@zakhaevv/envai

MAL-2026-1172

npmmalware3/3/2026
Description

Malicious code in @zakhaevv/envai (npm)

Indicators of Compromise
SHA256 Hashes (2)
12157c0eeb0adb6f316ee9f171691ae08e204ec84f3ad7dabf9213e2af244b7c
ccd4de2673a9f50b205b51474085ef3eb3e78f06618873183038582fb48bacfe
Details
Ecosystemnpm
Attack Typemalware
Published3/3/2026
Affected Versions
0
Aliases
GHSA-33h9-mg87-vq25
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001