@onlytoodles/crypto-jsa

MAL-2025-192397

npmmalware12/10/2025
Description

Malicious code in @onlytoodles/crypto-jsa (npm)

Indicators of Compromise
SHA256 Hashes (2)
9f4f73b2593673e363edf8174ffedd7502ee3088c424583092776d77c8044188
731c33f548ff79b458afc89fa8f3158762537acf2db8d026864792bb3222be7c
Details
Ecosystemnpm
Attack Typemalware
Published12/10/2025
Aliases
GHSA-8454-2xp4-m86m
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001