nottuff26

MAL-2026-10351

npmmalware7/13/2026
Description

Malicious code in nottuff26 (npm)

Indicators of Compromise
SHA256 Hashes (4)
180cd6e1e76555a8f74e0ed8bc3d5fcb0eefce908657fd66c3ac38bf52db08f2
4d6f3663bcc4d41d4ec7b7e07a43f82567efbbab2cfb098d7227f0f0803e7577
d56220f736c17017a0397de0432d9f4640d62ecf42ca4c0a9dfe4e526fe8aa43
dc7ef04cad8fe8d698b57a20aa5d9906155edaab18b772dad3f40c5c99251840
Details
Ecosystemnpm
Attack Typemalware
Published7/13/2026
Aliases
GHSA-gqpp-9m3q-r5pr
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001