npm
Malicious svelte-mapped-metrics @1.0.0
Vulnerability report · Last retrieved from osv.dev August 6, 2026 at 7:08 PM UTC
OSV ID
MAL-2026-13383
Ecosystem
npm
Summary
svelte-mapped-metrics@1.0.0 shows no evidence of credential access, install-time or import-time code execution from remote sources, silent relay of caller data, hardcoded attacker endpoints, or persistence mechanisms. No lifecycle-script network activity or suspicious file operations were observed in the package contents.
Source: amazon-inspector (666d747ec06fa428dfb0f21867e6001b52450fee1770061dcd9bd0ec9e3731fa)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.