MAL-2026-10893

    Dashboard / Malicious Package / MAL-2026-10893

    MAL-2026-10893

    Published: 20 Jul 2026Last Modified: 1 Sept 2026Aliases: 
    GHSA-wx6c-2wgg-hcwq

    Summary: Malicious code in ecto-cargo-wk1tm59a (npm)

    Details: Source: amazon-inspector (ee496f01ecebc77637213e597ba523c8cccda7efcd65e7ad2e700d804553dd29) Package [email protected] exhibits several contextual red flags worth human review: a randomized-suffix name pattern (`-wk1tm59a`) typical of disposable/throwaway publishes, an inflated `99.0.0` version typical of dependency-confusion / proof-of-concept publishes, and only 3 files in the tarball. Automated content inspection of the package's code did not produce a usable trace, but the content was non-trivial enough that an automated description could not be produced. No specific attacker domain, exfiltration endpoint, or install-time fetch-and-execute behavior has been concretely identified from the available evidence, so a public block verdict is not justified, but the combination of disposable-name shape, `99.0.0` version inflation, and untraced contents warrants human inspection before this package is trusted.

    Affected packages

    Package

    Name: ecto-cargo-wk1tm59a

    Purl: pkg:npm/ecto-cargo-wk1tm59a

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    99.0.0
    MAL-2026-10893 | CVE-DB