A collection of round outlined Svelte icons with 2px radius and 1.5px stroke width, designed for use in Svelte applications.
Installing the package automatically transmits an environment-sourced license key to a remote host. The normal imports are static Svelte icon exports, but the install hook creates a credential-exfiltration surface.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgAn automatic preinstall hook runs license-check.js during dependency installation.
package.jsonView on unpkg · L14A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
Icon3d/Icon3d.svelteView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkgThe hook reads CENTRAL_LICENSE_KEY and sends it as a Bearer token to a remote host.
license-check.jsView on unpkg · L1The hook reads CENTRAL_LICENSE_KEY and sends it as a Bearer token to a remote host.
license-check.jsView on unpkg · L14This report applies to @central-icons-svelte/round-outlined-radius-2-stroke-1.5@1.1.316.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L15An automatic preinstall hook runs license-check.js during dependency installation.
package.jsonView on unpkg · L14A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
Icon3d/Icon3d.svelteView on unpkgThe hook reads CENTRAL_LICENSE_KEY and sends it as a Bearer token to a remote host.
license-check.jsView on unpkg · L1The hook reads CENTRAL_LICENSE_KEY and sends it as a Bearer token to a remote host.
license-check.jsView on unpkg · L14Source fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkg