Summary
Togoder Security scanned the npm package @lit/reactive-element@2.1.1 on Oct 4, 2026. An AI review of 58 source files produced 3 low severity findings. No malicious behavior, install-time payloads, credential theft or exfiltration were identified.
Findings 3
dynamic code execution
NPS-5620E992A388
The code uses CSSStyleSheet.replaceSync and adoptedStyleSheets to apply CSS styles, which is standard for the lit library's css tag. No eval, Function, or other dynamic code execution mechanisms are present.
DOM manipulation
NPS-44B9F47D3E2B
The adoptStyles function creates <style> elements and appends them to the document or shadow root. This is intended behavior for applying styles and is confined to the page's DOM, not external systems.
Known legitimate polyfill
NPS-7572ECE3913F
This is the official @webcomponents/polyfill-support package from Google/Lit. It installs a globalThis.reactiveElementPolyfillSupport function that integrates ReactiveElement with ShadyCSS/ShadyDOM. No network calls, no obfuscation, no eval, no filesystem access, no environment/credential access, and no process spawning. The UMD wrapper and 'use strict' are standard.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| css-tag.js | safe | This is the standard lit-html CSS tag implementation from Google's Lit library, containing no malicious patterns. |
| decorators.js | safe | No malicious patterns detected |
| decorators/base.js | safe | No malicious patterns detected; the file is a standard Lit decorator utility with no network, filesystem, process, or dynamic execution behavior. |
| decorators/custom-element.js | safe | No malicious patterns detected; the code is a standard Lit customElement decorator from Google with clear licensing and no obfuscation or risky behavior. |
| decorators/event-options.js | safe | No malicious patterns detected; the code is a legitimate event options decorator from Lit that assigns options to a function or method. |
| decorators/property.js | safe | This is the standard Lit library property decorator implementation with no malicious patterns, network activity, credential access, or dynamic code execution. |
| decorators/query-all.js | safe | No malicious patterns detected |
| decorators/query-assigned-elements.js | safe | No malicious patterns detected |
| decorators/query-assigned-nodes.js | safe | No malicious patterns detected |
| decorators/query-async.js | safe | No malicious patterns detected in this standard Lit reactive property decorator utility. |
| decorators/query.js | safe | No malicious patterns detected |
| decorators/state.js | safe | No malicious patterns detected; this is a benign Lit decorator definition from Google's lit library that simply re-exports a state property decorator. |
| development/css-tag.js | safe | No malicious patterns detected; this is a legitimate Lit CSS-tag utility module with no data exfiltration, credential harvesting, obfuscation, or process execution. |
| development/decorators.js | safe | Cleared by Jev triage; no further analysis needed |
| development/decorators/base.js | safe | Cleared by Jev triage; no further analysis needed |
| development/decorators/custom-element.js | safe | No malicious patterns detected |
| development/decorators/event-options.js | safe | Cleared by Jev triage; no further analysis needed |
| development/decorators/property.js | safe | No malicious patterns detected; the file is legitimate Lit library decorator code with only expected warnings and metadata handling. |
| development/decorators/query-all.js | safe | Cleared by Jev triage; no further analysis needed |
| development/decorators/query-assigned-elements.js | safe | Cleared by Jev triage; no further analysis needed |
| development/decorators/query-assigned-nodes.js | safe | Cleared by Jev triage; no further analysis needed |
| development/decorators/query-async.js | safe | Cleared by Jev triage; no further analysis needed |
| development/decorators/query.js | safe | No malicious patterns detected; the file contains a legitimate Lit library property decorator with only development-mode warning logic and no network, filesystem, process, or dynamic code execution behavior. |
| development/decorators/state.js | safe | Cleared by Jev triage; no further analysis needed |
| development/polyfill-support.js | safe | No malicious patterns detected |
Show 33 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| development/reactive-controller.js | safe | No malicious patterns detected |
| development/reactive-element.js | safe | No malicious patterns detected; this is the standard Lit ReactiveElement base class implementation with dev-mode warnings and no network, filesystem, process, or dynamic code execution behavior. |
| node/css-tag.js | safe | The code is a minified build of lit's css-tag module, which safely handles CSS styles without any malicious patterns such as data exfiltration, credential harvesting, or backdoor installation. |
