npm
Malicious svelte-metric-map @1.0.1
Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC
OSV ID
MAL-2026-11390
Ecosystem
npm
Summary
No malicious behaviors were identified in the package contents. No install-time lifecycle scripts fetching external code, no credential or environment reads directed to non-first-party endpoints, no obfuscated payloads, and no known-bad network destinations are present.
Source: amazon-inspector (76c232192bc12931cca4480eb306026c8ca4776ace0353ddb00fe7b947515b25)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.