npm

svelte-streak-metrics @1.0.0

Vulnerability report · Last retrieved from osv.dev August 5, 2026 at 5:03 PM UTC

Malicious

OSV ID

MAL-2026-11038

Ecosystem

npm

Summary

The package contains no static or traced indicators of exfiltration, install-time remote code execution, silent-relay, credential distribution, backdoor, or self-propagation. No lifecycle scripts fetching or executing external content, no reads of installer credential paths, and no hardcoded attacker-controlled network destinations were observed in the analyzed files.

Source: amazon-inspector (45dbfe79dd6fb079811b798a734de0a661605d420454d97a0635dbdaec621efd)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.