opengov-k6-core

MAL-2026-2027

npmbackdoor3/22/2026
Description

Malicious code in opengov-k6-core (npm)

Indicators of Compromise
SHA256 Hashes (4)
1370c540f2157e1e42d9edb109b0b6c57f27d35cfcfd8ebef2a5dc2d44db6e39
39882ee3cb32889215387dc3fcc0a081feb399af90e432993d3682e46a18c25c
2d6d3e0e21551377d17f0e85338f6ea9650b7c18f717b6e1060b1d50962ed112
8a490860aa197454225752e73b19319b8da8f839686b33343fb7ee2e467e0e1e
Domains (1)
litellm.cloud
Details
Ecosystemnpm
Attack Typebackdoor
Published3/22/2026
Affected Versions
0
Aliases
GHSA-h38m-4w8q-55j2
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001