nottuff3

MAL-2026-10355

npmmalware7/13/2026
Description

Malicious code in nottuff3 (npm)

Indicators of Compromise
SHA256 Hashes (4)
54ac386de3a53cc8622f655f9c133550c8c4082388a061c66c559ff58e122b2b
1adec69437876499397efaf931f1aa569a8cb462462b673145b664c564701060
827aabf03b8e89c4e61ba513c8f069956fd9b052d904738053f266f9da46963d
eff04f52f6bd973b2ee9af4cd97d6e3f8baac76f32dd6d51e11e6a194debe8c4
Details
Ecosystemnpm
Attack Typemalware
Published7/13/2026
Aliases
GHSA-35r2-xv4w-hr3g
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001