nottuff6

MAL-2026-10358

npmmalware7/13/2026
Description

Malicious code in nottuff6 (npm)

Indicators of Compromise
SHA256 Hashes (4)
b379f4df94ba94af8270d0e79067cd5904dc914d3b48ce6206deed2e6097abc4
31a4e89de7dc0db67a1f6c404dc1b6b0b418cd8207e71ad82ef8d2027acb7ea9
5450b6740902f6a90f42484c4851717789920d7163096e12e512377a0ad822b1
d24e9c7be4f8787306797ee2eb472d5c36ef777d83cbf63324d239d7e893e6cc
Details
Ecosystemnpm
Attack Typemalware
Published7/13/2026
Aliases
GHSA-4473-gr94-55rw
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001