json-merge-tool

MAL-2026-1297

npmmalware3/9/2026
Description

Malicious code in json-merge-tool (npm)

Indicators of Compromise
SHA256 Hashes (3)
4bb041118bdac1123bd722a9b1f99ddb6ca406f7ce80d5de344b2c36614b89e9
f16e8d9c37feb30d5a44f7a94620c3a09d182a34cd5ccc1e7c97aaf4a991ab10
573d54372e591af2f5a25153f677feed589f98f0da62aef9c3bcc5afec37d1ae
Details
Ecosystemnpm
Attack Typemalware
Published3/9/2026
Affected Versions
0
Aliases
GHSA-cpf2-rx79-x333
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001