Togoder security

npm package security report

pretty-format@27.5.1 security report

Risky patterns found that deserve a look.

Needs review Version 27.5.1 Files reviewed 12 Size 44.0 KB Scanned

Summary

Togoder Security scanned the npm package pretty-format@27.5.1 on Oct 6, 2026. An AI review of 12 source files produced 1 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
3
low

Findings 4

medium

Dynamic code execution via Function constructor

NPS-14D7E22260C0

The IIFE used to determine the global object falls back to Function('return this')() when neither globalThis, global, self, nor window are defined. This constructs and executes code dynamically at module load time. While this is a known pattern used by Jest and similar libraries to obtain the global object, the use of the Function constructor is a code-evaluation primitive that could be abused or flagged by security scanners, and its presence in a serialization plugin is unnecessary for the stated functionality.

build/plugins/AsymmetricMatcher.js:18
low

Global object tampering / non-standard property access

NPS-E5B1B0232020

The code reads global['jest-symbol-do-not-touch'] before falling back to global.Symbol. This accesses a non-standard global property. Although the name suggests this is intentional (to allow Jest to inject a shared symbol), reading arbitrary global properties from a plugin is a pattern that could be exploited in a compromised environment and may indicate hidden backdoor hooks if the property were writable by an attacker.

build/plugins/AsymmetricMatcher.js:24
low

top-level side effect

NPS-66405B45FD0E

The module performs top-level global object resolution on import, accessing jest-symbol-do-not-touch and Symbol on the global object. This runs at import time but only reads symbols and does not exfiltrate data or execute external code.

build/plugins/ReactTestComponent.js:14
low

dynamic code execution

NPS-72E81A600A1D

The global object detection fallback uses Function('return this')(), which is a form of dynamic code execution via the Function constructor. While this is a common safe pattern for obtaining the global object when globalThis/global/self/window are all unavailable, it is still a code-injection-adjacent construct that warrants review.

build/plugins/ReactTestComponent.js:20

Files reviewed

FileVerdictWhat the reviewer saw
build/plugins/AsymmetricMatcher.js medium The file is a legitimate Jest pretty-format plugin for asymmetric matchers, but it uses the Function constructor as a global-object fallback (medium-risk dynamic code execution pattern) and reads a non-standard global property; no exfiltration, credential harvesting, obfuscation, or network/process activity was found.
build/plugins/ReactTestComponent.js medium No malicious behavior detected; the only notable pattern is the standard Function('return this')() global resolution fallback, which is a benign but dynamic code execution idiom.
build/collections.js safe No malicious patterns detected
build/index.js safe No malicious patterns detected in this Jest pretty-format build file; it contains only standard serialization and plugin-loading logic with no network, credential, process, or dynamic execution activity.
build/plugins/ConvertAnsi.js safe The code is a Jest plugin that converts ANSI escape codes to human-readable strings using only ansi-regex and ansi-styles, with no suspicious behavior.
build/plugins/DOMCollection.js safe No malicious patterns detected; the code is a standard Jest DOM collection serializer plugin with no network, filesystem, process execution, or obfuscated behavior.
build/plugins/DOMElement.js safe No malicious patterns detected
build/plugins/Immutable.js safe This appears to be a legitimate Jest pretty-format plugin for serializing Immutable.js data structures, with no malicious patterns detected.
build/plugins/ReactElement.js safe No malicious patterns detected; this is legitimate Jest React element serialization plugin code from Facebook.
build/plugins/lib/escapeHTML.js safe No malicious patterns detected
build/plugins/lib/markup.js safe No malicious patterns detected; the code is a benign React element serialization module from Jest with proper HTML escaping and no network, filesystem, or process operations.
build/types.js safe Cleared by Jev triage; no further analysis needed

Affected version ranges

None of the 2 scanned versions of pretty-format are flagged high or critical. The latest scanned version, 30.4.1, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.

3.8.030.4.1
VersionsVerdictCountRangeTop findings
29.7.0 โ€“ 30.4.1 Not scanned 3 >=29.7.0 <=30.4.1
27.5.1 Needs review 1 27.5.1 Dynamic code execution via Function constructor
3.8.0 No issues 1 3.8.0

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of pretty-format

VersionVerdictFilesScanned
27.5.1 Needs review 12 Oct 6, 2026
3.8.0 No issues 4 Oct 6, 2026

Frequently asked questions

Is pretty-format safe to use?

No confirmed malware was found in pretty-format@27.5.1, but the review flagged 1 medium, 3 low severity findings for risky patterns worth checking before you rely on it.

Does pretty-format contain malware?

No malware was identified in pretty-format@27.5.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was pretty-format checked?

Togoder Security downloaded the published npm package and had an AI model read its 12 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan pretty-format together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in pretty-format@27.5.1, cost nothing.

Related security reports