A lightweight React utility for fetching, validating, and managing SVG icons from CDN sources.
Calling getPlugin or setPlugin recursively reads caller-selected SVG paths, silently installs an undeclared package into the current project, then loads it. This creates remote code execution through a registry-fetched dependency.
Source file is highly similar to a previously finalized malicious package; route for source-aware review.
index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkgPackage source references dynamic require/import behavior.
index.jsView on unpkg · L17Package source references dynamic require/import behavior.
index.jsView on unpkg · L17Source file is highly similar to a previously finalized malicious package; route for source-aware review.
index.jsView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
index.jsView on unpkg