MAL-2026-10891

    Dashboard / Malicious Package / MAL-2026-10891

    MAL-2026-10891

    Published: 20 Jul 2026Last Modified: 1 Sept 2026Aliases: 
    GHSA-r2fr-28j9-gjh5

    Summary: Malicious code in bytecraft (npm)

    Details: Source: amazon-inspector (55b4433b369e2ff82bc33b11110ddfa63c15a2d685bf3484fb37092ae4bd077f) No suspicious behavior was identified in this version of bytecraft. There is no evidence of install-time network activity, lifecycle scripts fetching remote code, credential access, environment scraping, hardcoded exfiltration endpoints, or other supply-chain attack patterns. The package appears to be a normal library release.

    Affected packages

    Package

    Name: bytecraft

    Purl: pkg:npm/bytecraft

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    1.5.0
    MAL-2026-10891 | CVE-DB