A collection of round outlined Solid icons with 3px radius and 1.5px stroke width, designed for use in Solid applications.
No attack was identified. The install hook performs a package license check using a dedicated license key sent to the vendor license endpoint.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe manifest runs license-check.js during preinstall; prepublishOnly runs a build script.
package.jsonView on unpkg · L13Source fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkglicense-check.js reads the purpose-specific CENTRAL_LICENSE_KEY environment variable and requires it to be set.
license-check.jsView on unpkg · L1The script sends that key as a bearer credential to centralicons.com/license/check and identifies the package in the request.
license-check.jsView on unpkg · L14The script invokes the license check; no other credential collection or unrelated destination is shown in the inspected source.
license-check.jsView on unpkg · L41This report applies to @central-icons-solid/round-outlined-radius-3-stroke-1.5@1.2.4.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L14The manifest runs license-check.js during preinstall; prepublishOnly runs a build script.
package.jsonView on unpkg · L13license-check.js reads the purpose-specific CENTRAL_LICENSE_KEY environment variable and requires it to be set.
license-check.jsView on unpkg · L1The script sends that key as a bearer credential to centralicons.com/license/check and identifies the package in the request.
license-check.jsView on unpkg · L14The script invokes the license check; no other credential collection or unrelated destination is shown in the inspected source.
license-check.jsView on unpkg · L41Source fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkg