
Security News
Axios Maintainer Confirms Social Engineering Attack Behind npm Compromise
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.
@stylexswc/postcss-plugin
Advanced tools
Part of the StyleX SWC Plugin workspace
PostCSS plugin for an unofficial
napi-rs
compiler that includes the StyleX SWC code transformation under the hood.
To install the package, run the following command:
npm install --save-dev @stylexswc/postcss-plugin
Modify postcss.config.js. For example:
module.exports = {
plugins: {
'@stylexjs/postcss-plugin': {
include: ['src/**/*.{js,jsx,ts,tsx}'],
},
autoprefixer: {},
},
};
Use on of the plugins to process JS/TS files with StyleX code. For example:
/// next.config.js
const path = require('path');
const stylexPlugin = require('@stylexswc/nextjs-plugin');
const rootDir = __dirname;
module.exports = stylexPlugin({
// Add any StyleX options here
rsOptions: {
aliases: {
'@/*': [path.join(rootDir, '*')],
},
unstable_moduleResolution: {
type: 'commonJS',
},
},
// It's important to prevent creating a new CSS file with StyleX classes twice
extractCSS: false,
})({
transpilePackages: ['@stylexjs/open-props'],
// Optionally, add any other Next.js config below
});
[!WARNING] Each plugin of
@stylexswcnamespace accepts anextractCSSoption to control CSS extraction. When using thepostcssplugin, this option should be set tofalseto avoid double generation of CSS files with StyleX styles.
[!NOTE] This approach requires transpiling JS/TS files with StyleX code twice: first the source code and then using the PostCSS plugin. To avoid this behavior when using
NextJS, use the regular@stylexswc/nextjs-pluginpassing thetransformCssparameter to transform the generated CSS if it's possible, for example:/// next.config.js //...other code transformCss: async css => { const postcss = require('postcss'); const result = await postcss([require('autoprefixer')]).process(css); return result.css; }, //...other code
Add the following CSS file to your project:
/*[fileName].css*/
/**
* The @stylex directive is used by the @stylexjs/postcss-plugin.
* It is automatically replaced with generated CSS during builds.
*/
@stylex;
And import it in your JS/TS files:
import '[fileName].css';
The plugin accepts the following configuration options:
[!NOTE] Features: The
includeandexcludeoptions are exclusive to this NAPI-RS compiler implementation and are not available in the official StyleX Babel plugin.
include(string | RegExp)[]When omitted, the plugin auto-discovers source files in the project cwd and
direct dependencies that use StyleX.
exclude(string | RegExp)[]include pattern. Patterns are matched against paths relative to the current
working directory. Supports regex lookahead/lookbehind for advanced filtering.When include is omitted, the plugin automatically excludes common build and
dependency folders (for example node_modules, .next, dist, build) to
keep discovery focused on source files.
rsOptionsStyleXOptions{}useCSSLayersbooleanfalsecwdstringprocess.cwd()isDevbooleanimportSourcesArray<string | { from: string, as: string }>When provided, takes precedence over rsOptions.importSources. When omitted,
falls back to rsOptions.importSources, then the built-in defaults
(@stylexjs/stylex, stylex).
Include only specific directories:
{
'@stylexswc/postcss-plugin': {
include: ['src/**/*.{ts,tsx}', 'components/**/*.{ts,tsx}'],
},
}
Exclude test and story files:
{
'@stylexswc/postcss-plugin': {
include: ['src/**/*.{ts,tsx}'],
exclude: ['**/*.test.*', '**/*.stories.*', '**/__tests__/**'],
},
}
Using regular expressions:
{
'@stylexswc/postcss-plugin': {
include: ['src/**/*.{ts,tsx}', /components\/.*\.tsx$/],
exclude: [/\.test\./, /\.stories\./],
},
}
Exclude node_modules except specific packages (using lookahead):
{
'@stylexswc/postcss-plugin': {
include: ['src/**/*.{ts,tsx}', 'node_modules/**/*.js'],
// Exclude all node_modules except @stylexjs/open-props
exclude: [/node_modules(?!\/@stylexjs\/open-props)/],
},
}
Transform only specific packages from node_modules:
{
'@stylexswc/postcss-plugin': {
include: [
'src/**/*.{ts,tsx}',
'node_modules/@stylexjs/open-props/**/*.js',
'node_modules/@my-org/design-system/**/*.js',
],
exclude: ['**/*.test.*'],
},
}
Set STYLEX_POSTCSS_DEBUG=1 to print resolved plugin inputs, including:
importSources and where they came frominclude and exclude globsMIT — see LICENSE
FAQs
StyleX PostCSS plugin with NAPI-RS compiler
We found that @stylexswc/postcss-plugin demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.

Security News
The Axios compromise shows how time-dependent dependency resolution makes exposure harder to detect and contain.