A collection of round outlined Svelte icons with 2px radius and 1.5px stroke width, designed for use in Svelte applications.
No attack was identified. The install hook checks a caller-supplied license key with the package vendor, while the inspected icon source renders SVG content.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgThe preinstall hook runs a license check, and the package entrypoint exports Svelte icon components.
package.jsonView on unpkg · L14A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
Icon3d/Icon3d.svelteView on unpkgThe flagged icon component imports a shared Svelte base and contains SVG icon markup.
Icon3d/Icon3d.svelteView on unpkg · L1Source fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkgThe check reads an explicitly named license key from the environment and sends it to the vendor license endpoint for this package.
license-check.jsView on unpkg · L1This report applies to @central-icons-svelte/round-outlined-radius-2-stroke-1.5@1.2.6.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkg · L15The preinstall hook runs a license check, and the package entrypoint exports Svelte icon components.
package.jsonView on unpkg · L14The flagged icon component imports a shared Svelte base and contains SVG icon markup.
Icon3d/Icon3d.svelteView on unpkg · L1A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
Icon3d/Icon3d.svelteView on unpkgThe check reads an explicitly named license key from the environment and sends it to the vendor license endpoint for this package.
license-check.jsView on unpkg · L1Source fingerprint signature matches a known malicious package signature; route for source-aware review.
license-check.jsView on unpkg