Summary
Togoder Security scanned the npm package lit-html@3.3.1 on Oct 4, 2026. An AI review of 120 source files produced 11 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 19
Intentional unsafe HTML rendering
NPS-0A113B18E542
The unsafeHTML directive explicitly bypasses HTML escaping and renders raw HTML into the DOM. While this is a documented and intentional feature of the lit-html library, it is a dangerous pattern that can lead to cross-site scripting (XSS) if any user-controlled data is passed to it. The code even includes a warning comment about this danger.
TemplateResult impersonation
NPS-AA6D7F1130AE
The directive manually constructs an object that mimics a lit-html TemplateResult, including internal properties like '_$litType$'. The code comments acknowledge this is 'extremely dangerous' and that third-party directives should not do this. This could allow bypassing framework safety mechanisms if the directive is misused or compromised.
Unsafe HTML/SVG rendering by design
NPS-78781B2114E9
This directive intentionally bypasses sanitization and renders raw SVG content, which can enable XSS if used with untrusted input. The file's own documentation warns about this. It is an expected part of lit-html's API, not a malicious payload, but it is a security-sensitive feature.
unsafe HTML injection
NPS-0AFA10252A98
The unsafeStatic function allows arbitrary strings to be treated as static template content, bypassing Lit's normal HTML sanitization. The code explicitly warns that this function is unsafe for untrusted content and can lead to XSS if user input is passed to it. This is a deliberate API, but it represents a security-sensitive sink within the package.
unsafe template cache key construction
NPS-201009569167
The withStatic function builds a cache key by joining static strings with '$$lit$$' and stores the resulting staticStrings array without escaping. The comment itself notes that 'in general this pattern is unsafe' and may bypass Lit's security checks. This can create template instances with attacker-influenced static strings if unsafeStatic is used with untrusted input.
Intentional unsafe HTML rendering directive
NPS-62EF1ADB747D
This file defines the unsafeHTML directive from the Lit library. Despite being an official Google/Lit component, its entire purpose is to inject raw, unescaped HTML into the DOM (resultType=1 corresponds to HTML part rendering, bypassing Lit's default escaping). If the string passed to this directive ever originates from untrusted input, it enables XSS. The name itself documents the risk, and no sanitization is performed here. This is a security-relevant capability rather than a supply-chain compromise, but it is the kind of primitive a malicious package could abuse.
Potential Cross-Site Scripting (XSS) Risk
NPS-EE02602557C2
The templateContent directive renders the content of a template element as HTML using document.importNode. The code comments explicitly warn that the template should be developer-controlled and not user-controlled, as rendering a user-controlled template could lead to cross-site-scripting vulnerabilities. This is not a malicious pattern but a security risk if misused.
Direct rendering bypass of framework safety
NPS-7EDF0D8C5432
The render() method does not perform any sanitization (no DOMPurify, no escaping) and only enforces a type check that the value is a string. Any sanitization responsibility is delegated entirely to the caller, and there is no safe default. Because it constructs a fake TemplateResult with 'raw' strings, it forces Lit to insert the content via innerHTML-like parsing rather than text nodes.
Intentional XSS Risk (unsafe HTML rendering)
NPS-6881F74A1E1F
The directive 'unsafeHTML' renders a string as raw HTML by impersonating a Lit TemplateResult ('_$litType$' set to HTML_RESULT with the raw string as the template). This bypasses Lit's built-in escaping and will execute any embedded scripts/event handlers, leading to DOM-based cross-site scripting if used with untrusted input. The source even includes comments warning it is 'extremely dangerous' and 'unsafe to use with any user-provided input that hasn't been sanitized or escaped'. This is documented/by-design behavior of the library, not a hidden backdoor, but it is a significant security hazard for consumers of the package.
Unsafe rendering by design
NPS-EC9231890C4F
This directive intentionally renders unsanitized SVG content via innerHTML-like behavior (inherited from UnsafeHTMLDirective). Its name and JSDoc explicitly warn that using it with user-provided input can lead to XSS. This is a known, documented API surface in Lit, not a hidden backdoor, but it is a dangerous primitive if consumers pass untrusted data to it.
Intentional unsafe HTML rendering directive
NPS-62EF1ADB747D
This file defines the unsafeHTML directive from the Lit library. Despite being an official Google/Lit component, its entire purpose is to inject raw, unescaped HTML into the DOM (resultType=1 corresponds to HTML part rendering, bypassing Lit's default escaping). If the string passed to this directive ever originates from untrusted input, it enables XSS. The name itself documents the risk, and no sanitization is performed here. This is a security-relevant capability rather than a supply-chain compromise, but it is the kind of primitive a malicious package could abuse.
global symbol brand spoofing
NPS-ADD60B39BA1F
Symbol.for('') creates a globally shared symbol. Any other code in the same JavaScript realm can obtain the same symbol and forge objects that pass the unwrapStaticValue check, potentially injecting arbitrary static content into templates if such forged objects reach withStatic. The package documentation acknowledges interoperability goals but not this spoofing risk.
Minified/obfuscated source
NPS-4B182EC6B3EC
The code is heavily minified with short identifiers (e.g. t, i, r, s, e, o). While this is normal for published build artifacts and no obfuscation beyond minification is present, it reduces auditability and could conceal modifications relative to upstream source. The accompanying sourcemap reference suggests it is a legitimate build output.
intentional unsafe API
NPS-78ABAA566A06
The 'unsafeStatic' function and related static value handling deliberately bypass lit-html's normal sanitization, allowing direct HTML injection. This is a documented, intentional API for trusted content only, not a malicious pattern. The code and comments explicitly warn users not to pass untrusted input.
template cache key manipulation
NPS-E129FA990F23
The withStatic wrapper sets 'staticStrings.raw = staticStrings' and caches templates by a joined key. This is noted in comments as bypassing lit's security checks for static values. It is an intentional implementation detail required for the static value feature and not a covert backdoor.
Minified/obfuscated source
NPS-4B182EC6B3EC
The code is heavily minified with short identifiers (e.g. t, i, r, s, e, o). While this is normal for published build artifacts and no obfuscation beyond minification is present, it reduces auditability and could conceal modifications relative to upstream source. The accompanying sourcemap reference suggests it is a legitimate build output.
dynamic HTML parsing
NPS-E24475933D5E
The N.createElement method assigns a string to a template element's innerHTML. In this library the string is derived from validated template literal arrays passed through the P() function (which creates a Trusted Type when available), not from unsanitized user input. This is intrinsic to lit-html's templating design and is not exfiltration or code execution.
trusted types policy
NPS-4E59DE117244
The code creates a Trusted Types policy named 'lit-html' via globalThis.trustedTypes. This is a standard security feature used by lit-html to integrate with the browser's Trusted Types enforcement, not a malicious pattern.
randomized marker generation
NPS-6559476A0168
Math.random() is used to generate a unique marker string for template processing. This is a benign uniqueness mechanism, not cryptographic or security-sensitive, and does not indicate malicious intent.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| development/directives/unsafe-html.js | medium | The code is a legitimate part of the lit-html library implementing the documented unsafeHTML directive, which intentionally allows raw HTML rendering; the security concerns are inherent to its purpose and mitigated by clear warnings, but it remains a potential XSS vector if misused. |
| development/directives/unsafe-svg.js | medium | No malicious patterns detected; this is a legitimate lit-html directive for rendering unsanitized SVG with documented XSS risks. |
| development/static.js | medium | No malicious exfiltration, credential harvesting, or backdoor behavior found; the main concerns are documented but security-sensitive unsafe HTML injection and template-cache manipulation capabilities inherent to the library's API. |
| directives/unsafe-html.js | medium | This is the legitimate Lit unsafeHTML directive; it performs no network, filesystem, process, or credential access, but by design injects unescaped HTML and therefore carries inherent XSS risk if fed untrusted input. |
| node/development/directives/template-content.js | medium | No malicious patterns detected, but the directive can introduce XSS if used with untrusted templates. |
| node/development/directives/unsafe-html.js | medium | The file is an intentional, documented 'unsafeHTML' directive from Lit that allows raw HTML injection (XSS) by design; no exfiltration, credential harvesting, obfuscation, process spawning, or network activity was found, but it should be flagged as a dangerous API for consumers handling untrusted data. |
| node/development/directives/unsafe-svg.js | medium | The file defines Lit's documented unsafeSVG directive which deliberately renders unsanitized SVG (an XSS risk if misused), but contains no malicious patterns such as exfiltration, credential harvesting, obfuscation, process spawning, or install-time execution. |
| node/directives/unsafe-html.js | medium | This is the legitimate Lit unsafeHTML directive; it performs no network, filesystem, process, or credential access, but by design injects unescaped HTML and therefore carries inherent XSS risk if fed untrusted input. |
| async-directive.js | safe | No malicious patterns detected; this is a legitimate Google Lit library file implementing an async directive with no external network, filesystem, or process activity. |
| development/async-directive.js | safe | No malicious patterns detected |
| development/directive-helpers.js | safe | Cleared by Jev triage; no further analysis needed |
| development/directive.js | safe | Cleared by Jev triage; no further analysis needed |
| development/directives/async-append.js | safe | Cleared by Jev triage; no further analysis needed |
| development/directives/async-replace.js | safe | Cleared by Jev triage; no further analysis needed |
| development/directives/cache.js | safe | Cleared by Jev triage; no further analysis needed |
| development/directives/choose.js | safe | Cleared by Jev triage; no further analysis needed |
| development/directives/class-map.js | safe | Cleared by Jev triage; no further analysis needed |
| development/directives/guard.js | safe | Cleared by Jev triage; no further analysis needed |
| development/directives/if-defined.js | safe | Cleared by Jev triage; no further analysis needed |
| development/directives/join.js | safe | Cleared by Jev triage; no further analysis needed |
| development/directives/keyed.js | safe | Cleared by Jev triage; no further analysis needed |
| development/directives/live.js | safe | Cleared by Jev triage; no further analysis needed |
| development/directives/map.js | safe | Cleared by Jev triage; no further analysis needed |
| development/directives/private-async-helpers.js | safe | Cleared by Jev triage; no further analysis needed |
| development/directives/range.js | safe | Cleared by Jev triage; no further analysis needed |
Show 95 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| development/directives/ref.js | safe | Cleared by Jev triage; no further analysis needed |
| development/directives/repeat.js | safe | Cleared by Jev triage; no further analysis needed |
| development/directives/style-map.js | safe | Cleared by Jev triage; no further analysis needed |
| development/directives/template-content.js | safe | No malicious patterns detected; this is a legitimate Lit directive for rendering developer-controlled template content with an explicit XSS warning. |
| development/directives/unsafe-mathml.js | safe | No malicious patterns detected; the file is a standard Lit unsafeMathML directive with no network, filesystem, process, or code-execution behavior. |
| development/directives/until.js | safe | Cleared by Jev triage; no further analysis needed |
| development/directives/when.js | safe | Cleared by Jev triage; no further analysis needed |
| development/is-server.js | safe | Cleared by Jev triage; no further analysis needed |
| development/lit-html.js | safe | This is the legitimate Google Lit library's development build, with no malicious patterns detected. |
| development/polyfill-support.js | safe | No malicious patterns detected; the code is a legitimate Lit polyfill for ShadyDOM/ShadyCSS compatibility with no exfiltration, obfuscation, or unsafe operations. |
| development/private-ssr-support.js | safe | No malicious patterns detected; the file is a legitimate Lit library private SSR support module with no data exfiltration, credential harvesting, obfuscation, or other security concerns. |
| directive-helpers.js | safe | This is a minified but non-obfuscated excerpt from the Lit library (Google LLC, BSD-3-Clause) containing only template rendering helpers with no malicious patterns. |
| directive.js | safe | No malicious patterns detected |
| directives/async-append.js | safe | This is a legitimate Lit async-append directive, containing no malicious patterns, network activity, filesystem access, or obfuscated code. |
| directives/async-replace.js | safe | This is the legitimate Lit AsyncReplace directive from Google's lit-html library with no malicious patterns detected. |
| directives/cache.js | safe | This is the official lit-html cache directive from Google's Lit library; no malicious patterns, exfiltration, obfuscation, or dangerous operations detected. |
| directives/choose.js | safe | No malicious patterns detected; the code is a simple utility function with no security concerns |
| directives/class-map.js | safe | No malicious patterns detected; this is the standard Lit classMap directive from Google's lit-html library. |
| directives/guard.js | safe | This is the standard guard directive from the Lit library (Google), containing no malicious patterns, no network/filesystem access, and no dynamic code execution. |
| directives/if-defined.js | safe | The file is a small, legitimate Lit library directive that maps undefined/null values to a 'nothing' sentinel, with no malicious patterns detected. |
| directives/join.js | safe | No malicious patterns detected |
| directives/keyed.js | safe | No malicious patterns detected; the file is a legitimate Lit directive for keyed rendering. |
| directives/live.js | safe | No malicious patterns detected; this is the standard Lit 'live' directive implementation with only internal imports and no external data access or code execution. |
| directives/map.js | safe | No malicious patterns detected |
| directives/private-async-helpers.js | safe | No malicious patterns detected; the code is a legitimate Google Lit helper module for async iteration and weak reference management. |
| directives/range.js | safe | No malicious patterns detected |
| directives/ref.js | safe | This is the standard Lit library ref directive; it contains no malicious patterns, network calls, credential access, or dynamic code execution. |
| directives/repeat.js | safe | No malicious patterns detected; the file is a legitimate minified implementation of the lit-html repeat directive. |
| directives/style-map.js | safe | This is the standard Lit styleMap directive from the official lit-html package with no malicious patterns detected. |
| directives/template-content.js | safe | This is a legitimate Lit library directive for rendering template content with no malicious patterns detected. |
| directives/unsafe-mathml.js | safe | No malicious patterns detected; the file is a small, readable Lit directive extending UnsafeHTMLDirective with no network, filesystem, process, or dynamic execution behavior. |
| directives/unsafe-svg.js | safe | This is a legitimate Lit unsafeSVG directive from Google's lit-html library with no malicious patterns detected. |
| directives/until.js | safe | This is the standard Lit 'until' directive from the official lit-html package, containing only asynchronous rendering logic with no malicious patterns. |
| directives/when.js | safe | No malicious patterns detected |
| is-server.js | safe | No malicious patterns detected |
| lit-html.js | safe | No malicious patterns detected in this minified lit-html library; it is a legitimate Google rendering library with no data exfiltration, credential harvesting, obfuscated payloads, or suspicious network/file/process operations. |
| node/async-directive.js | safe | No malicious patterns detected; this is a legitimate Google Lit library file implementing an async directive with no external network, filesystem, or process activity. |
| node/development/async-directive.js | safe | This is a legitimate Lit library file implementing AsyncDirective connection state management with no malicious patterns detected. |
| node/development/directive-helpers.js | safe | Cleared by Jev triage; no further analysis needed |
| node/development/directive.js | safe | Cleared by Jev triage; no further analysis needed |
| node/development/directives/async-append.js | safe | Cleared by Jev triage; no further analysis needed |
| node/development/directives/async-replace.js | safe | Cleared by Jev triage; no further analysis needed |
| node/development/directives/cache.js | safe | Cleared by Jev triage; no further analysis needed |
| node/development/directives/choose.js | safe | Cleared by Jev triage; no further analysis needed |
| node/development/directives/class-map.js | safe | Cleared by Jev triage; no further analysis needed |
| node/development/directives/guard.js | safe | Cleared by Jev triage; no further analysis needed |
| node/development/directives/if-defined.js | safe | Cleared by Jev triage; no further analysis needed |
| node/development/directives/join.js | safe | Cleared by Jev triage; no further analysis needed |
| node/development/directives/keyed.js | safe | Cleared by Jev triage; no further analysis needed |
| node/development/directives/live.js | safe | Cleared by Jev triage; no further analysis needed |
| node/development/directives/map.js | safe | Cleared by Jev triage; no further analysis needed |
| node/development/directives/private-async-helpers.js | safe | Cleared by Jev triage; no further analysis needed |
| node/development/directives/range.js | safe | Cleared by Jev triage; no further analysis needed |
| node/development/directives/ref.js | safe | Cleared by Jev triage; no further analysis needed |
| node/development/directives/repeat.js | safe | Cleared by Jev triage; no further analysis needed |
| node/development/directives/style-map.js | safe | Cleared by Jev triage; no further analysis needed |
| node/development/directives/unsafe-mathml.js | safe | This file defines a lit-html UnsafeMathMLDirective that intentionally renders unsanitized MathML (documented as unsafe by design), but contains no malicious patterns such as exfiltration, credential harvesting, obfuscation, dynamic execution, or install-time behavior. |
| node/development/directives/until.js | safe | Cleared by Jev triage; no further analysis needed |
| node/development/directives/when.js | safe | Cleared by Jev triage; no further analysis needed |
| node/development/is-server.js | safe | Cleared by Jev triage; no further analysis needed |
| node/development/lit-html.js | safe | No malicious patterns detected; this is the official Lit library with standard template rendering, sanitization, and debugging code. |
| node/development/polyfill-support.js | safe | The code is a legitimate lit-html polyfill for ShadyCSS/ShadyDOM compatibility, with no malicious patterns such as data exfiltration, dynamic code execution, or file system manipulation. |
| node/development/private-ssr-support.js | safe | No malicious patterns detected in this Lit private SSR support module, which only contains legitimate internal framework utilities. |
| node/development/static.js | safe | This is legitimate Lit library source code implementing documented static value support; the unsafe behaviors are intentional, clearly documented, and not malicious. |
