nottuff8

MAL-2026-10359

npmmalware7/13/2026
Description

Malicious code in nottuff8 (npm)

Indicators of Compromise
SHA256 Hashes (4)
089e965414e614f8466f33131a676345c9345cb68ac6e2382c4de68fb449fcbc
4281f3e1363cd272d402582ac8d7bf2a0c0e0a75d42827a227dafaedebdc87d9
5bdd16826fccdc2a5c8dddeb6c75172029565a698cdf5c5f82a918e15561f60b
6b101643a3e3c28165db51cadc68b2921c6babb01b09e565e3cd4355833d1484
Details
Ecosystemnpm
Attack Typemalware
Published7/13/2026
Aliases
GHSA-475j-h2wx-3hmp
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001