shroom-kit

MAL-2026-428

npmmalware1/21/2026
Description

Malicious code in shroom-kit (npm)

Indicators of Compromise
SHA256 Hashes (2)
df93160efafaee42f3f1c238618282cd6845e4fea4f6b0804f5e759934e60f71
12ce31b267373b04b6db8fa70688917b146c9cf34f2d548b58890a950af4f32a
Details
Ecosystemnpm
Attack Typemalware
Published1/21/2026
Affected Versions
0
Aliases
GHSA-rhcw-7jjc-v2rq
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001