NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #4818 most downloaded on npm
Audited & minimal JS implementation of Salsa20, ChaCha and AES
Last release 1 months ago
27 Aug 2026
Release timing varies
gaps range from 8 days to 4 months
Nearly every release is documented
notes for 25 of 26 stable releases
4 versions withdrawn
withdrawn after publishing
3 years old
30 releases · first in 2023
One column per quarter.
ChaCha / Salsa: reject output buffers that partially overlap unread input
Full Changelog: 2.3.0...2.4.0
AEAD strictness: passing AAD to a cipher that doesn't support it now throws AAD not supported instead of silently ignoring it. Applies to both native
Hardening
Boost AES-SIV speed by 20%
Full Changelog: 2.2.0...2.3.0
AAD not supported instead of silently ignoring it. Applies to both native ciphers and the WebCrypto wrappers via a new withAAD cipher parameter.aes: bad decrypt instead of a padding-specific message, reducing padding-oracle signal.minLen now enforces the NIST SP 800-38G minimum of 2 in addition to radix ** minLen >= 100; stricter radix encoding guards.March 2026 self-audit (all files): no major issues found
ctr from webcrypto submodule used wrong counter wrappingUint8Array, while TS 5.9+ made it generic Uint8Array<ArrayBuffer>TS2345Full Changelog: 2.1.1...2.2.0
ctr implementation from the webcrypto submodule using incorrect counter wrapping.Uint8Array, while TypeScript 5.9+ made it generic: Uint8Array<ArrayBuffer>.TS2345.Deprecate old siv export in aes.js because it was an alias to gcmsiv
siv export in aes.js because it was an alias to gcmsivFull Changelog: 2.0.1...2.1.0
siv export in aes.js because it was an alias for gcmsiv.Disable extension-less imports. If you've used /chacha , switch to /chacha.js now. See 2.0.0 for more details.
/chacha, switch to /chacha.js now. See 2.0.0 for more details.This GH release does not include NPM & JSR attestations, until we fix bugs related to newly added GitHub Immutable Releases
Full Changelog: 2.0.0...2.0.1
/chacha, switch to /chacha.js. See 2.0.0 for more details.package.json to ensure TypeScript autocompletion.This GitHub release does not include NPM and JSR attestations due to bugs related to newly added GitHub Immutable Releases.
The package is now ESM-only. ESM can finally be loaded from common.js on node v20.19+
.js extension must be used for all modules
@noble/ciphers/aes@noble/ciphers/aes.jsrandomBytes and managedNonce to utils.jsstring_assert (use utils), _micro and crypto (use webcrypto)Full Changelog: 1.3.0...2.0.0
.js extension must be used for all modules.
@noble/ciphers/aes@noble/ciphers/aes.jsrandomBytes and managedNonce from WebCrypto to utils.js.Uint8Array; strings are prohibited.abytes to utils and removed ahash and toBytes._assert module (use utils), _micro, and crypto (use webcrypto).Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Modules are now available with .js extension
.js extension
@noble/ciphers/chacha@noble/ciphers/chacha.jsFull Changelog: 1.2.1...1.3.0
.js extension.
@noble/ciphers/chacha@noble/ciphers/chacha.jsUint8Array toHex and fromHex when available, providing a 13× speed-up on 256-byte arrays and a 20× speed-up on 32 KB arrays.utils.randomBytes has the same Uint8Array return type in older Node.js versions._assert into utils.siv to gcmsiv.erasableSyntaxOnly.Use typescript verbatimModuleSyntax to support future node.js type stripping
Full Changelog: 1.2.0...1.2.1
verbatimModuleSyntax to support future Node.js type stripping.The package is now available on JSR .
_assertFull Changelog: 1.1.3...1.2.0
isolatedDeclarations option, which substantially simplifies automatic documentation generation and more.
_assert module.Harden input / output buffer checks
Full Changelog: 1.1.2...1.1.3
Prohibit input and output overlaps
Full Changelog: https://github.com/paulmillr/noble-ciphers/compare/1.1.1...1.1.2
Fix usage with unaligned output. Closes gh-47
output. Closes gh-47output is zeroized before usageFull Changelog: https://github.com/paulmillr/noble-ciphers/compare/1.1.0...1.1.1
output. Closes #47.output is zeroized before use.Improve input validation logic: move key, nonce & input validation into wrapCipher
Full Changelog: https://github.com/paulmillr/noble-ciphers/compare/1.0.0...1.1.0
wrapCipher.
Prohibit AES-GCM nonces smaller than 8 bytes
Full Changelog: https://github.com/paulmillr/noble-ciphers/compare/0.6.0...1.0.0
Implement AESKW, AESKWP from RFC 3394 / RFC 5649
arx: Remove hard-dependency on TextEncoder
sigma variable for hsalsaFull Changelog: https://github.com/paulmillr/noble-ciphers/compare/0.5.2...0.5.3
@ocavue made their first contribution in https://github.com/paulmillr/noble-ciphers/pull/27
Full Changelog: https://github.com/paulmillr/noble-ciphers/compare/0.5.1...0.5.2
@mirceanis made their first contribution in https://github.com/paulmillr/noble-ciphers/pull/25
Import bugfix
Full Changelog: https://github.com/paulmillr/noble-ciphers/compare/0.5.0...0.5.1
Merge all webcrypto modules into one @noble/ciphers/webcrypto
@noble/ciphers/webcryptoFull Changelog: https://github.com/paulmillr/noble-ciphers/compare/0.4.1...0.5.0
AES: fix ctr mode nonce mutation
utils improvements
isBytes: improve reliability in bad environments such as jsdomconcatBytes: improve safety by early-checking the typeequalBytes: make constant-timeFull Changelog: https://github.com/paulmillr/noble-ciphers/compare/0.4.0...0.4.1
ECB, CBC, CTR, GCM, SIV modes are available
@noble/ciphers/aes and webcrypto @noble/ciphers/webcrypto/aesgcm(key, nonce). AES mode length is automatically selected based on key lengthcryptoSubtleUtilsFull Changelog: https://github.com/paulmillr/noble-ciphers/compare/0.3.0...0.4.0
Add webcrypto aes-gcm opitonal aad by @kigawas in https://github.com/paulmillr/noble-ciphers/pull/6
@noble/ciphers/simpleFull Changelog: https://github.com/paulmillr/noble-ciphers/compare/0.2.0...0.3.0
Add @noble/ciphers/simple hassle-free module
@noble/ciphers/simple hassle-free moduleoutput optional param to AEADs, to be able to reduce allocationssalsa20_poly1305 to salsa20poly1305chacha20_poly1305 to chacha20poly1305xchacha20_poly1305 to xchacha20poly1305Full Changelog: https://github.com/paulmillr/noble-ciphers/compare/0.1.4...0.2.0
Fix byte offset bug https://github.com/paulmillr/noble-ciphers/pull/2
Fix byte offset bug https://github.com/paulmillr/noble-ciphers/pull/2
Full Changelog: https://github.com/paulmillr/noble-ciphers/compare/0.1.3...0.1.4
A few build improvements Full Changelog: https://github.com/paulmillr/noble-ciphers/compare/0.1.2...0.1.3
A few build improvements
Full Changelog: https://github.com/paulmillr/noble-ciphers/compare/0.1.2...0.1.3
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →