envoy1

MAL-2026-871

npmmalware2/12/2026
Description

Malicious code in envoy1 (npm)

Indicators of Compromise
SHA256 Hashes (10)
10936bf606d5dc96a54b1ec67ee68c3426330a5b76de9f1edf791d8511aeff94
534025484f895df012bf58dea9bd0515a8d69d89db8b1a2b09757f358d18f8b6
b2847c44ec69d9e500dd372736c6ef45e0005dfc9dd7eccef8e77b33b590e32c
8fc4a93cab1e4251fee61e045956f17fbb416b228a8c5df9704cff5594edecbe
41d186df40a1546706a1c1be8b8ded4bd925b113674a892e0d0ea4d3fe21138c
f79c0c8be133658ce800aa6a4a1ef749479ec6dfa2ce70bedb051333d8ed181b
29af11c89730199dc1ae49a0282c144d1811b6a20de7b39fd5a726a776ff40f3
a6970274ff6fb5269440d5a9ef77ae654fd5b4257430ec8715414dffbf5dcdeb
877dda74ff1a6579d4bd819a2f752baae0c5f7972ae585756a93dceb01dd57af
f06e472b4bdab1dd15a395732da65c1814588afb9acec484f386061ec9c16b3c
Details
Ecosystemnpm
Attack Typemalware
Published2/12/2026
Affected Versions
0
Aliases
GHSA-f4fg-xj6v-j6r8
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001