@bokehjs/core

MAL-2026-2578

npmmalware4/13/2026
Description

Malicious code in @bokehjs/core (npm)

Indicators of Compromise
SHA256 Hashes (1)
6e18981ac8adec7cb489a1be8841f5f6862c8f1298c570346d5210c99dd275fe
Details
Ecosystemnpm
Attack Typemalware
Published4/13/2026
Affected Versions
0
Aliases
GHSA-j77c-vj44-wvq4
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001