Togoder security

npm package security report

ox@0.6.9 security report

No malicious code found.

No issues Version 0.6.9 Files reviewed 318 Size 2.0 MB Scanned

Summary

Togoder Security scanned the npm package ox@0.6.9 on Oct 4, 2026. An AI review of 318 source files produced 2 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.

0
critical
0
high
0
medium
2
low

Findings 2

low

weak randomness

NPS-C52ADA31D27E

The uid function uses Math.random() for generating identifiers, which is not cryptographically secure. If these IDs are used for security-sensitive purposes (e.g., session tokens, password reset tokens), they could be predictable. However, this is a common pattern for non-security-related unique IDs and does not indicate malicious intent.

_cjs/core/internal/uid.js:12
low

Embedded Bytecode / EVM Contract

NPS-0172EE9F084D

The file contains a large hex-encoded EVM bytecode blob (universalSignatureValidatorBytecode) for the ERC-6492 deployless signature validator. This is expected, legitimate functionality per the ERC-6492 standard and is not executed in Node.js; it is transmitted to a blockchain EVM. No Node.js execution occurs on it.

_esm/erc6492/WrappedSignature.js:12

Files reviewed

FileVerdictWhat the reviewer saw
_cjs/core/Abi.js safe No malicious patterns detected
_cjs/core/AbiConstructor.js safe No malicious patterns detected
_cjs/core/AbiError.js safe No malicious patterns detected
_cjs/core/AbiEvent.js safe No malicious patterns detected
_cjs/core/AbiFunction.js safe No malicious patterns detected; the code is a standard ABI encoding/decoding utility with no network, filesystem, process, or dynamic code execution behavior.
_cjs/core/AbiItem.js safe No malicious patterns detected in the analyzed JavaScript ABI utility file.
_cjs/core/AbiParameters.js safe No malicious patterns detected; the code is a standard ABI encoding/decoding utility with no network, filesystem, process, or obfuscated execution behavior.
_cjs/core/AccessList.js safe No malicious patterns detected; the code only performs local validation and transformation of Ethereum access list structures.
_cjs/core/AccountProof.js safe No malicious patterns detected
_cjs/core/Address.js safe No malicious patterns detected; the code is a legitimate Ethereum address utility for validation, checksumming, and comparison.
_cjs/core/AesGcm.js safe No malicious patterns detected
_cjs/core/Authorization.js safe This file contains pure data transformation and hashing utilities for Ethereum authorization objects with no network, filesystem, process, or dynamic code execution patterns.
_cjs/core/Base58.js safe Cleared by Jev triage; no further analysis needed
_cjs/core/Base64.js safe No malicious patterns detected; the code is a straightforward Base64 encoder/decoder with no network, filesystem, credential, or dynamic execution activity.
_cjs/core/BinaryStateTree.js safe No malicious patterns detected; the file implements a binary state tree using BLAKE3 hashing with no network, filesystem, process, or dynamic execution activity.
_cjs/core/Blobs.js safe No malicious patterns detected; the file contains standard Ethereum blob/KZG utility functions with no exfiltration, credential harvesting, obfuscation, process spawning, or network activity.
_cjs/core/Block.js safe No malicious patterns detected; the code only performs Ethereum block RPC serialization/deserialization using local hex and transaction utilities.
_cjs/core/BlockOverrides.js safe Cleared by Jev triage; no further analysis needed
_cjs/core/Bloom.js safe No malicious patterns detected; the code implements a standard Ethereum bloom filter check using only in-package modules and no network, filesystem, or dynamic execution capabilities.
_cjs/core/Bls.js safe This is a legitimate BLS12-381 cryptographic implementation using the well-known @noble/curves library, with no malicious patterns, network calls, credential harvesting, or code execution.
_cjs/core/BlsPoint.js safe Cleared by Jev triage; no further analysis needed
_cjs/core/Bytes.js safe No malicious patterns detected; the code is a standard byte manipulation utility library with no network, filesystem, process, or dynamic execution behavior.
_cjs/core/Caches.js safe No malicious patterns detected
_cjs/core/ContractAddress.js safe The code implements standard Ethereum contract address derivation (CREATE/CREATE2) using well-known cryptographic libraries without any malicious patterns.
_cjs/core/Ens.js safe No malicious patterns detected; the file implements ENS name normalization and hashing using only local crypto utilities and a standard normalization library.
Show 293 more files
FileVerdictWhat the reviewer saw
_cjs/core/Errors.js safe No malicious patterns detected in this error-handling utility class; it contains only standard error construction, message formatting, and error cause traversal logic with no network, filesystem, process, or dynamic code execution activities.
_cjs/core/Fee.js safe No malicious patterns detected
_cjs/core/Filter.js safe Cleared by Jev triage; no further analysis needed
_cjs/core/Hash.js safe The code is a simple cryptographic hash utility that delegates to well-known @noble/hashes functions and contains no malicious patterns.
_cjs/core/HdKey.js safe No malicious patterns detected; the code is a thin, standard wrapper around the @scure/bip32 library for HD key derivation.
