roots-cms-client

MAL-2026-617

npmmalware1/31/2026
Description

Malicious code in roots-cms-client (npm)

Indicators of Compromise
SHA256 Hashes (3)
5290f63f945a36e1d28eaf7c6340896e82a974ec0971f8bee7a52dfda4fc3e68
9670a58bdf8573b9c7d94a74cf58593a55692bfcf33d931693680389b981f89c
88007d193d64ac8d7a2a970903353601b1f620a48f22c3cd3c7a838da0cce4e8
Details
Ecosystemnpm
Attack Typemalware
Published1/31/2026
Affected Versions
0
Aliases
GHSA-q57g-x3rh-xj4x
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001