A collection of round filled Svelte icons with 0px radius and 1px stroke width, designed for use in Svelte applications.
No attack was identified. The preinstall hook performs a package-aligned license check, and the inspected icon source renders SVG content.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgpackage.json runs license-check.js during preinstall.
package.jsonView on unpkg · L14A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
Icon3d/Icon3d.svelteView on unpkgIcon3d/Icon3d.svelte imports the shared icon component and renders SVG paths.
Icon3d/Icon3d.svelteView on unpkg · L1Source fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkglicense-check.js reads CENTRAL_LICENSE_KEY and sends it to the vendor license-check endpoint with this package name and version.
license-check.jsView on unpkg · L13This report applies to @central-icons-svelte/round-filled-radius-0-stroke-1@1.2.7.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L15package.json runs license-check.js during preinstall.
package.jsonView on unpkg · L14Icon3d/Icon3d.svelte imports the shared icon component and renders SVG paths.
Icon3d/Icon3d.svelteView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
Icon3d/Icon3d.svelteView on unpkglicense-check.js reads CENTRAL_LICENSE_KEY and sends it to the vendor license-check endpoint with this package name and version.
license-check.jsView on unpkg · L13Source fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkg