A collection of round filled Svelte icons with 0px radius and 1px stroke width, designed for use in Svelte applications.
No confirmed attack was identified. The install hook performs authentication to a fixed package-aligned license service, and the inspected runtime sources provide SVG icons.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpackage.json runs license-check.js during preinstall and has no runtime self-dependency.
package.jsonView on unpkg · L15A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
Icon3d/Icon3d.svelteView on unpkgIcon3d/Icon3d.svelte imports the shared component and renders SVG paths.
Icon3d/Icon3d.svelteView on unpkg · L1Source fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkglicense-check.js sends the license key only to the fixed Central Icons license endpoint.
license-check.jsView on unpkg · L14This report applies to @central-icons-svelte/round-filled-radius-0-stroke-1@1.2.2.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L15package.json runs license-check.js during preinstall and has no runtime self-dependency.
package.jsonView on unpkg · L15Icon3d/Icon3d.svelte imports the shared component and renders SVG paths.
Icon3d/Icon3d.svelteView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
Icon3d/Icon3d.svelteView on unpkglicense-check.js sends the license key only to the fixed Central Icons license endpoint.
license-check.jsView on unpkg · L14Source fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkg