npm
Malicious svelte-vim-kit @1.0.0
Vulnerability report · Last retrieved from osv.dev August 13, 2026 at 4:27 AM UTC
OSV ID
MAL-2026-13769
Ecosystem
npm
Summary
No a static rule matches or traced behavior indicative of exfiltration, install-time remote code execution, silent relay, credential distribution, backdoor, or self-propagation were observed in this package version. No hardcoded attacker endpoints, lifecycle-hook-driven fetch-and-execute, or reads of installer-owned secret paths were identified.
Source: amazon-inspector (b0c572d78a3be9d0fc30b6124c044c329fec518da18bb9e1ca3c22d7f18195e3)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.