_cjs/core/Hex.js safe No malicious patterns detected; the code is a standard hex encoding/decoding utility library with no network, filesystem, process, or dynamic evaluation concerns.
_cjs/core/Json.js safe No malicious patterns detected; the code only provides JSON parsing/stringifying with BigInt support.
_cjs/core/Kzg.js safe No malicious patterns detected
_cjs/core/Log.js safe Cleared by Jev triage; no further analysis needed
_cjs/core/Mnemonic.js safe The file implements standard BIP39 mnemonic and HD key operations using trusted libraries with no malicious patterns, network calls, or suspicious behavior.
_cjs/core/P256.js safe No malicious patterns detected; the code is a standard cryptographic wrapper around @noble/curves for P-256 operations with no exfiltration, obfuscation, process spawning, or suspicious behavior.
_cjs/core/PersonalMessage.js safe No malicious patterns detected
_cjs/core/Provider.js safe No malicious patterns detected
_cjs/core/PublicKey.js safe No malicious patterns detected; the file contains only public key parsing, validation, and serialization logic with no network, filesystem, process, or dynamic code execution behavior.
_cjs/core/Rlp.js safe No malicious patterns detected; the code is a standard RLP encoding/decoding implementation with no exfiltration, credential harvesting, dynamic code execution, or process spawning.
_cjs/core/RpcRequest.js safe No malicious patterns detected; the code only creates JSON-RPC 2.0 request objects with no network, filesystem, process, or dynamic execution behavior.
_cjs/core/RpcResponse.js safe No malicious patterns detected; the file only defines JSON-RPC response parsing utilities and error classes.
_cjs/core/RpcSchema.js safe No malicious patterns detected
_cjs/core/RpcTransport.js safe No malicious patterns detected; the code implements a standard HTTP RPC transport with no suspicious behavior.
_cjs/core/Secp256k1.js safe The code is a clean cryptographic wrapper around @noble/curves for secp256k1 operations with no malicious patterns detected.
_cjs/core/Signature.js safe No malicious patterns detected; the code is a standard Ethereum signature handling utility with no network, filesystem, process, or obfuscation concerns.
_cjs/core/Siwe.js safe No malicious patterns detected; this is a legitimate SIWE (Sign-In with Ethereum) message parsing/validation module with no network, filesystem, process, or dynamic execution behavior.
_cjs/core/Solidity.js safe The code contains only Solidity type definitions and regex patterns with no malicious behavior.
_cjs/core/StateOverrides.js safe Cleared by Jev triage; no further analysis needed
_cjs/core/Transaction.js safe No malicious patterns detected
_cjs/core/TransactionEnvelope.js safe No malicious patterns detected; the file only defines custom error classes for transaction envelope validation.
_cjs/core/TransactionEnvelopeEip1559.js safe No malicious patterns detected
_cjs/core/TransactionEnvelopeEip2930.js safe No malicious patterns detected; the file implements EIP-2930 transaction serialization/deserialization with no network, filesystem, process, or dynamic code execution concerns.
_cjs/core/TransactionEnvelopeEip4844.js safe No malicious patterns detected; the code implements EIP-4844 transaction serialization/deserialization with only standard cryptographic and encoding dependencies.
_cjs/core/TransactionEnvelopeEip7702.js safe The code implements EIP-7702 transaction envelope serialization/deserialization with standard validation; no malicious patterns, exfiltration, obfuscation, or dangerous operations were detected.
_cjs/core/TransactionEnvelopeLegacy.js safe This is a standard Ethereum legacy transaction envelope implementation with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning.
_cjs/core/TransactionReceipt.js safe No malicious patterns detected
_cjs/core/TransactionRequest.js safe No malicious patterns detected; the code is a straightforward Ethereum transaction request serializer that safely converts numeric fields to hex strings without any exfiltration, code execution, or system access.
_cjs/core/TypedData.js safe No malicious patterns detected; the code is a standard EIP-712 typed data implementation with only local cryptographic and validation operations.
_cjs/core/ValidatorData.js safe No malicious patterns detected
_cjs/core/Value.js safe No malicious patterns detected
_cjs/core/WebAuthnP256.js safe This is a legitimate WebAuthn P256 implementation with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or unauthorized system access.
_cjs/core/WebCryptoP256.js safe No malicious patterns detected; the code implements standard P-256 ECDSA key generation, signing, and verification using the Web Crypto API.
_cjs/core/Withdrawal.js safe No malicious patterns detected; the code only performs straightforward type conversions for withdrawal data.
_cjs/core/internal/abi.js safe No malicious patterns detected
_cjs/core/internal/abiConstructor.js safe No malicious patterns detected; the file only contains a CommonJS export marker and a source map comment.
_cjs/core/internal/abiError.js safe No malicious patterns detected
_cjs/core/internal/abiEvent.js safe No malicious patterns detected
_cjs/core/internal/abiFunction.js safe No malicious patterns detected
_cjs/core/internal/abiItem.js safe No malicious patterns detected; the file contains legitimate ABI signature normalization and type validation logic for the viem Ethereum library.
