MAL-2026-10891

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bytecraft/MAL-2026-10891.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-10891
Aliases
  • GHSA-r2fr-28j9-gjh5
Published
2026-07-20T10:36:27Z
Modified
2026-09-01T11:30:57Z
Summary
Malicious code in bytecraft (npm)
Details

-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (55b4433b369e2ff82bc33b11110ddfa63c15a2d685bf3484fb37092ae4bd077f)

No suspicious behavior was identified in this version of bytecraft. There is no evidence of install-time network activity, lifecycle scripts fetching remote code, credential access, environment scraping, hardcoded exfiltration endpoints, or other supply-chain attack patterns. The package appears to be a normal library release.

Database specific
{
    "malicious-packages-origins": [
        {
            "id": "RLMA-2026-05504",
            "import_time": "2026-07-20T13:14:44.175930129Z",
            "modified_time": "2026-07-20T10:36:27Z",
            "sha256": "ea6749c0d90490ce1d96256089ac367d4f8ed4fd41c05366fcd20066e4dfffdb",
            "source": "reversing-labs",
            "versions": [
                "1.5.0",
                "2.0.0"
            ]
        },
        {
            "id": "IN-MAL-2026-013184",
            "import_time": "2026-08-05T06:00:51.413158945Z",
            "modified_time": "2026-08-05T05:45:53Z",
            "sha256": "5019255f92ddbba1d16121932a97c3dded3479048dea28e835e67751613a7e04",
            "source": "amazon-inspector",
            "versions": [
                "1.5.0"
            ]
        },
        {
            "id": "IN-MAL-2026-013181",
            "import_time": "2026-08-05T06:00:51.108124767Z",
            "modified_time": "2026-08-05T05:45:27Z",
            "sha256": "55b4433b369e2ff82bc33b11110ddfa63c15a2d685bf3484fb37092ae4bd077f",
            "source": "amazon-inspector",
            "versions": [
                "2.0.0"
            ]
        },
        {
            "id": "RLUA-2026-06103",
            "import_time": "2026-09-01T11:17:58.408600176Z",
            "modified_time": "2026-08-24T16:42:42Z",
            "sha256": "fb9bfa4e98ba9decd2bf6acacb0af852d6c086c1bcf7d3c08cf8794b97944002",
            "source": "reversing-labs"
        }
    ]
}
References
Credits

Affected packages

npm / bytecraft

Package

Affected ranges

Affected versions

1.*
1.5.0
2.*
2.0.0

Database specific

cwes
[
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    },
    {
        "cweId": "CWE-506",
        "description": "The product contains code that appears to be malicious in nature.",
        "name": "Embedded Malicious Code"
    }
]
source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bytecraft/MAL-2026-10891.json"