cognito-auth-plugin

MAL-2026-277

npmmalware1/16/2026
Description

Malicious code in cognito-auth-plugin (npm)

Indicators of Compromise
SHA256 Hashes (2)
c9a30b64637eafca16b5e2eba32def6f026de37b2e2085a66aa627c5bfe9403d
075ebb1d340d3f826c4eac89e18d07deb46b42ca209aa992f72d816aaf86a7df
Details
Ecosystemnpm
Attack Typemalware
Published1/16/2026
Affected Versions
0
Aliases
GHSA-qrj2-7j22-58mf
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001