
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
@otplib/plugin-crypto-noble
Advanced tools
Pure JavaScript crypto implementation using noble-hashes for otplib
Pure JavaScript crypto plugin for otplib using @noble/hashes.
npm install @otplib/plugin-crypto-noble
pnpm add @otplib/plugin-crypto-noble
yarn add @otplib/plugin-crypto-noble
This plugin provides HMAC and random byte generation using the @noble/hashes library - a zero-dependency, audited cryptographic implementation in pure JavaScript. It supports all standard hash algorithms:
sha1sha256sha512import { generateSecret, generate } from "otplib";
import { crypto } from "@otplib/plugin-crypto-noble";
import { base32 } from "@otplib/plugin-base32-scure";
// Generate a secret
const secret = generateSecret({ crypto, base32 });
// Generate a token
const token = await generate({
secret,
crypto,
base32,
});
import { generate } from "otplib";
import { crypto } from "@otplib/plugin-crypto-noble";
import { base32 } from "@otplib/plugin-base32-scure";
const token = await generate({
secret: "GEZDGNBVGY3TQOJQGEZDGNBVGY",
algorithm: "sha256",
crypto,
base32,
});
The noble crypto plugin supports both synchronous and asynchronous HMAC operations:
import { crypto } from "@otplib/plugin-crypto-noble";
// Sync HMAC (useful for high-volume operations)
const digest = crypto.hmacSync("sha1", key, data);
// Async HMAC (consistent API with web crypto)
const digest = await crypto.hmac("sha1", key, data);
Use this plugin when:
| Feature | plugin-crypto-noble | plugin-crypto-node | plugin-crypto-web |
|---|---|---|---|
| Node.js | Yes | Yes | No |
| Browser | Yes | No | Yes |
| Edge Runtime | Yes | No | Yes |
| Sync HMAC | Yes | Yes | No |
| Pure JS | Yes | No | No |
| Dependencies | @noble/hashes | None | None |
The @noble/hashes library adds approximately 15KB (gzipped) to your bundle. For browser applications where bundle size is critical, consider using @otplib/plugin-crypto-web instead.
Full documentation available at otplib.yeojz.dev:
FAQs
Pure JavaScript crypto implementation using noble-hashes for otplib
We found that @otplib/plugin-crypto-noble demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.