Summary
Togoder Security scanned the npm package ox@0.6.7 on Oct 4, 2026. An AI review of 315 source files produced 2 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings 2
weak randomness
NPS-C52ADA31D27E
The uid function uses Math.random() for generating identifiers, which is not cryptographically secure. If these IDs are used for security-sensitive purposes (e.g., session tokens, password reset tokens), they could be predictable. However, this is a common pattern for non-security-related unique IDs and does not indicate malicious intent.
Embedded Bytecode / EVM Contract
NPS-0172EE9F084D
The file contains a large hex-encoded EVM bytecode blob (universalSignatureValidatorBytecode) for the ERC-6492 deployless signature validator. This is expected, legitimate functionality per the ERC-6492 standard and is not executed in Node.js; it is transmitted to a blockchain EVM. No Node.js execution occurs on it.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| _cjs/core/Abi.js | safe | No malicious patterns detected |
| _cjs/core/AbiConstructor.js | safe | No malicious patterns detected |
| _cjs/core/AbiError.js | safe | No malicious patterns detected |
| _cjs/core/AbiEvent.js | safe | No malicious patterns detected; the file contains standard Ethereum ABI event encoding/decoding logic with no network, filesystem, process, or obfuscated code. |
| _cjs/core/AbiFunction.js | safe | No malicious patterns detected; the code is a standard ABI encoding/decoding utility with no network, filesystem, process, or dynamic code execution behavior. |
| _cjs/core/AbiItem.js | safe | No malicious patterns detected in the analyzed JavaScript ABI utility file. |
| _cjs/core/AbiParameters.js | safe | No malicious patterns detected; the code is a standard ABI encoding/decoding utility with no network, filesystem, process, or obfuscated execution behavior. |
| _cjs/core/AccessList.js | safe | No malicious patterns detected; the code only performs local validation and transformation of Ethereum access list structures. |
| _cjs/core/AccountProof.js | safe | No malicious patterns detected |
| _cjs/core/Address.js | safe | No malicious patterns detected; the code is a legitimate Ethereum address utility for validation, checksumming, and comparison. |
| _cjs/core/AesGcm.js | safe | No malicious patterns detected |
| _cjs/core/Authorization.js | safe | This file contains pure data transformation and hashing utilities for Ethereum authorization objects with no network, filesystem, process, or dynamic code execution patterns. |
| _cjs/core/Base58.js | safe | Cleared by Jev triage; no further analysis needed |
| _cjs/core/Base64.js | safe | No malicious patterns detected; the code is a straightforward Base64 encoder/decoder with no network, filesystem, credential, or dynamic execution activity. |
| _cjs/core/Blobs.js | safe | No malicious patterns detected; the file contains standard Ethereum blob/KZG utility functions with no exfiltration, credential harvesting, obfuscation, process spawning, or network activity. |
| _cjs/core/Block.js | safe | No malicious patterns detected; the code only performs Ethereum block RPC serialization/deserialization using local hex and transaction utilities. |
| _cjs/core/BlockOverrides.js | safe | Cleared by Jev triage; no further analysis needed |
| _cjs/core/Bloom.js | safe | No malicious patterns detected; the code implements a standard Ethereum bloom filter check using only in-package modules and no network, filesystem, or dynamic execution capabilities. |
| _cjs/core/Bls.js | safe | This is a legitimate BLS12-381 cryptographic implementation using the well-known @noble/curves library, with no malicious patterns, network calls, credential harvesting, or code execution. |
| _cjs/core/BlsPoint.js | safe | Cleared by Jev triage; no further analysis needed |
| _cjs/core/Bytes.js | safe | No malicious patterns detected; the code is a standard byte manipulation utility library with no network, filesystem, process, or dynamic execution behavior. |
| _cjs/core/Caches.js | safe | No malicious patterns detected |
| _cjs/core/ContractAddress.js | safe | The code implements standard Ethereum contract address derivation (CREATE/CREATE2) using well-known cryptographic libraries without any malicious patterns. |
| _cjs/core/Ens.js | safe | No malicious patterns detected; the file implements ENS name normalization and hashing using only local crypto utilities and a standard normalization library. |
| _cjs/core/Errors.js | safe | No malicious patterns detected in this error-handling utility class; it contains only standard error construction, message formatting, and error cause traversal logic with no network, filesystem, process, or dynamic code execution activities. |
Show 290 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| _cjs/core/Fee.js | safe | No malicious patterns detected |
| _cjs/core/Filter.js | safe | Cleared by Jev triage; no further analysis needed |
| _cjs/core/Hash.js | safe | The code is a simple cryptographic hash utility that delegates to well-known @noble/hashes functions and contains no malicious patterns. |
| _cjs/core/HdKey.js | safe | No malicious patterns detected; the code is a thin, standard wrapper around the @scure/bip32 library for HD key derivation. |
| _cjs/core/Hex.js | safe | No malicious patterns detected; the code is a standard hex encoding/decoding utility library with no network, filesystem, process, or dynamic evaluation concerns. |
| _cjs/core/Json.js | safe | No malicious patterns detected; the code only provides JSON parsing/stringifying with BigInt support. |
| _cjs/core/Kzg.js | safe | No malicious patterns detected |
| _cjs/core/Log.js | safe | Cleared by Jev triage; no further analysis needed |
| _cjs/core/Mnemonic.js | safe | The file implements standard BIP39 mnemonic and HD key operations using trusted libraries with no malicious patterns, network calls, or suspicious behavior. |
| _cjs/core/P256.js | safe | No malicious patterns detected; the code is a standard cryptographic wrapper around @noble/curves for P-256 operations with no exfiltration, obfuscation, process spawning, or suspicious behavior. |
| _cjs/core/PersonalMessage.js | safe | No malicious patterns detected |
| _cjs/core/Provider.js | safe | No malicious patterns detected |
| _cjs/core/PublicKey.js | safe | No malicious patterns detected; the file contains only public key parsing, validation, and serialization logic with no network, filesystem, process, or dynamic code execution behavior. |
| _cjs/core/Rlp.js | safe | No malicious patterns detected; the code is a standard RLP encoding/decoding implementation with no exfiltration, credential harvesting, dynamic code execution, or process spawning. |
| _cjs/core/RpcRequest.js | safe | No malicious patterns detected; the code only creates JSON-RPC 2.0 request objects with no network, filesystem, process, or dynamic execution behavior. |
| _cjs/core/RpcResponse.js | safe | No malicious patterns detected; the file only defines JSON-RPC response parsing utilities and error classes. |
| _cjs/core/RpcSchema.js | safe | No malicious patterns detected |
| _cjs/core/RpcTransport.js | safe | No malicious patterns detected; the code implements a standard HTTP RPC transport with no suspicious behavior. |
| _cjs/core/Secp256k1.js | safe | The code is a clean cryptographic wrapper around @noble/curves for secp256k1 operations with no malicious patterns detected. |
| _cjs/core/Signature.js | safe | No malicious patterns detected; the code is a standard Ethereum signature handling utility with no network, filesystem, process, or obfuscation concerns. |
| _cjs/core/Siwe.js | safe | No malicious patterns detected; this is a legitimate SIWE (Sign-In with Ethereum) message parsing/validation module with no network, filesystem, process, or dynamic execution behavior. |
| _cjs/core/Solidity.js | safe | The code contains only Solidity type definitions and regex patterns with no malicious behavior. |
| _cjs/core/StateOverrides.js | safe | Cleared by Jev triage; no further analysis needed |
| _cjs/core/Transaction.js | safe | No malicious patterns detected |
| _cjs/core/TransactionEnvelope.js | safe | No malicious patterns detected; the file only defines custom error classes for transaction envelope validation. |
| _cjs/core/TransactionEnvelopeEip1559.js | safe | No malicious patterns detected |
| _cjs/core/TransactionEnvelopeEip2930.js | safe | No malicious patterns detected; the file implements EIP-2930 transaction serialization/deserialization with no network, filesystem, process, or dynamic code execution concerns. |
| _cjs/core/TransactionEnvelopeEip4844.js | safe | No malicious patterns detected; the code implements EIP-4844 transaction serialization/deserialization with only standard cryptographic and encoding dependencies. |
| _cjs/core/TransactionEnvelopeEip7702.js | safe | The code implements EIP-7702 transaction envelope serialization/deserialization with standard validation; no malicious patterns, exfiltration, obfuscation, or dangerous operations were detected. |
| _cjs/core/TransactionEnvelopeLegacy.js | safe | This is a standard Ethereum legacy transaction envelope implementation with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning. |
| _cjs/core/TransactionReceipt.js | safe | No malicious patterns detected |
| _cjs/core/TransactionRequest.js | safe | No malicious patterns detected; the code is a straightforward Ethereum transaction request serializer that safely converts numeric fields to hex strings without any exfiltration, code execution, or system access. |
| _cjs/core/TypedData.js | safe | No malicious patterns detected; the code is a standard EIP-712 typed data implementation with only local cryptographic and validation operations. |
| _cjs/core/ValidatorData.js | safe | No malicious patterns detected |
| _cjs/core/Value.js | safe | No malicious patterns detected |
| _cjs/core/WebAuthnP256.js | safe | This is a legitimate WebAuthn P256 implementation with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or unauthorized system access. |
| _cjs/core/WebCryptoP256.js | safe | No malicious patterns detected; the code implements standard P-256 ECDSA key generation, signing, and verification using the Web Crypto API. |
| _cjs/core/Withdrawal.js | safe | No malicious patterns detected; the code only performs straightforward type conversions for withdrawal data. |
| _cjs/core/internal/abi.js | safe | No malicious patterns detected |
| _cjs/core/internal/abiConstructor.js | safe | No malicious patterns detected; the file only contains a CommonJS export marker and a source map comment. |
| _cjs/core/internal/abiError.js | safe | No malicious patterns detected |
| _cjs/core/internal/abiEvent.js | safe | No malicious patterns detected |
| _cjs/core/internal/abiFunction.js | safe | No malicious patterns detected |
