npm

svelte-metric-map @1.0.1

Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC

Malicious

OSV ID

MAL-2026-11390

Ecosystem

npm

Summary

No malicious behaviors were identified in the package contents. No install-time lifecycle scripts fetching external code, no credential or environment reads directed to non-first-party endpoints, no obfuscated payloads, and no known-bad network destinations are present.

Source: amazon-inspector (76c232192bc12931cca4480eb306026c8ca4776ace0353ddb00fe7b947515b25)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.