react-dropzone-truffle

MAL-2026-999

npmmalware2/23/2026
Description

Malicious code in react-dropzone-truffle (npm)

Indicators of Compromise
SHA256 Hashes (3)
f8fb0b7b6f07c6700ee7e81dec0edaa413cd2d7bce2283cb5a1a7cbfdf6eb051
deb9aafcb06b44346b4a153006bf1230d02f97d4f76ac2797f42a22005658c85
16cb75c339f5d6793d32bcbc47e29ef29d2f663d1f94388ac489cf88ebc8b638
Details
Ecosystemnpm
Attack Typemalware
Published2/23/2026
Affected Versions
0
Aliases
GHSA-h362-pxfp-fmhj
Agentic AI · Pentesting

Ready for Agentic Automated Testing?

Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.

Zero false positives
PoC for every finding
30+ tools orchestrated
Setup in 5 minutesSOC 2 & ISO 27001