npm

svelte-streak-metric @1.0.0

Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC

Malicious

OSV ID

MAL-2026-11391

Ecosystem

npm

Summary

The package contains no code paths matching supply-chain attack fingerprints: no install/postinstall lifecycle hooks fetching or executing remote content, no reads of installer secrets (~/.aws, ~/.ssh, ~/.npmrc, browser profiles, env-var scraping), no hardcoded attacker network destinations, no dropper, no silent-relay of caller-supplied data, and no backdoor mechanism.

Source: amazon-inspector (fc322e0a092d833331b172d9796648351685df0cc31d98f590288d859a00f77e)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.