dotenvx-ext

MAL-2026-1007

npmmalware2/24/2026
Description

Malicious code in dotenvx-ext (npm)

Indicators of Compromise
SHA256 Hashes (3)
a3af4fb14756c0946c71147b11cfa0f09db31ba182c62938c62671d2c2059c8e
cb1944d5124a9fcb2f280723cad9c0c8116d155fc29444186a9e86bfb3609afc
d86f9292a7e07995d83ba2b88d3fe7492ab45f8e6eb851e030ae732bab595e15
Details
Ecosystemnpm
Attack Typemalware
Published2/24/2026
Affected Versions
0
Aliases
GHSA-rggj-8jcg-33c7
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001