npm
Maliciousbytecraft@2.0.0
Vulnerability report · Last retrieved from osv.dev September 7, 2026 at 5:03 PM UTC
OSV ID
MAL-2026-10891
Ecosystem
npm
Summary
No suspicious behavior was identified in this version of bytecraft. There is no evidence of install-time network activity, lifecycle scripts fetching remote code, credential access, environment scraping, hardcoded exfiltration endpoints, or other supply-chain attack patterns. The package appears to be a normal library release.
Source: amazon-inspector (55b4433b369e2ff82bc33b11110ddfa63c15a2d685bf3484fb37092ae4bd077f)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.