| node/decorators.js | safe | No malicious patterns detected |
| node/decorators/base.js | safe | No malicious patterns detected; the file is a standard Lit decorator utility with no network, filesystem, process, or dynamic execution behavior. |
| node/decorators/custom-element.js | safe | No malicious patterns detected; the code is a standard Lit customElement decorator from Google with clear licensing and no obfuscation or risky behavior. |
| node/decorators/event-options.js | safe | No malicious patterns detected; the code is a legitimate event options decorator from Lit that assigns options to a function or method. |
| node/decorators/property.js | safe | This is the standard Lit library property decorator implementation with no malicious patterns, network activity, credential access, or dynamic code execution. |
| node/decorators/query-all.js | safe | No malicious patterns detected |
| node/decorators/query-assigned-elements.js | safe | No malicious patterns detected |
| node/decorators/query-assigned-nodes.js | safe | No malicious patterns detected |
| node/decorators/query-async.js | safe | No malicious patterns detected in this standard Lit reactive property decorator utility. |
| node/decorators/query.js | safe | No malicious patterns detected |
| node/decorators/state.js | safe | No malicious patterns detected; this is a benign Lit decorator definition from Google's lit library that simply re-exports a state property decorator. |
| node/development/css-tag.js | safe | No malicious patterns detected; the file is legitimate Lit CSS-tag implementation code with no network, filesystem, process, or credential-related activity. |
| node/development/decorators.js | safe | Cleared by Jev triage; no further analysis needed |
| node/development/decorators/base.js | safe | Cleared by Jev triage; no further analysis needed |
| node/development/decorators/custom-element.js | safe | The code is a standard Lit decorator for defining custom elements and contains no malicious patterns. |
| node/development/decorators/event-options.js | safe | Cleared by Jev triage; no further analysis needed |
| node/development/decorators/property.js | safe | No malicious patterns detected; the file is standard Lit decorator implementation code with no data exfiltration, credential harvesting, obfuscation, network activity, filesystem abuse, or shell execution. |
| node/development/decorators/query-all.js | safe | Cleared by Jev triage; no further analysis needed |
| node/development/decorators/query-assigned-elements.js | safe | Cleared by Jev triage; no further analysis needed |
| node/development/decorators/query-assigned-nodes.js | safe | Cleared by Jev triage; no further analysis needed |
| node/development/decorators/query-async.js | safe | Cleared by Jev triage; no further analysis needed |
| node/development/decorators/query.js | safe | No malicious patterns detected; the code is a standard Lit decorator implementation for DOM querying with no network, filesystem, process, or obfuscated behavior. |
| node/development/decorators/state.js | safe | Cleared by Jev triage; no further analysis needed |
| node/development/reactive-controller.js | safe | The file contains only a source map reference comment and no executable code or malicious patterns |
| node/development/reactive-element.js | safe | No malicious patterns detected; this is the legitimate Lit ReactiveElement base class with only standard dev-mode warnings and global state management. |
| node/reactive-controller.js | safe | The file contains only a source map reference comment and no executable code or malicious patterns |
| node/reactive-element.js | safe | No malicious patterns detected |
| polyfill-support.js | safe | This is a legitimate Web Components polyfill with no malicious patterns detected. |
| reactive-controller.js | safe | The file contains only a source map reference comment and no executable code or malicious patterns |
| reactive-element.js | safe | This is the standard Lit ReactiveElement implementation from Google with no malicious patterns detected. |
Scanned versions of @lit/reactive-element
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 2.1.1 | No issues | 58 | Oct 4, 2026 |
Frequently asked questions
Is @lit/reactive-element safe to use?
Our AI source review of @lit/reactive-element@2.1.1 found no malicious code: no install-time payloads, credential theft, exfiltration, obfuscated loaders or backdoors.
Does @lit/reactive-element contain malware?
No malware was identified in @lit/reactive-element@2.1.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @lit/reactive-element checked?
Togoder Security downloaded the published npm package and had an AI model read its 58 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @lit/reactive-element together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @lit/reactive-element@2.1.1, cost nothing.