Togoder security

npm package security report

styled-jsx@5.1.6 security report

Risky patterns found that deserve a look.

Needs review Version 5.1.6 Files reviewed 10 Size 971.3 KB Scanned

Summary

Togoder Security scanned the npm package styled-jsx@5.1.6 on Oct 6, 2026. An AI review of 10 source files produced 2 medium, 5 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
2
medium
5
low

Findings 7

medium

dynamic code execution via CSSOM

NPS-714B84B7A550

The StyleSheet class uses sheet.insertRule(rule, index) to inject CSS rules directly into the document's stylesheet. If an attacker can control the 'rule' string, they could inject malicious CSS (e.g., @import, expression(), or behavior) leading to data exfiltration or other client-side attacks. The code attempts to catch errors but does not sanitize the rule content on the client side.

dist/index/index.js:105
medium

dangerouslySetInnerHTML usage

NPS-8339387024F7

The mapRulesToStyle function uses React's dangerouslySetInnerHTML to inject CSS content into style tags. While the CSS content is derived from the component's props and processed via computeSelector and sanitize, this pattern could lead to XSS if an attacker can control the CSS content (e.g., via user input). The sanitize function only replaces '/style' with '\/style', which is not comprehensive. This is a potential security risk if untrusted data reaches this code.

dist/index/index.js:179
low

Dynamic module loading at import time

NPS-041A27D4F624

The file uses require('./dist/babel') with a relative path, which is normal, but it immediately invokes .test() on the imported module. This executes code from './dist/babel' at import time, which could be a vector for malicious code if the dist/babel file is compromised. However, the path is relative and within the package, so it is likely benign, but the immediate execution of .test() without validation is a potential risk if the imported module is malicious or unexpected.

babel-test.js:2
low

potential environment variable access

NPS-E2DB2024DA85

The code reads process.env.NODE_ENV to determine production mode. This is a common and benign pattern, but it indicates the package accesses environment variables. No sensitive variables are harvested, and the value is only used to set a boolean flag.

dist/index/index.js:36
low

nonce extraction from DOM

NPS-5C7FA17F7561

The code queries the DOM for a meta tag with property 'csp-nonce' and reads its content attribute to use as a nonce for style tags. This is a legitimate pattern for Content Security Policy compliance, but it could be abused if an attacker can inject a meta tag to bypass CSP. However, this is a standard practice and not inherently malicious.

dist/index/index.js:45
low

Dynamic module loading

NPS-1C59EC7D2365

The module uses require('./dist/babel').macro(), which dynamically loads and executes code from a relative path. While this is a common pattern for Babel macros, it does execute code at import time and could be exploited if the ./dist/babel module is malicious or compromised.

macro.js:1
low

Code execution at import time

NPS-2D14FD221F34

The invocation of .macro() at the top level means code is executed as soon as this module is imported. This is expected for Babel macros but is a potential risk if the underlying module contains malicious code.

macro.js:1

Files reviewed

FileVerdictWhat the reviewer saw
babel-test.js medium The file appears to be a simple test runner that imports and executes a function from a local module, but the pattern of executing code at import time warrants caution.
dist/index/index.js medium The code is a legitimate implementation of styled-jsx's style sheet management, but it contains patterns like dangerouslySetInnerHTML and dynamic CSS rule insertion that could be risky if fed untrusted input; no malicious exfiltration, credential harvesting, or backdoor patterns were found.
macro.js medium The file is a simple Babel macro entry point that dynamically loads and executes code from a relative module at import time, which is typical but carries inherent execution risk if the dependency is compromised.
babel.js safe Cleared by Jev triage; no further analysis needed
css.js safe Cleared by Jev triage; no further analysis needed
index.js safe Cleared by Jev triage; no further analysis needed
lib/style-transform.js safe Cleared by Jev triage; no further analysis needed
lib/stylesheet.js safe Cleared by Jev triage; no further analysis needed
style.js safe Cleared by Jev triage; no further analysis needed
webpack.js safe No malicious patterns detected

Frequently asked questions

Is styled-jsx safe to use?

No confirmed malware was found in styled-jsx@5.1.6, but the review flagged 2 medium, 5 low severity findings for risky patterns worth checking before you rely on it.

Does styled-jsx contain malware?

No malware was identified in styled-jsx@5.1.6 when Togoder Security scanned it on Oct 6, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was styled-jsx checked?

Togoder Security downloaded the published npm package and had an AI model read its 10 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan styled-jsx together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in styled-jsx@5.1.6, cost nothing.

Related security reports