npm

vczxijghsvizu4 @1.0.0

Vulnerability report · Last retrieved from osv.dev August 13, 2026 at 5:28 AM UTC

Malicious

OSV ID

MAL-2026-13839

Ecosystem

npm

Summary

Package vczxijghsvizu4@1.0.0 contains 2 files with no a static rule matches and no traced behavior indicating exfiltration, install-time code execution, credential access, silent relay, backdoor, or self-propagation. The random-looking package name is unusual and may indicate a placeholder, test upload, or throwaway publication, but the shipped code does not demonstrate any mechanism that harms an installer.

Source: amazon-inspector (7bae2fa8ce447bf7b8dbe7b16f14e37b56f713aff508b26f937188a1570d8309)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.