dotenv-plugin

MAL-2026-1716

npmmalware3/18/2026
Description

Malicious code in dotenv-plugin (npm)

Indicators of Compromise
SHA256 Hashes (2)
7e18b05c76322d19af0b81b73e433b3622cc093d5ce22bac8fa5f4b8e12fb8ab
8c1892dd92715cddb9d2bc58111d6b2e4352677ff4d6b155ed7ddc9e04f06edf
Details
Ecosystemnpm
Attack Typemalware
Published3/18/2026
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001