OpenSSF/OSV advisory MAL-2026-13705 confirms this npm version as malicious. iconova-react is a re-hosted copy of lucide-react (every icon file carries a `@license lucide-react` header; the package name is iconova-react but its entry points are `dist/cjs/lucide-react.js` and `dist/esm/lucide-react.mjs`) with a malicious loader injected into two icon modules, `dist/esm/icons/sparkle.mjs` and `dist/esm/icons/sparkles.mjs`...
Package source references child process execution.
dist/esm/icons/sparkle.mjsView on unpkg · L18A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/esm/icons/sparkle.mjsView on unpkg · L18Package source references a known benign dynamic code generation pattern.
dist/esm/icons/sparkle.mjsView on unpkg · L18Package source references child process execution.
dist/esm/icons/sparkle.mjsView on unpkg · L18A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/esm/icons/sparkle.mjsView on unpkg · L18Package source references a known benign dynamic code generation pattern.
dist/esm/icons/sparkle.mjsView on unpkg · L18