npm

svelte-goal-streak @1.0.0

Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC

Malicious

OSV ID

MAL-2026-11037

Ecosystem

npm

Summary

svelte-goal-streak@1.0.0 shows no evidence of exfiltration, install-time code fetching, credential access, silent-relay, backdoor, or self-propagation. No lifecycle-script network activity, no reads of installer secret paths, and no attacker-controlled network destinations were observed in the package's files.

Source: amazon-inspector (fdc009d2d22b9f02aa6b2cce1ac5eadfcb3f3a7d437cc2ba031eb1e6154da2a4)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.