_cjs/core/internal/abiParameters.js safe No malicious patterns detected; the file is a standard ABI encoding/decoding implementation for Ethereum smart contracts with no network, file system, process, or dynamic execution behavior.
_cjs/core/internal/base58.js safe No malicious patterns detected; the file implements standard Base58 encoding without network, filesystem, process, or credential access.
_cjs/core/internal/bytes.js safe Cleared by Jev triage; no further analysis needed
_cjs/core/internal/cursor.js safe No malicious patterns detected; the code implements a binary cursor with bounds checking and recursion limits, and contains no network, filesystem, process execution, or obfuscated activity.
_cjs/core/internal/ens.js safe No malicious patterns detected
_cjs/core/internal/entropy.js safe No malicious patterns detected; the file only defines a simple module-level boolean and setter with no network, filesystem, process, or dynamic code execution activity.
_cjs/core/internal/errors.js safe Cleared by Jev triage; no further analysis needed
_cjs/core/internal/hdKey.js safe No malicious patterns detected; the code is a straightforward adapter that converts a scure HD key object into a local format using pure cryptographic operations with no network, filesystem, or process activity.
_cjs/core/internal/hex.js safe No malicious patterns detected; the code only provides hex string manipulation utilities.
_cjs/core/internal/lru.js safe No malicious patterns detected
_cjs/core/internal/mnemonic/wordlists.js safe No malicious patterns detected
_cjs/core/internal/promise.js safe Cleared by Jev triage; no further analysis needed
_cjs/core/internal/register.js safe No malicious patterns detected
_cjs/core/internal/rpcSchema.js safe This file is a generated TypeScript declaration stub with no executable logic other than the standard CommonJS module marker, and contains no malicious patterns.
_cjs/core/internal/rpcSchemas/eth.js safe No malicious patterns detected
_cjs/core/internal/rpcSchemas/wallet.js safe No malicious patterns detected
_cjs/core/internal/rpcTransport.js safe No malicious patterns detected; the file implements a straightforward JSON-RPC transport wrapper with no obfuscation, network exfiltration, process spawning, or filesystem manipulation.
_cjs/core/internal/types.js safe No malicious patterns detected
_cjs/core/internal/uid.js safe No malicious patterns detected; only a minor use of non-cryptographic randomness for ID generation.
_cjs/core/internal/webauthn.js safe No malicious patterns detected; the code performs standard WebAuthn credential parsing using cryptographic primitives from @noble/curves and the Web Crypto API.
_cjs/core/version.js safe No malicious patterns detected
_cjs/erc4337/EntryPoint.js safe This file contains only static ABI definitions and contract addresses for ERC-4337 EntryPoint contracts; no executable code, network I/O, or malicious patterns were detected.
_cjs/erc4337/RpcSchema.js safe No malicious patterns detected
_cjs/erc4337/UserOperation.js safe No malicious patterns detected; the file contains only standard ERC-4337 UserOperation encoding, hashing, and serialization utilities.
_cjs/erc4337/UserOperationGas.js safe The code performs straightforward conversion of ERC-4337 UserOperation gas fields between RPC and internal BigInt representations with no malicious patterns or security concerns.
_cjs/erc4337/UserOperationReceipt.js safe No malicious patterns detected; the code only performs data serialization/deserialization for ERC-4337 user operation receipts.
_cjs/erc4337/index.js safe No malicious patterns detected
_cjs/erc6492/WrappedSignature.js safe This is a legitimate ERC-6492 signature wrapper utility with no malicious patterns detected.
_cjs/erc6492/index.js safe The file is a simple CommonJS re-export module with no malicious patterns detected.
_cjs/index.docs.js safe No malicious patterns detected
_cjs/index.js safe No malicious patterns detected; this file only re-exports modules from the core directory and contains no executable or suspicious code.
_cjs/trusted-setups/Paths.js safe No malicious patterns detected
_cjs/trusted-setups/index.js safe No malicious patterns detected
_cjs/trusted-setups/internal/paths.js safe The code simply resolves a file path relative to the module directory using Node.js path utilities, with no malicious patterns detected.
_cjs/version.js safe No malicious patterns detected
_cjs/window/index.js safe The file contains only standard CommonJS module boilerplate with no executable logic or malicious patterns.
_esm/core/Abi.js safe Cleared by Jev triage; no further analysis needed
_esm/core/AbiConstructor.js safe No malicious patterns detected in the AbiConstructor.js file; it contains standard ABI encoding/decoding logic with no exfiltration, credential harvesting, obfuscation, or dynamic code execution.
_esm/core/AbiError.js safe Cleared by Jev triage; no further analysis needed
_esm/core/AbiEvent.js safe The source file contains only standard ABI encoding/decoding utility functions for the 'ox' library with no malicious patterns, network calls, credential access, or dynamic code execution.
_esm/core/AbiFunction.js safe No malicious patterns detected; the code performs standard ABI encoding/decoding for Ethereum smart contracts without exfiltration, obfuscation, or suspicious behavior.
_esm/core/AbiItem.js safe Cleared by Jev triage; no further analysis needed
_esm/core/AbiParameters.js safe Cleared by Jev triage; no further analysis needed
