Summary
Togoder Security scanned the npm package unicorn-magic@0.3.0 on Oct 6, 2026. An AI review of 2 source files produced 2 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 2
Process execution utilities exported
NPS-66E004373CB3
The module exports wrappers around child_process.execFile and execFileSync with a raised maxBuffer. While these are standard APIs and no user-controlled input is used to construct commands in this file, exporting them allows arbitrary subprocess execution by consumers. This is not inherently malicious but is a capability worth noting in a security review, especially since the exported functions accept an 'options' object that is spread after the defaults, permitting callers to override security-relevant options like stdio, shell, uid/gid, env, etc.
Re-export of external module
NPS-9A120F1488EA
The file ends with 'export * from ./default.js', which re-exports all named exports from an unexamined local module. This could introduce additional attack surface if default.js contains malicious or unexpected behavior, but it cannot be assessed from the provided snippet.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| node.js | medium | The file contains no direct malicious patterns such as data exfiltration, credential harvesting, obfuscation, or backdoors; it primarily provides path and child_process utility wrappers, though exporting subprocess execution helpers warrants caution. |
| default.js | safe | Cleared by Jev triage; no further analysis needed |
Affected version ranges
None of the 3 scanned versions of unicorn-magic are flagged high or critical. The latest scanned version, 0.4.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.
| Versions | Verdict | Count | Range | Top findings |
|---|---|---|---|---|
| 0.3.0 โ 0.4.0 | Needs review | 2 | >=0.3.0 <=0.4.0 | |
| 0.1.0 | No issues | 1 | 0.1.0 |
Full list, including published versions not scanned yet: version ranges API.
Scanned versions of unicorn-magic
Frequently asked questions
Is unicorn-magic safe to use?
No confirmed malware was found in unicorn-magic@0.3.0, but the review flagged 2 low severity findings for risky patterns worth checking before you rely on it.
Does unicorn-magic contain malware?
No malware was identified in unicorn-magic@0.3.0 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was unicorn-magic checked?
Togoder Security downloaded the published npm package and had an AI model read its 2 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan unicorn-magic together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in unicorn-magic@0.3.0, cost nothing.