npm
Malicious svelte-cache-kit @1.0.0
Vulnerability report · Last retrieved from osv.dev August 10, 2026 at 10:20 PM UTC
OSV ID
MAL-2026-13676
Ecosystem
npm
Summary
No a static rule matches and no traced install-time or import-time behavior of concern were identified in this package version. No credential access, network exfiltration, remote fetch-and-execute, silent-relay, or persistence mechanisms are present in the shipped files.
Source: amazon-inspector (1453b15dc9dc17e87c7dd53ab81d2e1c5988a6a3436d37e90500acd83dacdd22)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.