_esm/core/AccessList.js safe No malicious patterns detected; the module only contains pure utility functions for Ethereum access list serialization with input validation.
_esm/core/AccountProof.js safe No malicious patterns detected
_esm/core/Address.js safe The code is a standard Ethereum address validation and checksum utility with no malicious patterns, network activity, or suspicious behavior.
_esm/core/AesGcm.js safe No malicious patterns detected; the code implements standard AES-GCM encryption and PBKDF2 key derivation using the Web Crypto API without data exfiltration, dynamic execution, or process spawning.
_esm/core/Authorization.js safe The file contains only standard EIP-7702 Authorization serialization/deserialization logic for the 'ox' Ethereum library; no malicious patterns, network calls, process spawning, credential access, or dynamic code execution were found.
_esm/core/Base58.js safe Cleared by Jev triage; no further analysis needed
_esm/core/Base64.js safe No malicious patterns detected in the Base64 encoding/decoding utility; it is a standard implementation with no external calls, code execution, or file system access.
_esm/core/BinaryStateTree.js safe Cleared by Jev triage; no further analysis needed
_esm/core/Blobs.js safe Cleared by Jev triage; no further analysis needed
_esm/core/Block.js safe No malicious patterns detected; the code is a straightforward Ethereum block serialization/deserialization utility with no network, filesystem, or process manipulation.
_esm/core/BlockOverrides.js safe Cleared by Jev triage; no further analysis needed
_esm/core/Bloom.js safe Cleared by Jev triage; no further analysis needed
_esm/core/Bls.js safe No malicious patterns detected; the file is a straightforward wrapper around the noble BLS12-381 library for cryptographic operations.
_esm/core/BlsPoint.js safe No malicious patterns detected; the code only performs standard BLS point serialization and deserialization using the @noble/curves library.
_esm/core/Bytes.js safe Cleared by Jev triage; no further analysis needed
_esm/core/Caches.js safe Cleared by Jev triage; no further analysis needed
_esm/core/ContractAddress.js safe The file is a legitimate Ethereum contract address implementation using CREATE and CREATE2 computation with no malicious patterns detected.
_esm/core/Ens.js safe Cleared by Jev triage; no further analysis needed
_esm/core/Errors.js safe Cleared by Jev triage; no further analysis needed
_esm/core/Fee.js safe The file contains only an empty export and a source map reference, with no executable or suspicious code.
_esm/core/Filter.js safe Cleared by Jev triage; no further analysis needed
_esm/core/Hash.js safe Cleared by Jev triage; no further analysis needed
_esm/core/HdKey.js safe No malicious patterns detected in the HD key utility module; it only wraps @scure/bip32 for BIP-32 key derivation.
_esm/core/Hex.js safe Cleared by Jev triage; no further analysis needed
_esm/core/Json.js safe Cleared by Jev triage; no further analysis needed
_esm/core/Kzg.js safe Cleared by Jev triage; no further analysis needed
_esm/core/Log.js safe No malicious patterns detected
_esm/core/Mnemonic.js safe No malicious patterns detected; the code is a legitimate BIP39 mnemonic utility library that only performs local cryptographic operations.
_esm/core/P256.js safe The code is a clean P256 ECDSA cryptography module that delegates to the audited @noble/curves library and contains no malicious patterns, network calls, credential harvesting, or dynamic code execution.
_esm/core/PersonalMessage.js safe The code is a clean implementation of ERC-191 personal message encoding and hashing with no malicious patterns.
_esm/core/Provider.js safe No malicious patterns detected
_esm/core/PublicKey.js safe No malicious patterns detected; the file contains standard public key parsing, validation, and serialization utilities with no external I/O, code execution, or credential access.
_esm/core/Rlp.js safe The RLP encoding/decoding module contains only pure data transformation logic with no network, filesystem, process, or dynamic code execution patterns.
_esm/core/RpcRequest.js safe Cleared by Jev triage; no further analysis needed
_esm/core/RpcResponse.js safe Cleared by Jev triage; no further analysis needed
_esm/core/RpcSchema.js safe No malicious patterns detected
_esm/core/RpcTransport.js safe No malicious patterns detected
_esm/core/Secp256k1.js safe No malicious patterns detected; the code is a legitimate secp256k1 cryptographic utility wrapper with no exfiltration, obfuscation, or suspicious behavior.
_esm/core/Signature.js safe No malicious patterns detected; the code is a standard Ethereum signature serialization/deserialization utility using secp256k1 with no network, filesystem, process, or dynamic code execution.
_esm/core/Siwe.js safe No malicious patterns detected; the code only implements EIP-4361 Sign-In with Ethereum message creation, parsing, and validation with no network, filesystem, process, or credential access.
_esm/core/Solidity.js safe Cleared by Jev triage; no further analysis needed
_esm/core/StateOverrides.js safe Cleared by Jev triage; no further analysis needed
_esm/core/Transaction.js safe No malicious patterns detected; the file only performs Ethereum transaction serialization/deserialization and type conversions.
_esm/core/TransactionEnvelope.js safe No malicious patterns detected; the code only defines error classes for Ethereum transaction validation with no network, filesystem, or dynamic execution behavior.
_esm/core/TransactionEnvelopeEip1559.js safe No malicious patterns detected in the EIP-1559 transaction envelope module; it performs standard serialization, validation, and hashing operations with no network, filesystem, or dynamic code execution.
_esm/core/TransactionEnvelopeEip2930.js safe No malicious patterns detected; the code is a legitimate EIP-2930 transaction envelope implementation with no data exfiltration, dynamic code execution, or other security concerns.
_esm/core/TransactionEnvelopeEip4844.js safe No malicious patterns detected; the file implements standard EIP-4844 transaction envelope serialization logic without any suspicious behavior.
_esm/core/TransactionEnvelopeEip7702.js safe No malicious patterns detected; the file implements standard EIP-7702 transaction envelope serialization from the 'ox' library with no exfiltration, credential harvesting, obfuscation, or process execution.
_esm/core/TransactionEnvelopeLegacy.js safe No malicious patterns detected; the code is a legitimate Ethereum legacy transaction envelope implementation from the ox library.
_esm/core/TransactionReceipt.js safe No malicious patterns detected; the code is a pure data transformation module for Ethereum transaction receipts with no network, filesystem, or dynamic execution behavior.
_esm/core/TransactionRequest.js safe No malicious patterns detected; the code is a straightforward utility that converts Ethereum transaction request objects to RPC format using hex encoding and authorization list conversion.
_esm/core/TypedData.js safe No malicious patterns detected
_esm/core/ValidatorData.js safe No malicious patterns detected; the file only implements ERC-191 validator data encoding and hashing using local imports.
_esm/core/Value.js safe Cleared by Jev triage; no further analysis needed
_esm/core/WebAuthnP256.js safe No malicious patterns detected in this WebAuthn P256 utility module.
_esm/core/WebCryptoP256.js safe No malicious patterns detected; the code implements standard P-256 ECDSA key generation, signing, and verification using WebCrypto with no exfiltration, obfuscation, or suspicious behavior.
_esm/core/Withdrawal.js safe No malicious patterns detected
_esm/core/internal/abi.js safe Cleared by Jev triage; no further analysis needed
_esm/core/internal/abiConstructor.js safe The file contains only an empty export and a source map comment; no executable or malicious code is present.
_esm/core/internal/abiError.js safe No malicious patterns detected
_esm/core/internal/abiEvent.js safe The file contains only an empty export statement and a source map reference, with no executable code or malicious patterns.
_esm/core/internal/abiFunction.js safe No malicious patterns detected
_esm/core/internal/abiItem.js safe No malicious patterns detected; the code is legitimate ABI signature normalization and type checking logic.
_esm/core/internal/abiParameters.js safe No malicious patterns detected; the file implements standard ABI parameter encoding/decoding logic with no exfiltration, obfuscation, or dynamic code execution.
_esm/core/internal/base58.js safe No malicious patterns detected
_esm/core/internal/bytes.js safe Cleared by Jev triage; no further analysis needed
_esm/core/internal/cursor.js safe No malicious patterns detected
_esm/core/internal/ens.js safe Cleared by Jev triage; no further analysis needed
_esm/core/internal/entropy.js safe Cleared by Jev triage; no further analysis needed
_esm/core/internal/errors.js safe Cleared by Jev triage; no further analysis needed
_esm/core/internal/hdKey.js safe No malicious patterns detected
_esm/core/internal/hex.js safe Cleared by Jev triage; no further analysis needed
_esm/core/internal/lru.js safe No malicious patterns detected; the code is a standard LRU cache implementation with no network, filesystem, process, environment, or obfuscated behavior.
_esm/core/internal/mnemonic/wordlists.js safe No malicious patterns detected; the file only re-exports standard BIP39 wordlists from the @scure/bip39 package.
_esm/core/internal/promise.js safe Cleared by Jev triage; no further analysis needed
_esm/core/internal/register.js safe No malicious patterns detected
_esm/core/internal/rpcSchema.js safe No malicious patterns detected; the file contains only an empty export and a source map reference.
_esm/core/internal/rpcSchemas/eth.js safe No malicious patterns detected
_esm/core/internal/rpcSchemas/wallet.js safe The file contains only an empty export statement and a source map reference, with no executable or suspicious code.
_esm/core/internal/rpcTransport.js safe No malicious patterns detected; the file implements a simple RPC transport wrapper with no network, filesystem, process, or dynamic execution concerns.
_esm/core/internal/types.js safe No malicious patterns detected
_esm/core/internal/uid.js safe No malicious patterns detected
_esm/core/internal/webauthn.js safe The code performs legitimate WebAuthn P-256 public key parsing and ASN.1 signature normalization without any malicious patterns such as exfiltration, obfuscation, or unauthorized system access.
_esm/core/version.js safe Cleared by Jev triage; no further analysis needed
_esm/erc4337/EntryPoint.js safe This file contains only static ABI definitions, contract addresses, and type declarations for Ethereum EntryPoint contracts with no executable or malicious code.
_esm/erc4337/RpcSchema.js safe No malicious patterns detected; the file contains only an empty export statement and a source map reference.
