tiny-model-update

MAL-2026-47

npmmalware12/22/2025
Description

Malicious code in tiny-model-update (npm)

Indicators of Compromise
SHA256 Hashes (6)
379adea31357db0c18b9dc0dac285a37eacd85a53ed958a310390351fa4caee2
2a69a5156f95b3b1ddd3a9c0ddd7e1fad0cdd92841e56dc6ea7b950a35a5eb34
b1c28ed6f53f3d5067c4e740d301ffefce73576bbaf2fe80ef0ee62b1b83aa34
040503a1495cd432de771855e636ade300a3ccc0813155aa4cc6df6a380c74d4
33db2f7a1ca69c062e135329323ceca033220f65a1e27ee5c312f73d60f5739e
6ce90a84bc9edd848e15e9d3249750a234abae0c914cecdb82618d9b8ed3691e
Details
Ecosystemnpm
Attack Typemalware
Published12/22/2025
Affected Versions
0
Aliases
GHSA-7m8x-5j4f-qj6p
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001