npm
Malicious @bikli/bikli @1.1.10
Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 6:32 AM UTC
OSV ID
MAL-2026-13778
Ecosystem
npm
Summary
No static or traced indicators of supply-chain attack behavior were observed in this package version. No lifecycle scripts fetching or executing remote content, no credential or environment scraping, no hardcoded attacker network destinations, no silent-relay of caller-supplied data, and no persistence or backdoor mechanisms are present in the scanned files.
Source: amazon-inspector (47a9677012577b19f49cd85cc6455abea3b1363e77a54030901ecf916b04c50b)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.