A lightweight React utility for fetching, validating, and managing SVG icons from CDN sources.
Calling getPlugin or setPlugin on an SVG path silently spawns a decoded npm install command, then dynamically loads the installed module. This creates remote package lifecycle/code execution outside declared dependencies.
Source decodes numeric character arrays into a child-process package-runner command and executes it.
index.jsView on unpkg · L17A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
index.jsView on unpkgPackage source references dynamic require/import behavior.
index.jsView on unpkg · L17Source decodes numeric character arrays into a child-process package-runner command and executes it.
index.jsView on unpkg · L17A package entrypoint or install-time lifecycle script reaches a source file with blocking dangerous behavior.
index.jsView on unpkgPackage source references dynamic require/import behavior.
index.jsView on unpkg · L17