hfkcdyuwbdx1 @1.0.0
Vulnerability report · Last retrieved from osv.dev August 13, 2026 at 4:27 AM UTC
OSV ID
MAL-2026-13812
Ecosystem
npm
Summary
Package hfkcdyuwbdx1@1.0.0 was scanned but produced no concrete findings from either rule-based checks or contextual code tracing. The package name is a random-looking alphanumeric string with no descriptive meaning, which is a common shape for throwaway/test/placeholder publications on npm. Without traced code evidence, no specific installer-harm mechanism (exfiltration, install-time fetch-and-execute, silent relay, credential distribution, backdoor) can be confirmed. Routing to human review so a reviewer can inspect the tarball contents and decide whether this is a benign placeholder, an abandoned test upload, or the start of a campaign.
Source: amazon-inspector (5c3d2f214c9d9ba8dcc912ba18272665044c75eb18d8335c18b959687d45cbdb)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.