| node/directive-helpers.js | safe | This is a minified but non-obfuscated excerpt from the Lit library (Google LLC, BSD-3-Clause) containing only template rendering helpers with no malicious patterns. |
| node/directive.js | safe | No malicious patterns detected |
| node/directives/async-append.js | safe | This is a legitimate Lit async-append directive, containing no malicious patterns, network activity, filesystem access, or obfuscated code. |
| node/directives/async-replace.js | safe | This is the legitimate Lit AsyncReplace directive from Google's lit-html library with no malicious patterns detected. |
| node/directives/cache.js | safe | This is the official lit-html cache directive from Google's Lit library; no malicious patterns, exfiltration, obfuscation, or dangerous operations detected. |
| node/directives/choose.js | safe | No malicious patterns detected; the code is a simple utility function with no security concerns |
| node/directives/class-map.js | safe | No malicious patterns detected; this is the standard Lit classMap directive from Google's lit-html library. |
| node/directives/guard.js | safe | This is the standard guard directive from the Lit library (Google), containing no malicious patterns, no network/filesystem access, and no dynamic code execution. |
| node/directives/if-defined.js | safe | The file is a small, legitimate Lit library directive that maps undefined/null values to a 'nothing' sentinel, with no malicious patterns detected. |
| node/directives/join.js | safe | No malicious patterns detected |
| node/directives/keyed.js | safe | No malicious patterns detected; the file is a legitimate Lit directive for keyed rendering. |
| node/directives/live.js | safe | No malicious patterns detected; this is the standard Lit 'live' directive implementation with only internal imports and no external data access or code execution. |
| node/directives/map.js | safe | No malicious patterns detected |
| node/directives/private-async-helpers.js | safe | No malicious patterns detected; the code is a legitimate Google Lit helper module for async iteration and weak reference management. |
| node/directives/range.js | safe | No malicious patterns detected |
| node/directives/ref.js | safe | This is the standard Lit library ref directive; it contains no malicious patterns, network calls, credential access, or dynamic code execution. |
| node/directives/repeat.js | safe | No malicious patterns detected; the file is a legitimate minified implementation of the lit-html repeat directive. |
| node/directives/style-map.js | safe | This is the standard Lit styleMap directive from the official lit-html package with no malicious patterns detected. |
| node/directives/template-content.js | safe | This is a legitimate Lit library directive for rendering template content with no malicious patterns detected. |
| node/directives/unsafe-mathml.js | safe | No malicious patterns detected; the file is a small, readable Lit directive extending UnsafeHTMLDirective with no network, filesystem, process, or dynamic execution behavior. |
| node/directives/unsafe-svg.js | safe | This is a legitimate Lit unsafeSVG directive from Google's lit-html library with no malicious patterns detected. |
| node/directives/until.js | safe | This is the standard Lit 'until' directive from the official lit-html package, containing only asynchronous rendering logic with no malicious patterns. |
| node/directives/when.js | safe | No malicious patterns detected |
| node/is-server.js | safe | No malicious patterns detected; the file simply exports a constant boolean indicating server-side execution. |
| node/lit-html.js | safe | The file is the standard minified lit-html v3.3.1 rendering library with no malicious patterns such as exfiltration, credential harvesting, obfuscated payloads, process spawning, or install-time code. |
| node/polyfill-support.js | safe | No malicious patterns detected; the code is a legitimate Lit polyfill support module with ShadyCSS/ShadyDOM handling and no exfiltration, obfuscation, or system access. |
| node/private-ssr-support.js | safe | This is a legitimate Lit library module for SSR support with no malicious patterns detected |
| node/static.js | safe | No malicious patterns detected; this is legitimate Lit static template caching code from Google with no network, filesystem, process, or dynamic execution activity. |
| polyfill-support.js | safe | No malicious patterns detected; the file is the standard Lit polyfill-support.js with legitimate ShadyCSS polyfill logic. |
| private-ssr-support.js | safe | This is a legitimate Lit library module for SSR support with no malicious patterns detected |
| static.js | safe | No malicious patterns detected; this is legitimate Lit static template caching code from Google with no network, filesystem, process, or dynamic execution activity. |
Frequently asked questions
Is lit-html safe to use?
No confirmed malware was found in lit-html@3.3.1, but the review flagged 11 medium, 8 low severity findings for risky patterns worth checking before you rely on it.
Does lit-html contain malware?
No malware was identified in lit-html@3.3.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was lit-html checked?
Togoder Security downloaded the published npm package and had an AI model read its 120 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan lit-html together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in lit-html@3.3.1, cost nothing.