clerk-js

MAL-2026-410

npmmalware1/21/2026
Description

Malicious code in clerk-js (npm)

Indicators of Compromise
SHA256 Hashes (2)
2433ecd39bbf328a21740fa34f33bb09d575e76f6f280b915c7ea15fbc55c2b3
380b4e8d88a5d8a96ffe344566787326dbace52224d29a853cd4553fac40bd1c
Details
Ecosystemnpm
Attack Typemalware
Published1/21/2026
Affected Versions
0
Aliases
GHSA-vr7m-h7j3-rxq6
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001