| _cjs/core/internal/abiItem.js | safe | No malicious patterns detected; the file contains legitimate ABI signature normalization and type validation logic for the viem Ethereum library. |
| _cjs/core/internal/abiParameters.js | safe | No malicious patterns detected; the file is a standard ABI encoding/decoding implementation for Ethereum smart contracts with no network, file system, process, or dynamic execution behavior. |
| _cjs/core/internal/base58.js | safe | No malicious patterns detected; the file implements standard Base58 encoding without network, filesystem, process, or credential access. |
| _cjs/core/internal/bytes.js | safe | Cleared by Jev triage; no further analysis needed |
| _cjs/core/internal/cursor.js | safe | No malicious patterns detected; the code implements a binary cursor with bounds checking and recursion limits, and contains no network, filesystem, process execution, or obfuscated activity. |
| _cjs/core/internal/ens.js | safe | No malicious patterns detected |
| _cjs/core/internal/entropy.js | safe | No malicious patterns detected; the file only defines a simple module-level boolean and setter with no network, filesystem, process, or dynamic code execution activity. |
| _cjs/core/internal/errors.js | safe | Cleared by Jev triage; no further analysis needed |
| _cjs/core/internal/hdKey.js | safe | No malicious patterns detected; the code is a straightforward adapter that converts a scure HD key object into a local format using pure cryptographic operations with no network, filesystem, or process activity. |
| _cjs/core/internal/hex.js | safe | No malicious patterns detected; the code only provides hex string manipulation utilities. |
| _cjs/core/internal/lru.js | safe | No malicious patterns detected |
| _cjs/core/internal/mnemonic/wordlists.js | safe | No malicious patterns detected |
| _cjs/core/internal/promise.js | safe | Cleared by Jev triage; no further analysis needed |
| _cjs/core/internal/register.js | safe | No malicious patterns detected |
| _cjs/core/internal/rpcSchema.js | safe | This file is a generated TypeScript declaration stub with no executable logic other than the standard CommonJS module marker, and contains no malicious patterns. |
| _cjs/core/internal/rpcSchemas/eth.js | safe | No malicious patterns detected |
| _cjs/core/internal/rpcSchemas/wallet.js | safe | No malicious patterns detected |
| _cjs/core/internal/rpcTransport.js | safe | No malicious patterns detected; the file implements a straightforward JSON-RPC transport wrapper with no obfuscation, network exfiltration, process spawning, or filesystem manipulation. |
| _cjs/core/internal/types.js | safe | No malicious patterns detected |
| _cjs/core/internal/uid.js | safe | No malicious patterns detected; only a minor use of non-cryptographic randomness for ID generation. |
| _cjs/core/internal/webauthn.js | safe | No malicious patterns detected; the code performs standard WebAuthn credential parsing using cryptographic primitives from @noble/curves and the Web Crypto API. |
| _cjs/core/version.js | safe | No malicious patterns detected |
| _cjs/erc4337/EntryPoint.js | safe | This file contains only static ABI definitions and contract addresses for ERC-4337 EntryPoint contracts; no executable code, network I/O, or malicious patterns were detected. |
| _cjs/erc4337/RpcSchema.js | safe | No malicious patterns detected |
| _cjs/erc4337/UserOperation.js | safe | No malicious patterns detected; the file contains only standard ERC-4337 UserOperation encoding, hashing, and serialization utilities. |
| _cjs/erc4337/UserOperationGas.js | safe | The code performs straightforward conversion of ERC-4337 UserOperation gas fields between RPC and internal BigInt representations with no malicious patterns or security concerns. |
| _cjs/erc4337/UserOperationReceipt.js | safe | No malicious patterns detected; the code only performs data serialization/deserialization for ERC-4337 user operation receipts. |
| _cjs/erc4337/index.js | safe | No malicious patterns detected |
| _cjs/erc6492/WrappedSignature.js | safe | This is a legitimate ERC-6492 signature wrapper utility with no malicious patterns detected. |
| _cjs/erc6492/index.js | safe | The file is a simple CommonJS re-export module with no malicious patterns detected. |
| _cjs/index.docs.js | safe | No malicious patterns detected |
| _cjs/index.js | safe | No malicious patterns detected; the file is a standard barrel index re-exporting viem-like Ethereum utility modules. |
| _cjs/trusted-setups/Paths.js | safe | No malicious patterns detected |
| _cjs/trusted-setups/index.js | safe | No malicious patterns detected |
| _cjs/trusted-setups/internal/paths.js | safe | The code simply resolves a file path relative to the module directory using Node.js path utilities, with no malicious patterns detected. |
| _cjs/version.js | safe | No malicious patterns detected |
| _cjs/window/index.js | safe | The file contains only standard CommonJS module boilerplate with no executable logic or malicious patterns. |
| _esm/core/Abi.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/AbiConstructor.js | safe | No malicious patterns detected in the AbiConstructor.js file; it contains standard ABI encoding/decoding logic with no exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
| _esm/core/AbiError.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/AbiEvent.js | safe | No malicious patterns detected; the code is a standard Ethereum ABI event encoding/decoding utility with no exfiltration, obfuscation, or suspicious behavior. |
| _esm/core/AbiFunction.js | safe | No malicious patterns detected; the code performs standard ABI encoding/decoding for Ethereum smart contracts without exfiltration, obfuscation, or suspicious behavior. |
| _esm/core/AbiItem.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/AbiParameters.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/AccessList.js | safe | No malicious patterns detected; the module only contains pure utility functions for Ethereum access list serialization with input validation. |
| _esm/core/AccountProof.js | safe | No malicious patterns detected |
| _esm/core/Address.js | safe | The code is a standard Ethereum address validation and checksum utility with no malicious patterns, network activity, or suspicious behavior. |
| _esm/core/AesGcm.js | safe | No malicious patterns detected; the code implements standard AES-GCM encryption and PBKDF2 key derivation using the Web Crypto API without data exfiltration, dynamic execution, or process spawning. |
| _esm/core/Authorization.js | safe | The file contains only standard EIP-7702 Authorization serialization/deserialization logic for the 'ox' Ethereum library; no malicious patterns, network calls, process spawning, credential access, or dynamic code execution were found. |
| _esm/core/Base58.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/Base64.js | safe | No malicious patterns detected in the Base64 encoding/decoding utility; it is a standard implementation with no external calls, code execution, or file system access. |
| _esm/core/Blobs.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/Block.js | safe | No malicious patterns detected; the code is a straightforward Ethereum block serialization/deserialization utility with no network, filesystem, or process manipulation. |
| _esm/core/BlockOverrides.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/Bloom.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/Bls.js | safe | No malicious patterns detected; the file is a straightforward wrapper around the noble BLS12-381 library for cryptographic operations. |
| _esm/core/BlsPoint.js | safe | No malicious patterns detected; the code only performs standard BLS point serialization and deserialization using the @noble/curves library. |
| _esm/core/Bytes.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/Caches.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/ContractAddress.js | safe | The file is a legitimate Ethereum contract address implementation using CREATE and CREATE2 computation with no malicious patterns detected. |
| _esm/core/Ens.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/Errors.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/Fee.js | safe | The file contains only an empty export and a source map reference, with no executable or suspicious code. |
| _esm/core/Filter.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/Hash.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/HdKey.js | safe | No malicious patterns detected in the HD key utility module; it only wraps @scure/bip32 for BIP-32 key derivation. |
| _esm/core/Hex.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/Json.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/Kzg.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/Log.js | safe | No malicious patterns detected |
| _esm/core/Mnemonic.js | safe | No malicious patterns detected; the code is a legitimate BIP39 mnemonic utility library that only performs local cryptographic operations. |
| _esm/core/P256.js | safe | The code is a clean P256 ECDSA cryptography module that delegates to the audited @noble/curves library and contains no malicious patterns, network calls, credential harvesting, or dynamic code execution. |
| _esm/core/PersonalMessage.js | safe | The code is a clean implementation of ERC-191 personal message encoding and hashing with no malicious patterns. |
| _esm/core/Provider.js | safe | No malicious patterns detected |
| _esm/core/PublicKey.js | safe | No malicious patterns detected; the file contains standard public key parsing, validation, and serialization utilities with no external I/O, code execution, or credential access. |
| _esm/core/Rlp.js | safe | The RLP encoding/decoding module contains only pure data transformation logic with no network, filesystem, process, or dynamic code execution patterns. |
| _esm/core/RpcRequest.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/RpcResponse.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/RpcSchema.js | safe | No malicious patterns detected |
| _esm/core/RpcTransport.js | safe | No malicious patterns detected |
| _esm/core/Secp256k1.js | safe | No malicious patterns detected; the code is a legitimate secp256k1 cryptographic utility wrapper with no exfiltration, obfuscation, or suspicious behavior. |
| _esm/core/Signature.js | safe | No malicious patterns detected; the code is a standard Ethereum signature serialization/deserialization utility using secp256k1 with no network, filesystem, process, or dynamic code execution. |
| _esm/core/Siwe.js | safe | No malicious patterns detected; the code only implements EIP-4361 Sign-In with Ethereum message creation, parsing, and validation with no network, filesystem, process, or credential access. |
| _esm/core/Solidity.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/StateOverrides.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/Transaction.js | safe | No malicious patterns detected; the file only performs Ethereum transaction serialization/deserialization and type conversions. |
| _esm/core/TransactionEnvelope.js | safe | No malicious patterns detected; the code only defines error classes for Ethereum transaction validation with no network, filesystem, or dynamic execution behavior. |
| _esm/core/TransactionEnvelopeEip1559.js | safe | No malicious patterns detected in the EIP-1559 transaction envelope module; it performs standard serialization, validation, and hashing operations with no network, filesystem, or dynamic code execution. |
| _esm/core/TransactionEnvelopeEip2930.js | safe | No malicious patterns detected; the code is a legitimate EIP-2930 transaction envelope implementation with no data exfiltration, dynamic code execution, or other security concerns. |
| _esm/core/TransactionEnvelopeEip4844.js | safe | No malicious patterns detected; the file implements standard EIP-4844 transaction envelope serialization logic without any suspicious behavior. |
| _esm/core/TransactionEnvelopeEip7702.js | safe | No malicious patterns detected; the file implements standard EIP-7702 transaction envelope serialization from the 'ox' library with no exfiltration, credential harvesting, obfuscation, or process execution. |
| _esm/core/TransactionEnvelopeLegacy.js | safe | No malicious patterns detected; the code is a legitimate Ethereum legacy transaction envelope implementation from the ox library. |
| _esm/core/TransactionReceipt.js | safe | No malicious patterns detected; the code is a pure data transformation module for Ethereum transaction receipts with no network, filesystem, or dynamic execution behavior. |
| _esm/core/TransactionRequest.js | safe | No malicious patterns detected; the code is a straightforward utility that converts Ethereum transaction request objects to RPC format using hex encoding and authorization list conversion. |
| _esm/core/TypedData.js | safe | No malicious patterns detected |
| _esm/core/ValidatorData.js | safe | No malicious patterns detected; the file only implements ERC-191 validator data encoding and hashing using local imports. |
| _esm/core/Value.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/WebAuthnP256.js | safe | No malicious patterns detected in this WebAuthn P256 utility module. |
| _esm/core/WebCryptoP256.js | safe | No malicious patterns detected; the code implements standard P-256 ECDSA key generation, signing, and verification using WebCrypto with no exfiltration, obfuscation, or suspicious behavior. |
| _esm/core/Withdrawal.js | safe | No malicious patterns detected |
| _esm/core/internal/abi.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/internal/abiConstructor.js | safe | The file contains only an empty export and a source map comment; no executable or malicious code is present. |
| _esm/core/internal/abiError.js | safe | No malicious patterns detected |
| _esm/core/internal/abiEvent.js | safe | The file contains only an empty export statement and a source map reference, with no executable code or malicious patterns. |
| _esm/core/internal/abiFunction.js | safe | No malicious patterns detected |
| _esm/core/internal/abiItem.js | safe | No malicious patterns detected; the code is legitimate ABI signature normalization and type checking logic. |
| _esm/core/internal/abiParameters.js | safe | No malicious patterns detected; the file implements standard ABI parameter encoding/decoding logic with no exfiltration, obfuscation, or dynamic code execution. |
| _esm/core/internal/base58.js | safe | No malicious patterns detected |
| _esm/core/internal/bytes.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/internal/cursor.js | safe | No malicious patterns detected |
| _esm/core/internal/ens.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/internal/entropy.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/internal/errors.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/internal/hdKey.js | safe | No malicious patterns detected |
| _esm/core/internal/hex.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/internal/lru.js | safe | No malicious patterns detected; the code is a standard LRU cache implementation with no network, filesystem, process, environment, or obfuscated behavior. |
| _esm/core/internal/mnemonic/wordlists.js | safe | No malicious patterns detected; the file only re-exports standard BIP39 wordlists from the @scure/bip39 package. |
| _esm/core/internal/promise.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/core/internal/register.js | safe | No malicious patterns detected |
| _esm/core/internal/rpcSchema.js | safe | No malicious patterns detected; the file contains only an empty export and a source map reference. |
| _esm/core/internal/rpcSchemas/eth.js | safe | No malicious patterns detected |
| _esm/core/internal/rpcSchemas/wallet.js | safe | The file contains only an empty export statement and a source map reference, with no executable or suspicious code. |
| _esm/core/internal/rpcTransport.js | safe | No malicious patterns detected; the file implements a simple RPC transport wrapper with no network, filesystem, process, or dynamic execution concerns. |
| _esm/core/internal/types.js | safe | No malicious patterns detected |
| _esm/core/internal/uid.js | safe | No malicious patterns detected |
| _esm/core/internal/webauthn.js | safe | The code performs legitimate WebAuthn P-256 public key parsing and ASN.1 signature normalization without any malicious patterns such as exfiltration, obfuscation, or unauthorized system access. |
