nottuff9

MAL-2026-10360

npmmalware7/13/2026
Description

Malicious code in nottuff9 (npm)

Indicators of Compromise
SHA256 Hashes (4)
f68e3e87e0493161905e0c66c8ae28f96135b916a9d627b663005af758ffe810
3c6210eaca44901153bc909ce8f071e22124821bb4f3faaad1c2e9fb1189f46c
66ffa2d71942d2e657b06e670bd87a513a3a98d75f598a1605682d6a2eb055ad
be23739a627860fe11818e78e331289f64d851840b35a9bb91fe5a09e3105858
Details
Ecosystemnpm
Attack Typemalware
Published7/13/2026
Aliases
GHSA-499v-5485-8jjx
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001