todo-plz
MAL-2026-1533
npmmalware3/18/2026
Description
Malicious code in todo-plz (npm)
Indicators of Compromise
SHA256 Hashes (2)
c0909f6ee25ac98389eaab0d48b518772c9636ec8439f6837a004af70cfdb539
9c7bb123cdceb6c5860209467edf1770ea558840b38b7fc0592d1d7e5d0593a6
References (1)
Details
Ecosystemnpm
Attack Typemalware
Published3/18/2026
Affected Versions
0
Aliases
GHSA-q93m-663h-q987
Quick Actions