| _esm/core/version.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/erc4337/EntryPoint.js | safe | This file contains only static ABI definitions, contract addresses, and type declarations for Ethereum EntryPoint contracts with no executable or malicious code. |
| _esm/erc4337/RpcSchema.js | safe | No malicious patterns detected; the file contains only an empty export statement and a source map reference. |
| _esm/erc4337/UserOperation.js | safe | No malicious patterns detected; the file contains standard ERC-4337 UserOperation encoding, hashing, and serialization logic with no network, filesystem, process, or dynamic code execution activity. |
| _esm/erc4337/UserOperationGas.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/erc4337/UserOperationReceipt.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/erc4337/index.js | safe | No malicious patterns detected |
| _esm/erc6492/WrappedSignature.js | safe | The module is a standard, benign implementation of ERC-6492 wrapped signature encoding/decoding (from the 'ox' library); it contains no exfiltration, credential harvesting, obfuscation, process spawning, or dynamic code execution patterns. |
| _esm/erc6492/index.js | safe | No malicious patterns detected; the file only re-exports the WrappedSignature module for ERC-6492 signature utilities. |
| _esm/index.docs.js | safe | This file only re-exports modules for documentation generation and contains no malicious patterns. |
| _esm/index.js | safe | No malicious patterns detected; the file only re-exports Ethereum-related utility modules via static ESM exports. |
| _esm/trusted-setups/Paths.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/trusted-setups/index.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/trusted-setups/internal/paths.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/version.js | safe | Cleared by Jev triage; no further analysis needed |
| _esm/window/index.js | safe | No malicious patterns detected |
| core/Abi.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/AbiConstructor.ts | safe | No malicious patterns detected; the code is a standard TypeScript ABI encoding/decoding utility with no network, filesystem, process, or dynamic execution operations. |
| core/AbiError.ts | safe | No malicious patterns detected |
| core/AbiEvent.ts | safe | No malicious patterns detected; the file contains standard Ethereum ABI event encoding/decoding utilities with no exfiltration, dynamic execution, or suspicious network/file/process operations. |
| core/AbiFunction.ts | safe | No malicious patterns detected; the file is a legitimate ABI encoding/decoding utility from the ox library with no network, file system, process, or dynamic code execution activity. |
| core/AbiItem.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/AbiParameters.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/AccessList.ts | safe | No malicious patterns detected |
| core/AccountProof.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/Address.ts | safe | No malicious patterns detected |
| core/AesGcm.ts | safe | No malicious patterns detected; the code is a straightforward AES-GCM encryption/decryption utility using the Web Crypto API with PBKDF2 key derivation. |
| core/Authorization.ts | safe | No malicious patterns detected; the code is a standard EIP-7702 Authorization utility module with no network, filesystem, process, or obfuscated behavior. |
| core/Base58.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/Base64.ts | safe | No malicious patterns detected; the code is a clean implementation of Base64 encoding/decoding with no network, filesystem, or dynamic code execution. |
| core/Blobs.ts | safe | The code implements EIP-4844 blob encoding, hashing, and KZG commitment/proof utilities with no network, filesystem, process, environment, or dynamic execution behavior. |
| core/Block.ts | safe | No malicious patterns detected; the file contains only standard Ethereum block type definitions and RPC serialization/deserialization utilities with no network, filesystem, process, or code-execution behavior. |
| core/BlockOverrides.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/Bloom.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/Bls.ts | safe | No malicious patterns detected; the code is a standard BLS12-381 cryptographic utility wrapper around @noble/curves. |
| core/BlsPoint.ts | safe | No malicious patterns detected; the code is a legitimate BLS point conversion utility using @noble/curves. |
| core/Bytes.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/Caches.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/ContractAddress.ts | safe | This file implements Ethereum CREATE and CREATE2 contract address derivation using standard cryptographic primitives with no network, filesystem, process, or dynamic code execution concerns. |
| core/Ens.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/Errors.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/Fee.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/Filter.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/Hash.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/HdKey.ts | safe | No malicious patterns detected; the code is a straightforward HD key utility wrapper around @scure/bip32 with no exfiltration, credential harvesting, obfuscation, or dynamic execution. |
