npm

rdfxvela-build @1.0.0

Vulnerability report · Last retrieved from osv.dev August 8, 2026 at 12:14 AM UTC

Malicious

OSV ID

MAL-2026-13492

Ecosystem

npm

Summary

The package contains 4 files and no static or traced findings indicate credential access, network exfiltration, install-time code fetch and execution, silent-relay of caller data, persistence, or other installer-side harmful behavior. No hardcoded attacker endpoints, obfuscated payloads, lifecycle-hook droppers, or credential-store reads are present in the analyzed contents.

Source: amazon-inspector (ef19b46ba2f8a9d7a30bedb44d2e45903d5e4e905d736b5ce5c20cbb0b77be12)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.