A collection of round outlined Solid icons with 0px radius and 1px stroke width, designed for use in Solid applications.
No attack was identified. The install hook only submits the caller-supplied Central Icons license key to the vendor license endpoint and does not run the response.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpackage.json is a Solid icon pack whose only install lifecycle script is preinstall running license-check.js, with a solid-js peer dependency and no runtime dependencies.
package.jsonView on unpkg · L13Source fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkglicense-check.js reads CENTRAL_LICENSE_KEY and POSTs it as a bearer token only to https://centralicons.com/license/check with this package name and version, then checks a JSON validity flag and logs errors without executing the response.
license-check.jsView on unpkg · L1license-check.js reads CENTRAL_LICENSE_KEY and POSTs it as a bearer token only to https://centralicons.com/license/check with this package name and version, then checks a JSON validity flag and logs errors without executing the response.
license-check.jsView on unpkg · L14This report applies to @central-icons-solid/round-outlined-radius-0-stroke-1@1.2.1.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L14package.json is a Solid icon pack whose only install lifecycle script is preinstall running license-check.js, with a solid-js peer dependency and no runtime dependencies.
package.jsonView on unpkg · L13license-check.js reads CENTRAL_LICENSE_KEY and POSTs it as a bearer token only to https://centralicons.com/license/check with this package name and version, then checks a JSON validity flag and logs errors without executing the response.
license-check.jsView on unpkg · L1license-check.js reads CENTRAL_LICENSE_KEY and POSTs it as a bearer token only to https://centralicons.com/license/check with this package name and version, then checks a JSON validity flag and logs errors without executing the response.
license-check.jsView on unpkg · L14Source fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkg