Summary
Togoder Security scanned the npm package @iconify/react@6.0.2 on Oct 6, 2026. An AI review of 5 source files produced 2 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 8
Dynamic code execution via dangerouslySetInnerHTML
NPS-D0A3FCED089E
The render function sets componentProps.dangerouslySetInnerHTML.__html from icon body content. While the package attempts to mitigate this with Trusted Types (cleanUpInnerHTML/window.trustedTypes.createPolicy), if Trusted Types is not enforced the raw SVG body from icon data (which can be loaded at runtime from remote API endpoints via loadIcons/fetchAPIModule) is injected as HTML. If an attacker can control icon data (e.g., via a compromised or malicious API provider configured via addAPIProvider or window.IconifyProviders), this could lead to XSS.
Dynamic innerHTML assignment
NPS-842E2820056E
The render function uses dangerouslySetInnerHTML to inject SVG body content. While the code includes a cleanUpInnerHTML function that attempts to use Trusted Types policy, this is primarily to satisfy CSP requirements and does not actually sanitize the HTML. If untrusted icon data is passed, this could lead to XSS. The comment explicitly states 'This code doesn't actually clean up anything.'
Dynamic RegExp construction from icon body content
NPS-04908E238504
replaceIDs builds a new RegExp from icon-provided id values (escaped) and performs global string replacement on SVG body. While the id is escaped, this pattern of dynamically constructing regexes from data derived from remotely loaded content is a fragile pattern and can be abused for ReDoS or injection if escaping is ever bypassed.
Network requests to external hosts
NPS-93DF4F8890BD
The module performs network fetches to external Iconify API hosts at runtime (https://api.iconify.design, https://api.simplesvg.com, https://api.unisvg.com) using the global fetch. This is expected functionality for icon loading, but it means icon data is retrieved from third-party servers and then rendered into the DOM, expanding the attack surface for supply-chain/remote-content injection.
Use of window/document global configuration at import time
NPS-ED5B280136F6
On import, the module reads window.IconifyPreload and window.IconifyProviders and calls addCollection/addAPIProvider with that attacker-influenceable global data. Combined with the dynamic loading and innerHTML rendering paths, this allows any script that can set those globals to influence which remote servers are contacted and what icon content is rendered.
External network requests
NPS-0D8EB23BC59E
The code makes network requests to external APIs (api.iconify.design, api.simplesvg.com, api.unisvg.com) to fetch icon data. This is expected functionality for an icon library but could be used for data exfiltration if the icon names or requests contain sensitive information.
Global object modification
NPS-7B3369636201
The code reads from window.IconifyPreload and window.IconifyProviders and processes them at import time. This allows external code to inject icon collections and API providers, which could be exploited if an attacker can control these global variables.
Dynamic URL construction
NPS-703317359300
The send function constructs URLs dynamically using prefix and icon names without validation in some paths. This could potentially be used for SSRF or other injection attacks if the inputs are not properly sanitized.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/iconify.cjs | medium | This is the legitimate Iconify React package; no backdoors, credential harvesting, or process execution were found, but it performs expected remote fetches and renders remotely-loaded SVG via dangerouslySetInnerHTML, which carries XSS/remote-content risk if icon sources are untrusted. |
| dist/iconify.js | medium | This appears to be a legitimate icon library (Iconify) with expected functionality, but contains a dangerous innerHTML assignment pattern and makes external network requests; the cleanUpInnerHTML function is explicitly noted as not actually sanitizing content. |
| dist/offline.cjs | safe | No malicious patterns detected; the code is a legitimate Iconify React offline rendering library with only local SVG manipulation and no network, filesystem, process, or dynamic code execution activity. |
| dist/offline.js | safe | The code is a legitimate Iconify React component library with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, dynamic code execution, or unauthorized network/file system access. |
| vitest.config.ts | safe | Cleared by Jev triage; no further analysis needed |
Frequently asked questions
Is @iconify/react safe to use?
No confirmed malware was found in @iconify/react@6.0.2, but the review flagged 2 medium, 6 low severity findings for risky patterns worth checking before you rely on it.
Does @iconify/react contain malware?
No malware was identified in @iconify/react@6.0.2 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @iconify/react checked?
Togoder Security downloaded the published npm package and had an AI model read its 5 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @iconify/react together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @iconify/react@6.0.2, cost nothing.