SafeDep
Install GitHub App
Start for Free
SafeDep
Install GitHub App
Start for Free

Summary

Single low confidence YARA match python_exec_complex in index.js is insufficient to classify svelte as malware. Verified provenance exists.

Verification Record

No verification record available.

Details

The package svelte version 5.53.0, published by sveltejs/svelte with high stars and forks (85765/4771), has a verified SLSA provenance. While the YARA rule python_exec_complex matched a javascript file (index.js), indicating the execution of code from a complex expression, this single low confidence finding is insufficient to classify it as malware. The rule can be triggered in legitimate javascript code that uses regular expressions or other dynamic code execution techniques. Without further corroborating evidence, it is safer to assume this is a false positive or legitimate use within the svelte compiler.

svelte@5.53.0Clean
Unverified
Analysed at: 2/18/26, 10:04 PM
Source: https://registry.npmjs.org/svelte/-/svelte-5.53.0.tgz
SHA256: d05a3d73671a9d54ee7d3f64076b4041d707ff63a422604a56af4f8c135d7732
Confidence: Medium