SafeDep
Install GitHub App

Summary

Multiple low confidence YARA matches for high entropy. Not enough evidence to classify as malware. False positive possible.

Verification Record

No verification record available.

Details

The package react-native-svg version 15.15.3 has multiple YARA rule matches for very_high_entropy. However, the confidence level is low. High entropy is not necessarily indicative of malicious behavior. It could be due to compression or obfuscation, which are sometimes used legitimately. Given the project's relatively high number of stars and forks, it's less likely to be malicious. Without stronger evidence, I cannot classify this package as malware.

react-native-svg@15.15.3Clean
Unverified
Analysed at: 2/9/26, 2:43 PM
Source: https://registry.npmjs.org/react-native-svg/-/react-native-svg-15.15.3.tgz
SHA256: 5b370a19f5198f776f14ab75862e44d8d52837f49bcf59e5306de1d233e9b7a5
Confidence: Medium