Summary
Togoder Security scanned the npm package styled-jsx@5.1.6 on Oct 6, 2026. An AI review of 10 source files produced 2 medium, 5 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 7
dynamic code execution via CSSOM
NPS-714B84B7A550
The StyleSheet class uses sheet.insertRule(rule, index) to inject CSS rules directly into the document's stylesheet. If an attacker can control the 'rule' string, they could inject malicious CSS (e.g., @import, expression(), or behavior) leading to data exfiltration or other client-side attacks. The code attempts to catch errors but does not sanitize the rule content on the client side.
dangerouslySetInnerHTML usage
NPS-8339387024F7
The mapRulesToStyle function uses React's dangerouslySetInnerHTML to inject CSS content into style tags. While the CSS content is derived from the component's props and processed via computeSelector and sanitize, this pattern could lead to XSS if an attacker can control the CSS content (e.g., via user input). The sanitize function only replaces '/style' with '\/style', which is not comprehensive. This is a potential security risk if untrusted data reaches this code.
Dynamic module loading at import time
NPS-041A27D4F624
The file uses require('./dist/babel') with a relative path, which is normal, but it immediately invokes .test() on the imported module. This executes code from './dist/babel' at import time, which could be a vector for malicious code if the dist/babel file is compromised. However, the path is relative and within the package, so it is likely benign, but the immediate execution of .test() without validation is a potential risk if the imported module is malicious or unexpected.
potential environment variable access
NPS-E2DB2024DA85
The code reads process.env.NODE_ENV to determine production mode. This is a common and benign pattern, but it indicates the package accesses environment variables. No sensitive variables are harvested, and the value is only used to set a boolean flag.
nonce extraction from DOM
NPS-5C7FA17F7561
The code queries the DOM for a meta tag with property 'csp-nonce' and reads its content attribute to use as a nonce for style tags. This is a legitimate pattern for Content Security Policy compliance, but it could be abused if an attacker can inject a meta tag to bypass CSP. However, this is a standard practice and not inherently malicious.
Dynamic module loading
NPS-1C59EC7D2365
The module uses require('./dist/babel').macro(), which dynamically loads and executes code from a relative path. While this is a common pattern for Babel macros, it does execute code at import time and could be exploited if the ./dist/babel module is malicious or compromised.
Code execution at import time
NPS-2D14FD221F34
The invocation of .macro() at the top level means code is executed as soon as this module is imported. This is expected for Babel macros but is a potential risk if the underlying module contains malicious code.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| babel-test.js | medium | The file appears to be a simple test runner that imports and executes a function from a local module, but the pattern of executing code at import time warrants caution. |
| dist/index/index.js | medium | The code is a legitimate implementation of styled-jsx's style sheet management, but it contains patterns like dangerouslySetInnerHTML and dynamic CSS rule insertion that could be risky if fed untrusted input; no malicious exfiltration, credential harvesting, or backdoor patterns were found. |
| macro.js | medium | The file is a simple Babel macro entry point that dynamically loads and executes code from a relative module at import time, which is typical but carries inherent execution risk if the dependency is compromised. |
| babel.js | safe | Cleared by Jev triage; no further analysis needed |
| css.js | safe | Cleared by Jev triage; no further analysis needed |
| index.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/style-transform.js | safe | Cleared by Jev triage; no further analysis needed |
| lib/stylesheet.js | safe | Cleared by Jev triage; no further analysis needed |
| style.js | safe | Cleared by Jev triage; no further analysis needed |
| webpack.js | safe | No malicious patterns detected |
Frequently asked questions
Is styled-jsx safe to use?
No confirmed malware was found in styled-jsx@5.1.6, but the review flagged 2 medium, 5 low severity findings for risky patterns worth checking before you rely on it.
Does styled-jsx contain malware?
No malware was identified in styled-jsx@5.1.6 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was styled-jsx checked?
Togoder Security downloaded the published npm package and had an AI model read its 10 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan styled-jsx together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in styled-jsx@5.1.6, cost nothing.