# postcss@8.5.28 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:23:45.000Z
- Files reviewed: 29
- Findings: 8 low severity findings
- Report: https://security.togoder.click/npm/postcss
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package postcss@8.5.28 on Oct 6, 2026. An AI review of 29 source files produced 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [low] Prototype manipulation via __proto__ assignment

Finding ID: `NPS-17A1E22AD8ED`

File: `lib/fromJSON.js:13`

The hydrateInputs function constructs objects with literal '__proto__' properties: '{ ...input, __proto__: Input.prototype }' and '{ ...inputHydrated.map, __proto__: PreviousMap.prototype }'. While this appears intended to rehydrate class instances from JSON, setting '__proto__' explicitly is widely flagged as a dangerous pattern because it can be abused for prototype pollution. In this specific file the value is a hard-coded library prototype (not attacker-controlled), so it does not directly enable pollution, but it is a fragile and security-sensitive construct worth noting.

### [low] Unsafe spread of untrusted JSON into object prototypes

Finding ID: `NPS-D1A1817D0529`

File: `lib/fromJSON.js:23`

constructNode does 'let defaults = { ...json }' on data coming from JSON (potentially untrusted input to fromJSON). If any nested property named '__proto__' or 'constructor' is present in the JSON, spread/merge semantics could interact with prototype chains depending on runtime and downstream constructors. This mirrors known prototype-pollution risks in deserialization helpers.

### [low] Network requests

Finding ID: `NPS-9EA4A5A0F2C8`

File: `lib/map-generator.js`

The code does not make any network requests. It only manipulates paths and URLs locally.

### [low] File system manipulation

Finding ID: `NPS-3452E692B95B`

File: `lib/map-generator.js`

The code uses path manipulation functions (dirname, relative, resolve) but does not perform any file system operations like reading or writing files. It only computes paths.

### [low] Environment variable harvesting

Finding ID: `NPS-29213932EC1F`

File: `lib/map-generator.js`

No environment variables are accessed or harvested in this code.

### [low] Process spawning

Finding ID: `NPS-5FDC46B03987`

File: `lib/map-generator.js`

No child process spawning or shell command execution is present.

### [low] Dynamic imports

Finding ID: `NPS-6839F5B02D57`

File: `lib/map-generator.js`

The code uses require() with static paths only. No dynamic imports based on computed input.

### [low] Dynamic code execution

Finding ID: `NPS-38F3E64D8C6A`

File: `lib/map-generator.js:484`

The code uses Buffer.from() and window.btoa() which are not dynamic code execution functions. The toBase64 function heavily relies on Buffer but this is a standard Node.js API for encoding strings to base64, not an eval or Function constructor.

## Files reviewed

- `lib/fromJSON.js` (medium): No exfiltration, credential harvesting, shell execution, network calls, or install-time hooks were found; the only concerns are the explicit __proto__ assignments during instance rehydration, which are a security-sensitive but hard-coded pattern.
- `lib/at-rule.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/comment.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/container.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/css-syntax-error.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/declaration.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/document.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/input.js` (safe): No malicious patterns detected; the file is legitimate PostCSS input handling code with no exfiltration, credential harvesting, dynamic execution, or suspicious network/file/process activity.
- `lib/lazy-result.js` (safe): No malicious patterns detected
- `lib/list.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/map-generator.js` (safe): The analyzed code is a standard source map generator for CSS processing with no malicious patterns detected.
- `lib/no-work-result.js` (safe): No malicious patterns detected; the file is a standard PostCSS result wrapper with no network, filesystem, process, or dynamic code execution activity.
- `lib/node.js` (safe): This is the standard PostCSS Node class implementation with no malicious patterns; it handles CSS AST manipulation, cloning, and serialization without network, filesystem, or process operations.
- `lib/parse.js` (safe): No malicious patterns detected
- `lib/parser.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/postcss.js` (safe): No malicious patterns detected; the file is the standard PostCSS entry point with only legitimate module exports and a deprecation warning.
- `lib/postcss.mjs` (safe): Cleared by Jev triage; no further analysis needed
- `lib/previous-map.js` (safe): No malicious patterns detected
- `lib/processor.js` (safe): No malicious patterns detected; the file contains standard PostCSS processor logic with no data exfiltration, credential harvesting, dynamic code execution, or suspicious behavior.
- `lib/result.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/root.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/rule.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/stringifier.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/stringify.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/symbols.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/terminal-highlight.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/tokenize.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/warn-once.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/warning.js` (safe): Cleared by Jev triage; no further analysis needed

## Version ranges

None of the 2 scanned versions of postcss are flagged high or critical. The latest scanned version, 8.5.28, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 8.5.28 (`8.5.28`): medium
- 8.5.25 (`8.5.25`): not scanned
- 8.5.23 (`8.5.23`): medium (Path Traversal Risk in Source Map Loading)
- 7.0.39 – 8.4.49 (`>=7.0.39 <=8.4.49`): not scanned

## Scanned versions

- [8.5.28](https://security.togoder.click/npm/postcss@8.5.28): medium, 2026-10-06T14:23:45.000Z
- [8.5.23](https://security.togoder.click/npm/postcss@8.5.23): medium, 2026-10-06T14:22:43.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
