npm

truecxikdsal @1.0.0

Vulnerability report · Last retrieved from osv.dev August 14, 2026 at 6:32 AM UTC

Malicious

OSV ID

MAL-2026-13835

Ecosystem

npm

Summary

Package truecxikdsal@1.0.0 contains 2 files and no static or traced findings indicate exfiltration, install-time code execution, credential access, silent-relay, backdoor, or self-propagation. The package name has no obvious relationship to a known project and could reflect a placeholder or test publication, but the shipped contents do not exhibit a supply-chain attack pattern against installers.

Source: amazon-inspector (f817d78ce8fd51571e9d9b3d0d10c09a75dc8353e43e55f5440afa8e303c4ce2)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.