micro-eth-signer is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
85
High Risk
Affected versions of this package may leak private keys due to a vulnerability similar to one recently identified in elliptic.js, where private keys could be extracted from signatures. While deterministic signatures remain identical across sessions and can expose sensitive information, hedged signatures introduce randomness in each signing operation, offering stronger protection against such leaks. The noble-curves package already supports hedged signatures, providing a more secure alternative and is now the default method in the patched version.
You are affected if you are using a version that falls within the vulnerable range.
micro-eth-signer is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.1.1 - 0.13.3.
Upgrade the micro-eth-signer library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant