npm

cvvkshuelwiu @1.0.0

Vulnerability report · Last retrieved from osv.dev August 13, 2026 at 4:27 AM UTC

Malicious

OSV ID

MAL-2026-13800

Ecosystem

npm

Summary

Package cvvkshuelwiu@1.0.0 contains 2 files with no a static rule matches and no traced behaviors of concern. No install-time scripts, network callbacks, credential access, or code execution primitives were identified. The package name is a random-looking alphabetic string, which is unusual for a legitimate library, but the shipped contents do not exhibit any supply-chain attack fingerprint (no exfiltration, no dropper, no silent-relay, no backdoor, no credential distribution).

Source: amazon-inspector (de3f325329894b841474989d30370570a7f1b68d02334db1b98dcaf109899fa9)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.