A collection of round filled Solid icons with 2px radius and 1px stroke width, designed for use in Solid applications.
No malicious attack was identified. The preinstall script performs a package license check against the package vendor.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpackage.json runs license-check.js during preinstall.
package.jsonView on unpkg · L14Source fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkglicense-check.js requires a caller-provided CENTRAL_LICENSE_KEY and sends it to the package vendor's license-check endpoint for validation.
license-check.jsView on unpkg · L1license-check.js requires a caller-provided CENTRAL_LICENSE_KEY and sends it to the package vendor's license-check endpoint for validation.
license-check.jsView on unpkg · L14The check runs when the script is invoked; no unrelated credential source or recipient is shown.
license-check.jsView on unpkg · L46This report applies to @central-icons-solid/round-filled-radius-2-stroke-1@1.2.6.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L14package.json runs license-check.js during preinstall.
package.jsonView on unpkg · L14license-check.js requires a caller-provided CENTRAL_LICENSE_KEY and sends it to the package vendor's license-check endpoint for validation.
license-check.jsView on unpkg · L1license-check.js requires a caller-provided CENTRAL_LICENSE_KEY and sends it to the package vendor's license-check endpoint for validation.
license-check.jsView on unpkg · L14The check runs when the script is invoked; no unrelated credential source or recipient is shown.
license-check.jsView on unpkg · L46Source fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkg