A collection of square outlined Solid icons with 0px radius and 2px stroke width, designed for use in Solid applications.
npm installation automatically transmits a caller environment credential to a remote license endpoint. This is credential exfiltration from an unrelated icon package.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe preinstall hook automatically runs license-check.js during npm installation.
package.jsonView on unpkg · L13Source fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkgThe install script reads CENTRAL_LICENSE_KEY and sends it as a Bearer credential to centralicons.com.
license-check.jsView on unpkg · L1The install script reads CENTRAL_LICENSE_KEY and sends it as a Bearer credential to centralicons.com.
license-check.jsView on unpkg · L14Installation throws when the license environment variable is absent, pressuring users to expose that credential to the hook.
license-check.jsView on unpkg · L3This report applies to @central-icons-solid/square-outlined-radius-0-stroke-2@1.1.320.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L14The preinstall hook automatically runs license-check.js during npm installation.
package.jsonView on unpkg · L13The install script reads CENTRAL_LICENSE_KEY and sends it as a Bearer credential to centralicons.com.
license-check.jsView on unpkg · L1Installation throws when the license environment variable is absent, pressuring users to expose that credential to the hook.
license-check.jsView on unpkg · L3The install script reads CENTRAL_LICENSE_KEY and sends it as a Bearer credential to centralicons.com.
license-check.jsView on unpkg · L14Source fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkg