dotenvv-tool

MAL-2026-3758

npmmalware5/14/2026
Description

Malicious code in dotenvv-tool (npm)

Indicators of Compromise
SHA256 Hashes (6)
1062669f2c30cac905f3866fea3c00fe6911ad978798418549d6a5e7c5547074
aaf6769b158992b3a645fdae457ee3d759a0082919726b4eacc57d0832db8c07
cc6d0e6e0c6fde21facbe811f1b8cfa6076b62061cc10d6f272e27855181299c
4bca8ab293e09471eee82235e122a8791d1194d3433a117f5b4e2ee3075ab05d
5f795e9a94b971ddc6e554688cf6e7f4d38796486582095a7b9de48ba121ca03
79fd33c6e511ab11f10b1dae91e2f083f486dd020bbf2dca5256eabc904f61b7
Details
Ecosystemnpm
Attack Typemalware
Published5/14/2026
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001