@polka-ui/loader

MAL-2026-4420

npmmalware5/25/2026
Description

Malicious code in @polka-ui/loader (npm)

Indicators of Compromise
SHA256 Hashes (2)
599a7dd2ffe3f950a7dcf18279f01e9e4e6e457741b73fff5ace7a283b9c9539
f93cf8dde7e6a1252424fc82f38e8502a37d9e427d92d412fd8944c91b8ee5a4
Details
Ecosystemnpm
Attack Typemalware
Published5/25/2026
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001