_esm/erc4337/UserOperation.js safe No malicious patterns detected; the file contains standard ERC-4337 UserOperation encoding, hashing, and serialization logic with no network, filesystem, process, or dynamic code execution activity.
_esm/erc4337/UserOperationGas.js safe Cleared by Jev triage; no further analysis needed
_esm/erc4337/UserOperationReceipt.js safe Cleared by Jev triage; no further analysis needed
_esm/erc4337/index.js safe No malicious patterns detected
_esm/erc6492/WrappedSignature.js safe The module is a standard, benign implementation of ERC-6492 wrapped signature encoding/decoding (from the 'ox' library); it contains no exfiltration, credential harvesting, obfuscation, process spawning, or dynamic code execution patterns.
_esm/erc6492/index.js safe No malicious patterns detected; the file only re-exports the WrappedSignature module for ERC-6492 signature utilities.
_esm/index.docs.js safe This file only re-exports modules for documentation generation and contains no malicious patterns.
_esm/index.js safe No malicious patterns detected; the file consists solely of static re-exports and documentation for the 'ox' Ethereum utility library.
_esm/trusted-setups/Paths.js safe Cleared by Jev triage; no further analysis needed
_esm/trusted-setups/index.js safe Cleared by Jev triage; no further analysis needed
_esm/trusted-setups/internal/paths.js safe Cleared by Jev triage; no further analysis needed
_esm/version.js safe Cleared by Jev triage; no further analysis needed
_esm/window/index.js safe No malicious patterns detected
core/Abi.ts safe Cleared by Jev triage; no further analysis needed
core/AbiConstructor.ts safe No malicious patterns detected; the code is a standard TypeScript ABI encoding/decoding utility with no network, filesystem, process, or dynamic execution operations.
core/AbiError.ts safe No malicious patterns detected
core/AbiEvent.ts safe No malicious patterns detected; the file only implements ABI event encoding/decoding utilities with standard imports and no external data handling, network, filesystem, or dynamic execution.
core/AbiFunction.ts safe No malicious patterns detected; the file is a legitimate ABI encoding/decoding utility from the ox library with no network, file system, process, or dynamic code execution activity.
core/AbiItem.ts safe Cleared by Jev triage; no further analysis needed
core/AbiParameters.ts safe Cleared by Jev triage; no further analysis needed
core/AccessList.ts safe No malicious patterns detected
core/AccountProof.ts safe Cleared by Jev triage; no further analysis needed
core/Address.ts safe No malicious patterns detected
core/AesGcm.ts safe No malicious patterns detected; the code is a straightforward AES-GCM encryption/decryption utility using the Web Crypto API with PBKDF2 key derivation.
core/Authorization.ts safe No malicious patterns detected; the code is a standard EIP-7702 Authorization utility module with no network, filesystem, process, or obfuscated behavior.
core/Base58.ts safe Cleared by Jev triage; no further analysis needed
core/Base64.ts safe No malicious patterns detected; the code is a clean implementation of Base64 encoding/decoding with no network, filesystem, or dynamic code execution.
core/BinaryStateTree.ts safe No malicious patterns detected; the code is a legitimate Binary State Tree implementation using Blake3 hashing with no network, filesystem, or process interactions.
core/Blobs.ts safe The code implements EIP-4844 blob encoding, hashing, and KZG commitment/proof utilities with no network, filesystem, process, environment, or dynamic execution behavior.
core/Block.ts safe No malicious patterns detected; the file contains only standard Ethereum block type definitions and RPC serialization/deserialization utilities with no network, filesystem, process, or code-execution behavior.
core/BlockOverrides.ts safe Cleared by Jev triage; no further analysis needed
core/Bloom.ts safe Cleared by Jev triage; no further analysis needed
core/Bls.ts safe No malicious patterns detected; the code is a standard BLS12-381 cryptographic utility wrapper around @noble/curves.
core/BlsPoint.ts safe No malicious patterns detected; the code is a legitimate BLS point conversion utility using @noble/curves.
core/Bytes.ts safe Cleared by Jev triage; no further analysis needed
core/Caches.ts safe Cleared by Jev triage; no further analysis needed
core/ContractAddress.ts safe This file implements Ethereum CREATE and CREATE2 contract address derivation using standard cryptographic primitives with no network, filesystem, process, or dynamic code execution concerns.
core/Ens.ts safe Cleared by Jev triage; no further analysis needed
core/Errors.ts safe Cleared by Jev triage; no further analysis needed
core/Fee.ts safe Cleared by Jev triage; no further analysis needed
core/Filter.ts safe Cleared by Jev triage; no further analysis needed
core/Hash.ts safe Cleared by Jev triage; no further analysis needed
core/HdKey.ts safe No malicious patterns detected; the code is a straightforward HD key utility wrapper around @scure/bip32 with no exfiltration, credential harvesting, obfuscation, or dynamic execution.
core/Hex.ts safe No malicious patterns detected; the file implements standard hexadecimal encoding/decoding utilities using only local dependencies and Node's built-in TextEncoder/TextDecoder, with no network, filesystem, process, or dynamic code execution activity.
core/Json.ts safe Cleared by Jev triage; no further analysis needed
core/Kzg.ts safe Cleared by Jev triage; no further analysis needed
core/Log.ts safe No malicious patterns detected; the file contains only type definitions and pure data transformation functions for Ethereum log objects with no network, filesystem, process, or dynamic code execution behavior.
core/Mnemonic.ts safe No malicious patterns detected; the code provides standard BIP39 mnemonic utilities (generation, validation, seed/HD key derivation) with no exfiltration, obfuscation, or suspicious side effects.
core/P256.ts safe No malicious patterns detected in the P256 cryptographic utility module.
core/PersonalMessage.ts safe No malicious patterns detected; the code implements ERC-191 personal message encoding and hashing using only local cryptographic utilities.
core/Provider.ts safe No malicious patterns detected; the code implements a standard EIP-1193 provider abstraction with type-safe RPC handling and error parsing.
core/PublicKey.ts safe No malicious patterns detected; the code is a standard cryptographic public key utility library with no data exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior.
core/Rlp.ts safe No malicious patterns detected; the file implements standard RLP encoding/decoding with no network, filesystem, process, or dynamic code execution concerns.
core/RpcRequest.ts safe Cleared by Jev triage; no further analysis needed
core/RpcResponse.ts safe Cleared by Jev triage; no further analysis needed
core/RpcSchema.ts safe This file is a purely type-level TypeScript RPC schema definition with no runtime logic, network calls, filesystem access, or malicious patterns.
core/RpcTransport.ts safe No malicious patterns detected; the code is a legitimate JSON-RPC HTTP transport implementation for a TypeScript library.
core/Secp256k1.ts safe This is a legitimate secp256k1 cryptographic utility library wrapping @noble/curves with no malicious patterns detected.
core/Signature.ts safe No malicious patterns detected; the code is a standard ECDSA signature utility library with no network, filesystem, process, or obfuscated behavior.
core/Siwe.ts safe The Siwe.ts file implements EIP-4361 Sign-In with Ethereum message creation, parsing, and validation with no malicious patterns such as data exfiltration, credential harvesting, obfuscated code, or dynamic execution detected.
core/Solidity.ts safe Cleared by Jev triage; no further analysis needed
core/StateOverrides.ts safe Cleared by Jev triage; no further analysis needed
core/Transaction.ts safe No malicious patterns detected
core/TransactionEnvelope.ts safe No malicious patterns detected; file contains only type definitions and error classes for Ethereum transaction envelopes with no executable/network/filesystem/credential-harvesting behavior.
core/TransactionEnvelopeEip1559.ts safe This is a legitimate EIP-1559 transaction envelope implementation from the 'ox' library with no malicious patterns, no network calls, no filesystem access, no credential harvesting, and no dynamic code execution.
core/TransactionEnvelopeEip2930.ts safe No malicious patterns detected
core/TransactionEnvelopeEip4844.ts safe No malicious patterns detected; the file implements EIP-4844 transaction envelope serialization/deserialization and validation logic with no network, filesystem, or dynamic code execution concerns.
core/TransactionEnvelopeEip7702.ts safe No malicious patterns detected; the code is a legitimate EIP-7702 transaction envelope implementation with standard cryptographic and serialization operations.
core/TransactionEnvelopeLegacy.ts safe No malicious patterns detected; the code is a legitimate Ethereum legacy transaction envelope implementation from the ox library with standard cryptographic operations, serialization, and validation.
core/TransactionReceipt.ts safe No malicious patterns detected; the file contains only type definitions, constants, and pure conversion functions for Ethereum transaction receipts.
core/TransactionRequest.ts safe No malicious patterns detected
core/TypedData.ts safe No malicious patterns detected; the file is a legitimate EIP-712 typed data implementation using only local imports and standard cryptographic primitives with no network, filesystem, process execution, or dynamic code evaluation.
core/ValidatorData.ts safe No malicious patterns detected
core/Value.ts safe Cleared by Jev triage; no further analysis needed
core/WebAuthnP256.ts safe No malicious patterns detected; the code is a legitimate WebAuthn P256 credential handling library using standard WebAuthn APIs without any suspicious or malicious behavior.
core/WebCryptoP256.ts safe No malicious patterns detected
core/Withdrawal.ts safe Cleared by Jev triage; no further analysis needed
core/internal/abi.ts safe Cleared by Jev triage; no further analysis needed
core/internal/abiConstructor.ts safe Cleared by Jev triage; no further analysis needed
core/internal/abiError.ts safe Cleared by Jev triage; no further analysis needed
core/internal/abiEvent.ts safe Cleared by Jev triage; no further analysis needed
core/internal/abiFunction.ts safe Cleared by Jev triage; no further analysis needed
core/internal/abiItem.ts safe Cleared by Jev triage; no further analysis needed
core/internal/abiParameters.ts safe Cleared by Jev triage; no further analysis needed
core/internal/base58.ts safe The code implements standard Base58 encoding with no network, filesystem, process, or dynamic execution capabilities, and contains no malicious patterns.
