# styled-jsx@5.1.6 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:24:40.000Z
- Files reviewed: 10
- Findings: 2 medium, 5 low severity findings
- Report: https://security.togoder.click/npm/styled-jsx
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package styled-jsx@5.1.6 on Oct 6, 2026. An AI review of 10 source files produced 2 medium, 5 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] dynamic code execution via CSSOM

Finding ID: `NPS-714B84B7A550`

File: `dist/index/index.js:105`

The StyleSheet class uses sheet.insertRule(rule, index) to inject CSS rules directly into the document's stylesheet. If an attacker can control the 'rule' string, they could inject malicious CSS (e.g., @import, expression(), or behavior) leading to data exfiltration or other client-side attacks. The code attempts to catch errors but does not sanitize the rule content on the client side.

### [medium] dangerouslySetInnerHTML usage

Finding ID: `NPS-8339387024F7`

File: `dist/index/index.js:179`

The mapRulesToStyle function uses React's dangerouslySetInnerHTML to inject CSS content into style tags. While the CSS content is derived from the component's props and processed via computeSelector and sanitize, this pattern could lead to XSS if an attacker can control the CSS content (e.g., via user input). The sanitize function only replaces '/style' with '\/style', which is not comprehensive. This is a potential security risk if untrusted data reaches this code.

### [low] Dynamic module loading at import time

Finding ID: `NPS-041A27D4F624`

File: `babel-test.js:2`

The file uses require('./dist/babel') with a relative path, which is normal, but it immediately invokes .test() on the imported module. This executes code from './dist/babel' at import time, which could be a vector for malicious code if the dist/babel file is compromised. However, the path is relative and within the package, so it is likely benign, but the immediate execution of .test() without validation is a potential risk if the imported module is malicious or unexpected.

### [low] potential environment variable access

Finding ID: `NPS-E2DB2024DA85`

File: `dist/index/index.js:36`

The code reads process.env.NODE_ENV to determine production mode. This is a common and benign pattern, but it indicates the package accesses environment variables. No sensitive variables are harvested, and the value is only used to set a boolean flag.

### [low] nonce extraction from DOM

Finding ID: `NPS-5C7FA17F7561`

File: `dist/index/index.js:45`

The code queries the DOM for a meta tag with property 'csp-nonce' and reads its content attribute to use as a nonce for style tags. This is a legitimate pattern for Content Security Policy compliance, but it could be abused if an attacker can inject a meta tag to bypass CSP. However, this is a standard practice and not inherently malicious.

### [low] Dynamic module loading

Finding ID: `NPS-1C59EC7D2365`

File: `macro.js:1`

The module uses require('./dist/babel').macro(), which dynamically loads and executes code from a relative path. While this is a common pattern for Babel macros, it does execute code at import time and could be exploited if the ./dist/babel module is malicious or compromised.

### [low] Code execution at import time

Finding ID: `NPS-2D14FD221F34`

File: `macro.js:1`

The invocation of .macro() at the top level means code is executed as soon as this module is imported. This is expected for Babel macros but is a potential risk if the underlying module contains malicious code.

## Files reviewed

- `babel-test.js` (medium): The file appears to be a simple test runner that imports and executes a function from a local module, but the pattern of executing code at import time warrants caution.
- `dist/index/index.js` (medium): The code is a legitimate implementation of styled-jsx's style sheet management, but it contains patterns like dangerouslySetInnerHTML and dynamic CSS rule insertion that could be risky if fed untrusted input; no malicious exfiltration, credential harvesting, or backdoor patterns were found.
- `macro.js` (medium): The file is a simple Babel macro entry point that dynamically loads and executes code from a relative module at import time, which is typical but carries inherent execution risk if the dependency is compromised.
- `babel.js` (safe): Cleared by Jev triage; no further analysis needed
- `css.js` (safe): Cleared by Jev triage; no further analysis needed
- `index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/style-transform.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/stylesheet.js` (safe): Cleared by Jev triage; no further analysis needed
- `style.js` (safe): Cleared by Jev triage; no further analysis needed
- `webpack.js` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
