@ikyyofc/gemini-cli

MAL-2026-4394

npmmalware5/20/2026
Description

Malicious code in @ikyyofc/gemini-cli (npm)

Indicators of Compromise
SHA256 Hashes (15)
02dc0713ef228e85a00c9b42387d372926de86995282046d97097ec2c70949a2
eb34383a3b5afed7609c8ffaba4251d3f76d2911dd89b847f99e0982e2ea50d7
fe916093166227f9f446f7a296135ec423d17d0c85a5b0c6790e73c76f8b99ce
4332ef1d823062f94ca9e4c46d6f549050a63909182e5e0275df2d30e14c6a1f
5793a1cde3de83b8c15b49a0f9981d72fbf431067a4416ce6b2bd5650ea4a4d6
65c21755d121ec1e9099c7b27daa4f3f925f43a4c780d513d9db740a68589ef9
9115fec7bc81baed4d91bd288d70fb3ee335022f809e49a1977dd26a9bb7ed3f
ab1f4ebb9b0999f78e07156fee9ddc4a5d5fba62dde9860d53c6ffdca17ae40e
ac6f383bb15ad3695b0076a2eeb174abd4046cc2d8f5f6887a75817432bd8dba
e9f688d1eb6f150c806dffd9d1254a79b840bbaa197a0e4b89433ec800b690f3
Details
Ecosystemnpm
Attack Typemalware
Published5/20/2026
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001