Summary
Togoder Security scanned the npm package pretty-format@27.5.1 on Oct 6, 2026. An AI review of 12 source files produced 1 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 4
Dynamic code execution via Function constructor
NPS-14D7E22260C0
The IIFE used to determine the global object falls back to Function('return this')() when neither globalThis, global, self, nor window are defined. This constructs and executes code dynamically at module load time. While this is a known pattern used by Jest and similar libraries to obtain the global object, the use of the Function constructor is a code-evaluation primitive that could be abused or flagged by security scanners, and its presence in a serialization plugin is unnecessary for the stated functionality.
Global object tampering / non-standard property access
NPS-E5B1B0232020
The code reads global['jest-symbol-do-not-touch'] before falling back to global.Symbol. This accesses a non-standard global property. Although the name suggests this is intentional (to allow Jest to inject a shared symbol), reading arbitrary global properties from a plugin is a pattern that could be exploited in a compromised environment and may indicate hidden backdoor hooks if the property were writable by an attacker.
top-level side effect
NPS-66405B45FD0E
The module performs top-level global object resolution on import, accessing jest-symbol-do-not-touch and Symbol on the global object. This runs at import time but only reads symbols and does not exfiltrate data or execute external code.
dynamic code execution
NPS-72E81A600A1D
The global object detection fallback uses Function('return this')(), which is a form of dynamic code execution via the Function constructor. While this is a common safe pattern for obtaining the global object when globalThis/global/self/window are all unavailable, it is still a code-injection-adjacent construct that warrants review.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| build/plugins/AsymmetricMatcher.js | medium | The file is a legitimate Jest pretty-format plugin for asymmetric matchers, but it uses the Function constructor as a global-object fallback (medium-risk dynamic code execution pattern) and reads a non-standard global property; no exfiltration, credential harvesting, obfuscation, or network/process activity was found. |
| build/plugins/ReactTestComponent.js | medium | No malicious behavior detected; the only notable pattern is the standard Function('return this')() global resolution fallback, which is a benign but dynamic code execution idiom. |
| build/collections.js | safe | No malicious patterns detected |
| build/index.js | safe | No malicious patterns detected in this Jest pretty-format build file; it contains only standard serialization and plugin-loading logic with no network, credential, process, or dynamic execution activity. |
| build/plugins/ConvertAnsi.js | safe | The code is a Jest plugin that converts ANSI escape codes to human-readable strings using only ansi-regex and ansi-styles, with no suspicious behavior. |
| build/plugins/DOMCollection.js | safe | No malicious patterns detected; the code is a standard Jest DOM collection serializer plugin with no network, filesystem, process execution, or obfuscated behavior. |
| build/plugins/DOMElement.js | safe | No malicious patterns detected |
| build/plugins/Immutable.js | safe | This appears to be a legitimate Jest pretty-format plugin for serializing Immutable.js data structures, with no malicious patterns detected. |
| build/plugins/ReactElement.js | safe | No malicious patterns detected; this is legitimate Jest React element serialization plugin code from Facebook. |
| build/plugins/lib/escapeHTML.js | safe | No malicious patterns detected |
| build/plugins/lib/markup.js | safe | No malicious patterns detected; the code is a benign React element serialization module from Jest with proper HTML escaping and no network, filesystem, or process operations. |
| build/types.js | safe | Cleared by Jev triage; no further analysis needed |
Affected version ranges
None of the 2 scanned versions of pretty-format are flagged high or critical. The latest scanned version, 30.4.1, is not scanned. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 29.7.0 โ 30.4.1 | Not scanned | 3 | >=29.7.0 <=30.4.1 | |
| 27.5.1 | Needs review | 1 | 27.5.1 | Dynamic code execution via Function constructor |
| 3.8.0 | No issues | 1 | 3.8.0 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of pretty-format
Frequently asked questions
Is pretty-format safe to use?
No confirmed malware was found in pretty-format@27.5.1, but the review flagged 1 medium, 3 low severity findings for risky patterns worth checking before you rely on it.
Does pretty-format contain malware?
No malware was identified in pretty-format@27.5.1 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was pretty-format checked?
Togoder Security downloaded the published npm package and had an AI model read its 12 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan pretty-format together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in pretty-format@27.5.1, cost nothing.