Togoder security

npm package security report

uint8arrays npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 3.1.1 Files reviewed 21 Size 9.4 KB Scanned

Summary

Togoder Security scanned the npm package uint8arrays@3.1.1 on Oct 4, 2026. An AI review of 21 source files produced 2 medium severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
0
low

Findings 2

medium

missing input validation

NPS-F1613054D1FD

The length parameter is not validated against the total size of the input arrays. A caller-supplied length greater than the actual data length results in uninitialized data being returned, and a negative or non-integer length could cause unexpected behavior in allocUnsafe.

esm/src/concat.js:2
medium

uninitialized memory exposure

NPS-7802E859CD53

allocUnsafe allocates uninitialized memory. When an explicit length larger than the sum of the input array lengths is provided, the returned buffer will contain uninitialized heap memory bytes after the copied data. This can leak sensitive process memory (e.g., credentials, keys) to callers or consumers of the output.

esm/src/concat.js:5

Files reviewed

FileVerdictWhat the reviewer saw
esm/src/concat.js medium Function uses allocUnsafe with an unvalidated caller-supplied length, potentially exposing uninitialized memory; no exfiltration, execution, or backdoor patterns found.
cjs/src/alloc.js safe Cleared by Jev triage; no further analysis needed
cjs/src/compare.js safe Cleared by Jev triage; no further analysis needed
cjs/src/concat.js safe Cleared by Jev triage; no further analysis needed
cjs/src/equals.js safe Cleared by Jev triage; no further analysis needed
cjs/src/from-string.js safe Cleared by Jev triage; no further analysis needed
cjs/src/index.js safe Cleared by Jev triage; no further analysis needed
cjs/src/to-string.js safe Cleared by Jev triage; no further analysis needed
cjs/src/util/as-uint8array.js safe Cleared by Jev triage; no further analysis needed
cjs/src/util/bases.js safe Cleared by Jev triage; no further analysis needed
cjs/src/xor.js safe Cleared by Jev triage; no further analysis needed
esm/src/alloc.js safe Cleared by Jev triage; no further analysis needed
esm/src/compare.js safe Cleared by Jev triage; no further analysis needed
esm/src/equals.js safe Cleared by Jev triage; no further analysis needed
esm/src/from-string.js safe Cleared by Jev triage; no further analysis needed
esm/src/index.js safe Cleared by Jev triage; no further analysis needed
esm/src/to-string.js safe Cleared by Jev triage; no further analysis needed
esm/src/util/as-uint8array.js safe Cleared by Jev triage; no further analysis needed
esm/src/util/bases.js safe Cleared by Jev triage; no further analysis needed
esm/src/xor.js safe Cleared by Jev triage; no further analysis needed
index.js safe Cleared by Jev triage; no further analysis needed

Affected version ranges

None of the 2 scanned versions of uint8arrays are flagged high or critical. The latest scanned version, 3.1.1, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

2.1.53.1.1
VersionsVerdictCountRangeTop findings
3.1.1 Needs review 1 3.1.1 uninitialized memory exposure; missing input validation
3.1.0 No issues 1 3.1.0
2.1.5 Not scanned 1 2.1.5

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of uint8arrays

VersionVerdictFilesScanned
3.1.1 Needs review 21 Oct 4, 2026
3.1.0 No issues 19 Oct 4, 2026

Frequently asked questions

Is uint8arrays safe to use?

No confirmed malware was found in uint8arrays@3.1.1, but the review flagged 2 medium severity findings for risky patterns worth checking before you rely on it.

Does uint8arrays contain malware?

No malware was identified in uint8arrays@3.1.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was uint8arrays checked?

Togoder Security downloaded the published npm package and had an AI model read its 21 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan uint8arrays together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in uint8arrays@3.1.1, cost nothing.

Related security reports