# lightningcss@1.33.0 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:24:53.000Z
- Files reviewed: 5
- Findings: 1 medium, 3 low severity findings
- Report: https://security.togoder.click/npm/lightningcss
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package lightningcss@1.33.0 on Oct 6, 2026. An AI review of 5 source files produced 1 medium, 3 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Dynamic import with computed module name

Finding ID: `NPS-6C18DD52DEF4`

File: `node/index.js:15`

The code constructs a module name dynamically using platform, architecture, and libc detection (e.g., 'lightningcss-linux-x64-gnu') and attempts to require it. While this appears to be a legitimate pattern for loading platform-specific native binaries, the dynamic require could potentially be exploited if an attacker can influence the resolved module path or if a malicious package with a matching name exists in the registry.

### [low] Top-level code execution on import

Finding ID: `NPS-A66B9D5EFD9D`

File: `node/index.js:1`

The file executes platform detection and native module loading immediately when imported, including calling detect-libc's familySync() and attempting to load native binaries. This is typical for wrapper packages but does involve top-level filesystem access and native code loading.

### [low] Dynamic module loading with fallback

Finding ID: `NPS-31BCA9F590D3`

File: `node/index.js:15`

The try/catch attempts to require a native .node file from the parent directory if the scoped package fails. This fallback mechanism could potentially load unexpected native code if the package structure is manipulated.

### [low] Function wrapping and option modification

Finding ID: `NPS-C1E902D1FCB9`

File: `node/index.js:24`

The wrap function modifies the options object by replacing the visitor function and injecting dependency tracking. This is benign in this context but represents code that intercepts and modifies user-provided callbacks.

## Files reviewed

- `node/index.js` (medium): The code appears to be a legitimate native module loader for lightningcss with platform detection, but uses dynamic require patterns and top-level execution that warrant caution.
- `node/browserslistToTargets.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/composeVisitors.js` (safe): Cleared by Jev triage; no further analysis needed
- `node/flags.js` (safe): No malicious patterns detected
- `node/index.mjs` (safe): Cleared by Jev triage; no further analysis needed

## Version ranges

None of the 2 scanned versions of lightningcss are flagged high or critical. The latest scanned version, 1.33.0, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 1.32.0 – 1.33.0 (`>=1.32.0 <=1.33.0`): medium (Dynamic import with computed module name)
- 1.27.0 (`1.27.0`): not scanned

## Scanned versions

- [1.33.0](https://security.togoder.click/npm/lightningcss@1.33.0): medium, 2026-10-06T14:24:53.000Z
- [1.32.0](https://security.togoder.click/npm/lightningcss@1.32.0): medium, 2026-10-06T14:17:44.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
