npm
Malicious cvbmxiowkwqla6 @1.0.0
Vulnerability report · Last retrieved from osv.dev August 13, 2026 at 5:28 AM UTC
OSV ID
MAL-2026-13796
Ecosystem
npm
Summary
Package cvbmxiowkwqla6@1.0.0 contains only two files and no behaviors matching supply-chain attack patterns were identified. No lifecycle scripts, network calls, credential reads, or code-execution primitives are present in the analyzed contents. The package name is a random-looking string, which is consistent with placeholder, test, or throwaway publications.
Source: amazon-inspector (0dbfcc7e82fc725383c9578e9d53c4e69bdf6af9ba8037d2bf9fa50dce51969e)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.