local-mcp

MAL-2026-4601

npmmalware5/20/2026
Description

Malicious code in local-mcp (npm)

Indicators of Compromise
SHA256 Hashes (24)
0d270e7bca623f361b45598f9c9ac210409ee2460ce89e9b0d58cb54f7966389
eae7d3f7204b548521c31041765e21a943c6d86a41dd0c81a5879adafe6fa9df
f19b9aea05a8e8e76d8059bdfbd10db3dc928899ee587127a7b6a30ae176550e
19720486e8e8b8446772a14fcc74015b1d1cec3b905c2986f717bf421456719a
46a78d4864ea2d47b4aef53ee9d8cbacb7739a5dfb71bbd37add2ccb5f80a5e0
64532d8dc97d420332500887dc9a5e0c02b62567e7d281966d639624f0fbbb43
aa31cf61a1882525f095989af831377fd28b27b67219a1fd954c1f1c05cd705e
ac0d1f2f5410f7fdba5d8f16107463f4ea481380ed7e0fdf6a32e9dce2d93cd3
c97072bb416e1bb7b86a2500f96a0c5a44e432110c81d0613e160219e2eeefaa
ff277ff7b93c32122a7e27425f8085412dcf1552e0284f2b0818b3823b08eb04
Details
Ecosystemnpm
Attack Typemalware
Published5/20/2026
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001