@kyriba/mf-kit

MAL-2026-165

npmmalware1/8/2026
Description

Malicious code in @kyriba/mf-kit (npm)

Indicators of Compromise
SHA256 Hashes (3)
c79fa513677c2f0d2cd3c56b216959c44395c65ef382d1fbdb86db6a6d0a8e16
fa1b2dd3479a677d975d11f8fe29e2cb24cbcc3a90c05081fa1632822c7c2f5a
5316d385b586e69d62f54165ad5c9a973bf0bdfc3ef7023a0f7f53c784bb7131
Details
Ecosystemnpm
Attack Typemalware
Published1/8/2026
Affected Versions
0
Aliases
GHSA-vm49-whhj-p386
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001