nottuff2

MAL-2026-10346

npmmalware7/13/2026
Description

Malicious code in nottuff2 (npm)

Indicators of Compromise
SHA256 Hashes (4)
072c875496e01626857bdffbbbaee26844e3099941015a151b830d8f3de426f7
2505cd60f257bd1c69e2bd6ccbaa987e2045a453adb8c0e1c529c34afade95c7
3235e57552282600b42096bfe757dcc8f219fd452eb73f95a4e681dd683c6395
9817d609a80e74f8d0f0398387dc8a4f98ecfce0bb0c17006b17ede9959cd892
Details
Ecosystemnpm
Attack Typemalware
Published7/13/2026
Aliases
GHSA-cw6g-9475-rfqx
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001