JFrog Security Real Time Posts
Last Updated On 14 Jul, 2026

AsyncAPI npm packages previously compromised during Shai-Hulud: The Second Coming were hijacked again, this time to deliver Miasma v3. The malicious releases use valid npm provenance, execute when loaded, and install a persistent cross-platform backdoor.

We deobfuscated a massive campaign of 148 npm packages, including charlie-kirk and ilovefemboys. Disguised as student web proxies, these packages hid mutable remote code execution vectors and a high-performance Wisp-compatible WebSocket traffic generator used to conscript visitors into DDoS botnets.

Attackers compromised the official Injective TypeScript SDK release line and shipped a runtime wallet-key stealer disguised as key-derivation telemetry.

Only a month after we exposed the IronWorm infostealer, an evolved variant has surfaced in compromised versions of the popular jscrambler npm package. The malware has shed its Linux-only skin, deploying a three-platform CSI container to target macOS and Windows, expanding its persistence, and automating its own propagation via direct registry PUT operations.

JFrog Security Research identified malicious npm packages masquerading as Rollup polyfill tooling and leading to a multi-stage JavaScript payload.

JFrog Security Research identified a new Shai-Hulud/Hades npm wave affecting 20 packages in the Leo/RStreams ecosystem.

DirtyClone (CVE-2026-43503) is a CVSS 8.8 Linux kernel LPE discovered independently by JFrog Security Research and Hyunwoo Kim. Patch to Linux v7.1-rc5 or apply the full 4-CVE fix chain.

JFrog Security Research identified two hijacked npm packages, `html-to-gutenberg` and `fetch-pacage-assets`, that used a hidden VS Code task to launch a multi-stage malware chain. The payloads used blockchain transaction data as dead drops, installed JavaScript and Python runtime components, and deployed a backdoor and infostealer targeting credentials, browsers, wallets, developer tools, and environment secrets.

JFrog Security Research analyzed a suspicious npm package named postcss-minify-selector-parser. The package impersonates the popular PostCSS selector-parser ecosystem and hides a multi-stage payload that downloads a Windows Python/Nuitka RAT.

A supply chain campaign targeting Mastra npm packages added the malicious `easy-day-js` dependency, causing installs to execute a staged Node.js backdoor with persistence, reconnaissance, C2 polling, and remote code execution.