cw-isdk

MAL-2026-1420

npmmalware3/13/2026
Description

Malicious code in cw-isdk (npm)

Indicators of Compromise
SHA256 Hashes (18)
a4ddcc5674d5c16f194910e57e000058bf09ed62fc7d55c77e5df1eb8f83fd92
d24aa2de1a9c568893245ad4db43225e926678014e8e8e449c5a1124ff16a533
faf17028795f038f1d2dc298ec9862ff83144b538f4cc137eb159f1d3b439533
c11546602f59c7a53394ba1379bbec5436cad4125bc4d38053ec354d685cf2ae
c40d289372b701bbc83af5302246ca9628e1c850ca415e7b4094cdcf3e765c49
c4a4dfa8d0475e93d21d819cfe8cb6989303bb457e7dea11f5b6dae4cddcedca
1ba54a67d63db10a40bc903c5f0a249e7ff3dc1f7da70b93fc10492e6db07b76
31acfd7f47028b23155766119c87fdadd94352e9a52a048e0283df75aee57bd4
4fd1bdb6bd8a8c7439fa5a5c89173c8186c9d7815ebe7acb15b3b18ecc12aaa4
298be3a18defb650677d42d53a4fd7722d962b0122d69fe859e8a4af9b3d97de
Details
Ecosystemnpm
Attack Typemalware
Published3/13/2026
Affected Versions
0
Aliases
GHSA-4gjw-qxx7-crc6
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001