@lyxa.ai/core

MAL-2026-13434

npmmalware8/6/2026
Description

Malicious code in @lyxa.ai/core (npm)

Indicators of Compromise
SHA256 Hashes (20)
0aab606a35cc885f17daa4b943ffbc1ee3e691adfffa24513e5741758090953e
28e9b605fd0af18680342f725e028fc612744a47e2ddf6dc86b4352babc60bde
9bc2087e4e8aefbb672176906a2c4024a3deb2b6b4114dcd2d75c5d222558588
e8f074d2f617feee28f5f09f393dd6810df53a03b48cd23111239972d4dc6f7c
f9322cb3d37df8cb254835171dd2d48cee1076ae99e09344db7faa6c8ae15212
c120262f3806a610de489ebcba7302780d2de23d17a488f5f234e4a7f3e13d65
d4092c78614b93ae58f52ffada20d6d58314406edb72d0629e991148a6d0c8e4
e4814f0506585fa3e90397e31051bcf2f7eb91f431f546f199b3ffe9afb51bc5
9cafacec65b89c0bcfb7e67a3ddc0343a810ebebefec2b351341920e403545e9
a25f0470927b0a29c20475fea96ba8ae11cc06b574aefea78b7359f2aca853ad
Details
Ecosystemnpm
Attack Typemalware
Published8/6/2026
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001