evilcharts-svelte
Warn
Audited by Socket on Sep 5, 2026
1 alert found:
SecuritySecurityreferences/implementation-guide.md
MEDIUMSecurityMEDIUM
references/implementation-guide.md
High supply-chain risk. The guide instructs installing chart components via npx using a remote registry/spec from a suspicious domain, then importing executable code from $lib/components/evilcharts/... into the application. No integrity/signing/pinning controls are described. While the snippet itself contains no explicit malicious payload code, the described install-and-execute pipeline makes the overall guidance dangerous and warrants rejecting the install source and verifying any downloaded artifacts against trusted, integrity-checked sources.
Confidence: 78%Severity: 92%
Audit Metadata