nottuff5

MAL-2026-10357

npmmalware7/13/2026
Description

Malicious code in nottuff5 (npm)

Indicators of Compromise
SHA256 Hashes (4)
aeaa37a35be71c14ab4040dd8100819afd2ca4fb6aa639879ff50ad323acebf8
0e18070e680629849560dab1723a73f80d61312d0a9efe429b0c8f43b2177bbd
7ab0ca87f0c8238d0e0336d8905741ff7a72d393c4a2294caf162b508feef099
b6d23a66f4751d6e57f438538c830e9b220e5ec363b45d330baa614f5a193dbe
Details
Ecosystemnpm
Attack Typemalware
Published7/13/2026
Aliases
GHSA-hqcf-hxmg-9rgv
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001