OpenSSF/OSV advisory MAL-2026-10891 confirms this npm version as malicious. No suspicious behavior was identified in this version of bytecraft. There is no evidence of install-time network activity, lifecycle scripts fetching remote code, credential access, environment scraping, hardcoded exfiltration endpoints, or other supply-chain attack patterns. The package appears to be a normal library release.
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in bytecraft (npm)
Details
No suspicious behavior was identified in this version of bytecraft. There is no evidence of install-time network activity, lifecycle scripts fetching remote code, credential access, environment scraping, hardcoded exfiltration endpoints, or other supply-chain attack patterns. The package appears to be a normal library release.
Decision reason
OpenSSF Malicious Packages via OSV confirms bytecraft@1.5.0 as malicious (MAL-2026-10891): Malicious code in bytecraft (npm)