core/internal/bytes.ts safe Cleared by Jev triage; no further analysis needed
core/internal/cursor.ts safe No malicious patterns detected; the code is a legitimate binary cursor/reader utility with bounds checking and no external I/O, network, or process execution.
core/internal/ens.ts safe No malicious patterns detected; the code implements ENS DNS packet encoding and labelhash wrapping/unwrapping without external calls, dynamic execution, or filesystem access.
core/internal/entropy.ts safe Cleared by Jev triage; no further analysis needed
core/internal/errors.ts safe Cleared by Jev triage; no further analysis needed
core/internal/hdKey.ts safe No malicious patterns detected; the code is a straightforward adapter for HD key derivation with no network, filesystem, process, or dynamic execution activity.
core/internal/hex.ts safe Cleared by Jev triage; no further analysis needed
core/internal/lru.ts safe Cleared by Jev triage; no further analysis needed
core/internal/mnemonic/wordlists.ts safe This file only re-exports standard BIP39 wordlists from the @scure/bip39 package and contains no malicious patterns.
core/internal/promise.ts safe Cleared by Jev triage; no further analysis needed
core/internal/register.ts safe No malicious patterns detected
core/internal/rpcSchema.ts safe Cleared by Jev triage; no further analysis needed
core/internal/rpcSchemas/eth.ts safe This file contains only TypeScript type definitions for Ethereum JSON-RPC methods with no executable code, network calls, filesystem access, or other malicious patterns.
core/internal/rpcSchemas/wallet.ts safe This file contains only TypeScript type definitions for Ethereum JSON-RPC wallet methods with no executable code, network calls, or malicious patterns.
core/internal/rpcTransport.ts safe No malicious patterns detected; the code defines a standard JSON-RPC transport wrapper without any exfiltration, dynamic execution, filesystem, or process-spawning behavior.
core/internal/types.ts safe Cleared by Jev triage; no further analysis needed
core/internal/uid.ts safe The code is a simple UID generator using Math.random and does not contain any malicious patterns or security concerns.
core/internal/webauthn.ts safe No malicious patterns detected; the file contains only WebAuthn type definitions and cryptographic parsing utilities with no data exfiltration, credential harvesting, obfuscation, or network/file/process manipulation.
core/version.ts safe Cleared by Jev triage; no further analysis needed
erc4337/EntryPoint.ts safe This file contains only static Ethereum ABI definitions and contract address constants for ERC-4337 EntryPoint versions 0.6 and 0.7, with no executable or malicious code.
erc4337/RpcSchema.ts safe No malicious patterns detected
erc4337/UserOperation.ts safe No malicious patterns detected
erc4337/UserOperationGas.ts safe Cleared by Jev triage; no further analysis needed
erc4337/UserOperationReceipt.ts safe Cleared by Jev triage; no further analysis needed
erc4337/index.ts safe This file contains only static ES module re-exports of ERC-4337 utility modules with no executable code, network activity, file system access, or other malicious patterns.
erc6492/WrappedSignature.ts safe The file implements ERC-6492 wrapped signature parsing/serialization with standard ABI and hex utilities, containing only expected constants and pure functions with no network, filesystem, process, or dynamic-execution behavior.
erc6492/index.ts safe No malicious patterns detected; the file only re-exports an ERC-6492 WrappedSignature module with documentation and type declarations.
index.docs.ts safe The file contains only re-export statements for documentation generation via api-extractor; no malicious patterns detected.
index.ts safe This is a barrel/index file for the 'ox' Ethereum utility library that only contains documented module re-exports with no executable code, network calls, credential access, or other malicious patterns.
trusted-setups/Paths.ts safe Cleared by Jev triage; no further analysis needed
trusted-setups/index.ts safe Cleared by Jev triage; no further analysis needed
trusted-setups/internal/paths.ts safe Cleared by Jev triage; no further analysis needed
version.ts safe Cleared by Jev triage; no further analysis needed
window/index.ts safe No malicious patterns detected

Affected version ranges

None of the 4 scanned versions of ox are flagged high or critical. The latest scanned version, 0.14.0, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

0.6.70.14.0
VersionsVerdictCountRangeTop findings
0.9.17 – 0.14.0 Not scanned 2 >=0.9.17 <=0.14.0
0.6.7 – 0.9.6 No issues 4 >=0.6.7 <=0.9.6

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of ox

VersionVerdictFilesScanned
0.9.6 No issues 331 Oct 4, 2026
0.9.3 No issues 331 Oct 4, 2026
0.6.9 No issues 318 Oct 4, 2026
0.6.7 No issues 315 Oct 4, 2026

Frequently asked questions

Is ox safe to use?

Our AI source review of ox@0.6.9 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.

Does ox contain malware?

No malware was identified in ox@0.6.9 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was ox checked?

Togoder Security downloaded the published npm package and had an AI model read its 318 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan ox together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in ox@0.6.9, cost nothing.

Related security reports