@depro0x/despicable-me

MAL-2026-873

npmmalware2/12/2026
Description

Malicious code in @depro0x/despicable-me (npm)

Indicators of Compromise
SHA256 Hashes (8)
6462180066b4c25e184d616993e44ba94d6e6fdf065db3e0e6ce52a1015a0aa0
408ee2d3c535747e02e11f32f8a20bafa12ddc1ac413c41dc80ed7375e926b02
e5e59fdbcd5eae4cddc95424e34ba5de09ae15fd2d265fcf832a68c4c4495a4a
4615e7677b737a414d7c43332b795fe84cb5d272e491befba14d42456ae28cfc
9d4f645b4e971818c96437326820425423bc5c41700995b66b0a6d96d110f145
cfd0bd7743a9548666d2cb6e0bbe7392bde2f52356f29403ba18b846c2f6c8d0
3fc28a0966ecc924884cf1cd6a75caf42b173878d6934a7f4774e294fba62ccd
0e512041534d296b22312d733434bb54944a4e026f6ddeaa493240cccc429ee9
Details
Ecosystemnpm
Attack Typemalware
Published2/12/2026
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001