@voiceflow/natural-language-commander

MAL-2025-191356

npmmalware11/25/2025
Description

Malicious code in @voiceflow/natural-language-commander (npm)

Indicators of Compromise
SHA256 Hashes (3)
c36ff4b9d85a8936abeb34dfa4ccdb4371d59602d32c7e59a2a210dccee485a2
e8749cf076a2f41ebb0f9c63659b21196586da1eca7a3a5067ef0d45918390fc
bcffcb39c546d02117506c26844a1fddcedc61f18cd934b27642817c62189437
Details
Ecosystemnpm
Attack Typemalware
Published11/25/2025
Aliases
GHSA-4xjf-wwjc-fmhv
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001