npm

vlbhvgovbbhfab @1.0.0

Vulnerability report · Last retrieved from osv.dev August 13, 2026 at 4:27 AM UTC

Malicious

OSV ID

MAL-2026-13842

Ecosystem

npm

Summary

Package vlbhvgovbbhfab@1.0.0 contains 2 files. No install-time lifecycle scripts, exfiltration primitives, hardcoded network destinations, credential-file reads, obfuscated payloads, or dropper patterns were observed in the package contents. The random-looking name and minimal footprint are consistent with a placeholder or test publication rather than a functional library.

Source: amazon-inspector (d5b717c270d7c4f965a421923d78bff7a86b044999f557386a258c7050768620)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.