| core/Hex.ts | safe | No malicious patterns detected; the file implements standard hexadecimal encoding/decoding utilities using only local dependencies and Node's built-in TextEncoder/TextDecoder, with no network, filesystem, process, or dynamic code execution activity. |
| core/Json.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/Kzg.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/Log.ts | safe | No malicious patterns detected; the file contains only type definitions and pure data transformation functions for Ethereum log objects with no network, filesystem, process, or dynamic code execution behavior. |
| core/Mnemonic.ts | safe | No malicious patterns detected; the code provides standard BIP39 mnemonic utilities (generation, validation, seed/HD key derivation) with no exfiltration, obfuscation, or suspicious side effects. |
| core/P256.ts | safe | No malicious patterns detected in the P256 cryptographic utility module. |
| core/PersonalMessage.ts | safe | No malicious patterns detected; the code implements ERC-191 personal message encoding and hashing using only local cryptographic utilities. |
| core/Provider.ts | safe | No malicious patterns detected; the code implements a standard EIP-1193 provider abstraction with type-safe RPC handling and error parsing. |
| core/PublicKey.ts | safe | No malicious patterns detected; the code is a standard cryptographic public key utility library with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior. |
| core/Rlp.ts | safe | No malicious patterns detected; the file implements standard RLP encoding/decoding with no network, filesystem, process, or dynamic code execution concerns. |
| core/RpcRequest.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/RpcResponse.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/RpcSchema.ts | safe | This file is a purely type-level TypeScript RPC schema definition with no runtime logic, network calls, filesystem access, or malicious patterns. |
| core/RpcTransport.ts | safe | No malicious patterns detected; the code is a legitimate JSON-RPC HTTP transport implementation for a TypeScript library. |
| core/Secp256k1.ts | safe | This is a legitimate secp256k1 cryptographic utility library wrapping @noble/curves with no malicious patterns detected. |
| core/Signature.ts | safe | No malicious patterns detected; the code is a standard ECDSA signature utility library with no network, filesystem, process, or obfuscated behavior. |
| core/Siwe.ts | safe | The Siwe.ts file implements EIP-4361 Sign-In with Ethereum message creation, parsing, and validation with no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or dynamic execution detected. |
| core/Solidity.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/StateOverrides.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/Transaction.ts | safe | No malicious patterns detected |
| core/TransactionEnvelope.ts | safe | No malicious patterns detected; file contains only type definitions and error classes for Ethereum transaction envelopes with no executable/network/filesystem/credential-harvesting behavior. |
| core/TransactionEnvelopeEip1559.ts | safe | This is a legitimate EIP-1559 transaction envelope implementation from the 'ox' library with no malicious patterns, no network calls, no filesystem access, no credential harvesting, and no dynamic code execution. |
| core/TransactionEnvelopeEip2930.ts | safe | No malicious patterns detected |
| core/TransactionEnvelopeEip4844.ts | safe | No malicious patterns detected; the file implements EIP-4844 transaction envelope serialization/deserialization and validation logic with no network, filesystem, or dynamic code execution concerns. |
| core/TransactionEnvelopeEip7702.ts | safe | No malicious patterns detected; the code is a legitimate EIP-7702 transaction envelope implementation with standard cryptographic and serialization operations. |
| core/TransactionEnvelopeLegacy.ts | safe | No malicious patterns detected; the code is a legitimate Ethereum legacy transaction envelope implementation from the ox library with standard cryptographic operations, serialization, and validation. |
| core/TransactionReceipt.ts | safe | No malicious patterns detected; the file contains only type definitions, constants, and pure conversion functions for Ethereum transaction receipts. |
| core/TransactionRequest.ts | safe | No malicious patterns detected |
| core/TypedData.ts | safe | No malicious patterns detected; the file is a legitimate EIP-712 typed data implementation using only local imports and standard cryptographic primitives with no network, filesystem, process execution, or dynamic code evaluation. |
| core/ValidatorData.ts | safe | No malicious patterns detected |
| core/Value.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/WebAuthnP256.ts | safe | No malicious patterns detected; the code is a legitimate WebAuthn P256 credential handling library using standard WebAuthn APIs without any suspicious or malicious behavior. |
| core/WebCryptoP256.ts | safe | No malicious patterns detected |
| core/Withdrawal.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/abi.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/abiConstructor.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/abiError.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/abiEvent.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/abiFunction.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/abiItem.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/abiParameters.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/base58.ts | safe | The code implements standard Base58 encoding with no network, filesystem, process, or dynamic execution capabilities, and contains no malicious patterns. |
