Togoder security

npm package security report

unicorn-magic npm package: is it safe?

Risky patterns found that deserve a look.

Needs review Version 0.4.0 Files reviewed 2 Size 1.6 KB Scanned

Summary

Togoder Security scanned the npm package unicorn-magic@0.4.0 on Oct 6, 2026. An AI review of 2 source files produced 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
0
medium
2
low

Findings 2

low

Process execution utilities exported

NPS-66E004373CB3

The module exports wrappers around child_process.execFile and execFileSync with a raised maxBuffer. While these are standard APIs and no user-controlled input is used to construct commands in this file, exporting them allows arbitrary subprocess execution by consumers. This is not inherently malicious but is a capability worth noting in a security review, especially since the exported functions accept an 'options' object that is spread after the defaults, permitting callers to override security-relevant options like stdio, shell, uid/gid, env, etc.

node.js:33
low

Re-export of external module

NPS-9A120F1488EA

The file ends with 'export * from ./default.js', which re-exports all named exports from an unexamined local module. This could introduce additional attack surface if default.js contains malicious or unexpected behavior, but it cannot be assessed from the provided snippet.

node.js:52

Files reviewed

FileVerdictWhat the reviewer saw
node.js medium The file contains no direct malicious patterns such as data exfiltration, credential harvesting, obfuscation, or backdoors; it primarily provides path and child_process utility wrappers, though exporting subprocess execution helpers warrants caution.
default.js safe Cleared by Jev triage; no further analysis needed

Affected version ranges

None of the 3 scanned versions of unicorn-magic are flagged high or critical. The latest scanned version, 0.4.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

0.1.00.4.0
VersionsVerdictCountRangeTop findings
0.3.0 โ€“ 0.4.0 Needs review 2 >=0.3.0 <=0.4.0
0.1.0 No issues 1 0.1.0

Full list, including published versions not scanned yet: version ranges API.

Scanned versions of unicorn-magic

VersionVerdictFilesScanned
0.4.0 Needs review 2 Oct 6, 2026
0.3.0 Needs review 2 Oct 6, 2026
0.1.0 No issues 2 Oct 6, 2026

Frequently asked questions

Is unicorn-magic safe to use?

No confirmed malware was found in unicorn-magic@0.4.0, but the review flagged 2 low severity findings for risky patterns worth checking before you rely on it.

Does unicorn-magic contain malware?

No malware was identified in unicorn-magic@0.4.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was unicorn-magic checked?

Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan unicorn-magic together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in unicorn-magic@0.4.0, cost nothing.

Related security reports