npm

hfkcdyuwbdx1 @1.0.0

Vulnerability report · Last retrieved from osv.dev August 13, 2026 at 4:27 AM UTC

Malicious

OSV ID

MAL-2026-13812

Ecosystem

npm

Summary

Package hfkcdyuwbdx1@1.0.0 was scanned but produced no concrete findings from either rule-based checks or contextual code tracing. The package name is a random-looking alphanumeric string with no descriptive meaning, which is a common shape for throwaway/test/placeholder publications on npm. Without traced code evidence, no specific installer-harm mechanism (exfiltration, install-time fetch-and-execute, silent relay, credential distribution, backdoor) can be confirmed. Routing to human review so a reviewer can inspect the tarball contents and decide whether this is a benign placeholder, an abandoned test upload, or the start of a campaign.

Source: amazon-inspector (5c3d2f214c9d9ba8dcc912ba18272665044c75eb18d8335c18b959687d45cbdb)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.