| core/internal/bytes.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/cursor.ts | safe | No malicious patterns detected; the code is a legitimate binary cursor/reader utility with bounds checking and no external I/O, network, or process execution. |
| core/internal/ens.ts | safe | No malicious patterns detected; the code implements ENS DNS packet encoding and labelhash wrapping/unwrapping without external calls, dynamic execution, or filesystem access. |
| core/internal/entropy.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/errors.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/hdKey.ts | safe | No malicious patterns detected; the code is a straightforward adapter for HD key derivation with no network, filesystem, process, or dynamic execution activity. |
| core/internal/hex.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/lru.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/mnemonic/wordlists.ts | safe | This file only re-exports standard BIP39 wordlists from the @scure/bip39 package and contains no malicious patterns. |
| core/internal/promise.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/register.ts | safe | No malicious patterns detected |
| core/internal/rpcSchema.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/rpcSchemas/eth.ts | safe | This file contains only TypeScript type definitions for Ethereum JSON-RPC methods with no executable code, network calls, filesystem access, or other malicious patterns. |
| core/internal/rpcSchemas/wallet.ts | safe | This file contains only TypeScript type definitions for Ethereum JSON-RPC wallet methods with no executable code, network calls, or malicious patterns. |
| core/internal/rpcTransport.ts | safe | No malicious patterns detected; the code defines a standard JSON-RPC transport wrapper without any exfiltration, dynamic execution, filesystem, or process-spawning behavior. |
| core/internal/types.ts | safe | Cleared by Jev triage; no further analysis needed |
| core/internal/uid.ts | safe | The code is a simple UID generator using Math.random and does not contain any malicious patterns or security concerns. |
| core/internal/webauthn.ts | safe | No malicious patterns detected; the file contains only WebAuthn type definitions and cryptographic parsing utilities with no data exfiltration, credential harvesting, obfuscation, or network/file/process manipulation. |
| core/version.ts | safe | Cleared by Jev triage; no further analysis needed |
| erc4337/EntryPoint.ts | safe | This file contains only static Ethereum ABI definitions and contract address constants for ERC-4337 EntryPoint versions 0.6 and 0.7, with no executable or malicious code. |
| erc4337/RpcSchema.ts | safe | No malicious patterns detected |
| erc4337/UserOperation.ts | safe | No malicious patterns detected |
| erc4337/UserOperationGas.ts | safe | Cleared by Jev triage; no further analysis needed |
| erc4337/UserOperationReceipt.ts | safe | Cleared by Jev triage; no further analysis needed |
| erc4337/index.ts | safe | This file contains only static ES module re-exports of ERC-4337 utility modules with no executable code, network activity, file system access, or other malicious patterns. |
| erc6492/WrappedSignature.ts | safe | The file implements ERC-6492 wrapped signature parsing/serialization with standard ABI and hex utilities, containing only expected constants and pure functions with no network, filesystem, process, or dynamic-execution behavior. |
| erc6492/index.ts | safe | No malicious patterns detected; the file only re-exports an ERC-6492 WrappedSignature module with documentation and type declarations. |
| index.docs.ts | safe | The file contains only re-export statements for documentation generation via api-extractor; no malicious patterns detected. |
| index.ts | safe | The file contains only JSDoc documentation and re-exports of ABI/crypto/transaction utility modules from the 'ox' library, with no malicious patterns, no runtime code execution, no network activity, no credential harvesting, and no obfuscation. |
| trusted-setups/Paths.ts | safe | Cleared by Jev triage; no further analysis needed |
| trusted-setups/index.ts | safe | Cleared by Jev triage; no further analysis needed |
| trusted-setups/internal/paths.ts | safe | Cleared by Jev triage; no further analysis needed |
| version.ts | safe | Cleared by Jev triage; no further analysis needed |
| window/index.ts | safe | No malicious patterns detected |
Affected version ranges
None of the 4 scanned versions of ox are flagged high or critical. The latest scanned version, 0.14.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 0.9.17 – 0.14.0 | Not scanned | 2 | >=0.9.17 <=0.14.0 | |
| 0.6.7 – 0.9.6 | No issues | 4 | >=0.6.7 <=0.9.6 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of ox
Frequently asked questions
Is ox safe to use?
Our AI source review of ox@0.6.7 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does ox contain malware?
No malware was identified in ox@0.6.7 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was ox checked?
Togoder Security downloaded the published npm package and had an AI model read its 315 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan ox together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in ox@0.6.7, cost nothing.