystem, process, or dynamic code execution activity.
core/TransactionEnvelope.ts safe No malicious patterns detected
core/TransactionEnvelopeEip1559.ts safe No malicious patterns detected; the file is a legitimate EIP-1559 transaction envelope implementation with no data exfiltration, credential harvesting, obfuscated code, or any other suspicious behavior.
core/TransactionEnvelopeEip2930.ts safe No malicious patterns detected
core/TransactionEnvelopeEip4844.ts safe No malicious patterns detected: the file implements EIP-4844 transaction handling with no network, filesystem, process, or dynamic code execution concerns.
core/TransactionEnvelopeEip7702.ts safe No malicious patterns detected
core/TransactionEnvelopeLegacy.ts safe This is a legitimate Ethereum legacy transaction envelope implementation with no malicious patterns, exfiltration, dynamic code execution, or suspicious behavior.
core/TransactionReceipt.ts safe No malicious patterns detected; the file contains only type definitions and data conversion utilities for Ethereum transaction receipts with no network, filesystem, process, or dynamic code execution activity.
core/TransactionRequest.ts safe No malicious patterns detected
core/TypedData.ts safe No malicious patterns detected; the code implements standard EIP-712 typed data hashing/encoding without any exfiltration, dynamic execution, or process spawning.
core/ValidatorData.ts safe No malicious patterns detected
core/Value.ts safe Cleared by Jev triage; no further analysis needed
core/WebAuthnP256.ts safe No malicious patterns detected; this is a legitimate WebAuthn P256 library implementation from the 'ox' package.
core/WebCryptoP256.ts safe No malicious patterns detected; the code is a legitimate WebCrypto P-256 ECDSA/ECDH wrapper with no exfiltration, obfuscation, or suspicious behavior.
core/Withdrawal.ts safe Cleared by Jev triage; no further analysis needed
core/X25519.ts safe No malicious patterns detected
core/internal/abi.ts safe Cleared by Jev triage; no further analysis needed
core/internal/abiConstructor.ts safe Cleared by Jev triage; no further analysis needed
core/internal/abiError.ts safe Cleared by Jev triage; no further analysis needed
core/internal/abiEvent.ts safe Cleared by Jev triage; no further analysis needed
core/internal/abiFunction.ts safe Cleared by Jev triage; no further analysis needed
core/internal/abiItem.ts safe Cleared by Jev triage; no further analysis needed
core/internal/abiParameters.ts safe Cleared by Jev triage; no further analysis needed
core/internal/base58.ts safe The code implements standard Base58 encoding with no network, filesystem, process, or dynamic execution capabilities, and contains no malicious patterns.
core/internal/bytes.ts safe Cleared by Jev triage; no further analysis needed
core/internal/cursor.ts safe No malicious patterns detected; the code is a well-structured binary cursor utility with no network, filesystem, process, or dynamic execution activity.
core/internal/ens.ts safe No malicious patterns detected; the code implements ENS DNS packet encoding and labelhash wrapping/unwrapping without external calls, dynamic execution, or filesystem access.
core/internal/entropy.ts safe Cleared by Jev triage; no further analysis needed
core/internal/errors.ts safe Cleared by Jev triage; no further analysis needed
core/internal/hdKey.ts safe No malicious patterns detected; the code is a straightforward adapter for HD key derivation with no network, filesystem, process, or dynamic execution activity.
core/internal/hex.ts safe Cleared by Jev triage; no further analysis needed
core/internal/lru.ts safe Cleared by Jev triage; no further analysis needed
core/internal/mnemonic/wordlists.ts safe This file only re-exports standard BIP39 wordlists from the @scure/bip39 package and contains no malicious patterns.
core/internal/promise.ts safe Cleared by Jev triage; no further analysis needed
core/internal/register.ts safe No malicious patterns detected
core/internal/rpcSchema.ts safe Cleared by Jev triage; no further analysis needed
core/internal/rpcSchemas/eth.ts safe This file contains only TypeScript type definitions for Ethereum JSON-RPC methods with no executable code, network calls, filesystem access, or other malicious patterns.
core/internal/rpcSchemas/wallet.ts safe No malicious patterns detected; the file only contains TypeScript type definitions for Ethereum wallet JSON-RPC methods with no runtime code, network calls, file access, or dynamic execution.
core/internal/rpcTransport.ts safe No malicious patterns detected; the code defines a standard JSON-RPC transport wrapper without any exfiltration, dynamic execution, filesystem, or process-spawning behavior.
core/internal/types.ts safe Cleared by Jev triage; no further analysis needed
core/internal/uid.ts safe The code is a simple UID generator using Math.random and does not contain any malicious patterns or security concerns.
core/internal/webauthn.ts safe No malicious patterns detected; the file contains only WebAuthn type definitions and cryptographic parsing utilities with no data exfiltration, credential harvesting, obfuscation, or network/file/process manipulation.
core/version.ts safe Cleared by Jev triage; no further analysis needed
erc4337/EntryPoint.ts safe No malicious patterns detected
erc4337/RpcSchema.ts safe No malicious patterns detected
erc4337/UserOperation.ts safe This file is a legitimate ERC-4337 UserOperation TypeScript module containing only type definitions, encoding/decoding helpers for user operations, and no network, filesystem, process, or dynamic code execution patterns.
erc4337/UserOperationGas.ts safe Cleared by Jev triage; no further analysis needed
erc4337/UserOperationReceipt.ts safe Cleared by Jev triage; no further analysis needed
erc4337/index.ts safe This file contains only static ES module re-exports of ERC-4337 utility modules with no executable code, network activity, file system access, or other malicious patterns.
erc6492/SignatureErc6492.ts safe The code implements ERC-6492 signature wrapping/unwrapping and validation using only standard ABI encoding/decoding and hex utilities, with no network, filesystem, process, or dynamic execution behavior.
erc6492/index.ts safe No malicious patterns detected
erc8010/SignatureErc8010.ts safe Code implements ERC-8010 signature wrapping/unwrapping with only standard cryptographic and ABI operations, no malicious patterns detected.
erc8010/index.ts safe No malicious patterns detected in the ERC-8010 signature utility wrapper file.
index.docs.ts safe The file only contains standard re-export statements for documentation generation, with no malicious patterns detected.
trusted-setups/Paths.ts safe Cleared by Jev triage; no further analysis needed
trusted-setups/index.ts safe Cleared by Jev triage; no further analysis needed
trusted-setups/internal/paths.ts safe Cleared by Jev triage; no further analysis needed
version.ts safe Cleared by Jev triage; no further analysis needed
window/index.ts safe No malicious patterns detected

Affected version ranges

None of the 4 scanned versions of ox are flagged high or critical. The latest scanned version, 0.14.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

0.6.70.14.0
VersionsVerdictCountRangeTop findings
0.9.17 – 0.14.0 Not scanned 2 >=0.9.17 <=0.14.0
0.6.7 – 0.9.6 No issues 4 >=0.6.7 <=0.9.6

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of ox

VersionVerdictFilesScanned
0.9.6 No issues 331 Oct 4, 2026
0.9.3 No issues 331 Oct 4, 2026
0.6.9 No issues 318 Oct 4, 2026
0.6.7 No issues 315 Oct 4, 2026

Frequently asked questions

Is ox safe to use?

Our AI source review of ox@0.9.6 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does ox contain malware?

No malware was identified in ox@0.9.6 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was ox checked?

Togoder Security downloaded the published npm package and had an AI model read its 331 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan ox together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in ox@0.9.6, cost nothing.

Related security reports