{"id":"MAL-2026-10891","summary":"Malicious code in bytecraft (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (55b4433b369e2ff82bc33b11110ddfa63c15a2d685bf3484fb37092ae4bd077f)\nNo suspicious behavior was identified in this version of bytecraft. There is no evidence of install-time network activity, lifecycle scripts fetching remote code, credential access, environment scraping, hardcoded exfiltration endpoints, or other supply-chain attack patterns. The package appears to be a normal library release.\n","aliases":["GHSA-r2fr-28j9-gjh5"],"modified":"2026-09-01T11:30:57.594371590Z","published":"2026-07-20T10:36:27Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-07-20T13:14:44.175930129Z","modified_time":"2026-07-20T10:36:27Z","sha256":"ea6749c0d90490ce1d96256089ac367d4f8ed4fd41c05366fcd20066e4dfffdb","source":"reversing-labs","versions":["1.5.0","2.0.0"],"id":"RLMA-2026-05504"},{"sha256":"5019255f92ddbba1d16121932a97c3dded3479048dea28e835e67751613a7e04","source":"amazon-inspector","versions":["1.5.0"],"id":"IN-MAL-2026-013184","import_time":"2026-08-05T06:00:51.413158945Z","modified_time":"2026-08-05T05:45:53Z"},{"versions":["2.0.0"],"id":"IN-MAL-2026-013181","import_time":"2026-08-05T06:00:51.108124767Z","modified_time":"2026-08-05T05:45:27Z","sha256":"55b4433b369e2ff82bc33b11110ddfa63c15a2d685bf3484fb37092ae4bd077f","source":"amazon-inspector"},{"sha256":"fb9bfa4e98ba9decd2bf6acacb0af852d6c086c1bcf7d3c08cf8794b97944002","source":"reversing-labs","id":"RLUA-2026-06103","import_time":"2026-09-01T11:17:58.408600176Z","modified_time":"2026-08-24T16:42:42Z"}]},"references":[{"type":"WEB","url":"https://safedep.io/procwire-npm-windows-dropper-campaign"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/bytecraft/v/1.5.0"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/bytecraft/v/2.0.0"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-r2fr-28j9-gjh5"}],"affected":[{"package":{"name":"bytecraft","ecosystem":"npm","purl":"pkg:npm/bytecraft"},"versions":["1.5.0","2.0.0"],"database_specific":{"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/bytecraft/MAL-2026-10891.json","cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"}]}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"ReversingLabs","contact":["https://www.reversinglabs.com"],"type":"FINDER"}]}