npm

chmjdsidwlf5 @1.0.0

Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 6:32 AM UTC

Malicious

OSV ID

MAL-2026-13792

Ecosystem

npm

Summary

Package chmjdsidwlf5@1.0.0 contains 2 files with no a static rule matches and no traced behavior indicating exfiltration, install-time remote code execution, silent relay, credential distribution, backdoor, or self-propagation. The random-looking package name is unusual, but name shape alone is not a threat and the code performs no installer-facing harmful action.

Source: amazon-inspector (e5c33467a3378e72f39a5093bded42a1aba6c08cca38cd631ea1ecc233e0377a)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.