A collection of square filled Solid icons with 0px radius and 1px stroke width, designed for use in Solid applications.
No attack was identified; the inspected preinstall behavior checks the package license with its vendor service.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpackage.json runs license-check.js during preinstall and declares Solid as a peer dependency.
package.jsonView on unpkg · L13Source fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkglicense-check.js reads CENTRAL_LICENSE_KEY and sends it as a bearer credential to centralicons.com/license/check for package license validation.
license-check.jsView on unpkg · L1license-check.js reads CENTRAL_LICENSE_KEY and sends it as a bearer credential to centralicons.com/license/check for package license validation.
license-check.jsView on unpkg · L13This report applies to @central-icons-solid/square-filled-radius-0-stroke-1@1.2.8.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L14package.json runs license-check.js during preinstall and declares Solid as a peer dependency.
package.jsonView on unpkg · L13license-check.js reads CENTRAL_LICENSE_KEY and sends it as a bearer credential to centralicons.com/license/check for package license validation.
license-check.jsView on unpkg · L1license-check.js reads CENTRAL_LICENSE_KEY and sends it as a bearer credential to centralicons.com/license/check for package license validation.
license-check.jsView on unpkg · L13Source fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkg