json-bundling

MAL-2026-1977

npmmalware3/20/2026
Description

Malicious code in json-bundling (npm)

Indicators of Compromise
SHA256 Hashes (4)
debc855dc41e080d6afbfd087c2a01d8d9e5fac885734e59fb2e1adb870d6198
61f19cbc17dc9182ab2266b7b505dedb74da2b797aa6661669f53efd1b86777a
f530ce38d9a2941eb6a59e2e5e77f62d33890162e4efb2e525a743af6a2995b3
e84a515586ae462b94817088e4b6dfd8c2489ab47181ae0e0e99347a3d49b324
Details
Ecosystemnpm
Attack Typemalware
Published3/20/2026
Affected Versions
0
Aliases
GHSA-58m2-f8rc-wwq2
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001