@mcpassure/mcp-anvisa-bulario

MAL-2026-4406

npmmalware5/20/2026
Description

Malicious code in @mcpassure/mcp-anvisa-bulario (npm)

Indicators of Compromise
SHA256 Hashes (10)
2cb99eb86200644b4f108b751a41ac2fa4ac3c2996160eac58da8369d8be80b6
e846cabb7b5077244737d7a465e944ebe7635db46cc55e7e5736eeda47d30938
3be741993dd2133dfb8effe009f0d798f80ea44283059adc964d4c639a4d1b5c
4783477f054bd24b84a903f7b8b66ff56f7752970bb0d362b0c117b03be62fdf
b82c82ddf6a54b51ff773c550650233a2a05888aca35918911c2b277d1436c03
5581b1fa309dcd3b41b45f5fc16c6abe59cfda373116e92fe137fb7bf772c3e5
590355913700543ba116384af4aff83e5aefcadae860c2c3c6a4ba434b1f6872
5f2f6e0a8441ee1e78d37fed1a981e6342ee276e8667b1ff0e1124bc3a0213f9
cde284274517321fc712dc124b72622fc6cd4d1255851e1b9a49b5dbef8d9bbb
e25c90fdc87c17cd388b917a0618ad5feb612becb07d01aa0bda5095b9116f8b
Details
Ecosystemnpm
Attack Typemalware
Published5/20/2026
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001