@addai/entity-runtime

MAL-2026-13410

npmmalware8/6/2026
Description

Malicious code in @addai/entity-runtime (npm)

Indicators of Compromise
SHA256 Hashes (12)
248d92bb0f9ac7a066bb69c3f3ecea88241e5dd35ea1b61393896c88c07b0856
cc5ab4270a0a70d482a6f9330a2f91d996ca6f0d3e6000d3bc34f9dadc0b4216
d9484bdd16ab9c436109c23a4f9ed8bdcba73a042d5f5b2fb8826fae1ba1abe3
e3b20d90f97a5d37e2127b427614c3a0859b08ecd1e99be97065112007910d61
f6c0c153959ae4bda2c8db51b34f1b769c3ea329324a9dda38041aa012e6c3d4
2a2c056dc9d2bfeb44511be27e07f31e4222b356605969294f3284ad0445e132
3d63c259eb725774353d4e5ff7478d7e88c8ae030855bfa3d2a653d20f33bffa
7a66f3ce363db41a478bf2a8d3e052bf639c962de5942a5e989725af3ab6b3c8
b3d98d001e4e4b7f1397c2dee761c04e56b70370c6957754772f3e1674a6bbb1
c2f8b71ac7ea395aa6b4a7ec7f6cad04bb9c9188c3befd0650232f6c49aba75e
Details
Ecosystemnpm
Attack Typemalware
Published8/6/2026
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001