npm

cvbmxiowkwqla6 @1.0.0

Vulnerability report · Last retrieved from osv.dev August 13, 2026 at 5:28 AM UTC

Malicious

OSV ID

MAL-2026-13796

Ecosystem

npm

Summary

Package cvbmxiowkwqla6@1.0.0 contains only two files and no behaviors matching supply-chain attack patterns were identified. No lifecycle scripts, network calls, credential reads, or code-execution primitives are present in the analyzed contents. The package name is a random-looking string, which is consistent with placeholder, test, or throwaway publications.

Source: amazon-inspector (0dbfcc7e82fc725383c9578e9d53c4e69bdf6af9ba8037d2bf9fa50dce51969e)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.