JFrog Security Real Time Posts
Last Updated On 30 Aug, 2026

JFrog Security Research analyzed a new Mini Shai-Hulud wave on @7nohe/openapi-react-query-codegen. Ten npm versions drop a Trinitite-labeled worm through preinstall and an obfuscated binding.gyp command.

On August 20th, the popular Rust crates arrayref, internment, and append-only-vec were compromised on crates.io. The malicious versions silently pulled in proc-macro1, a typosquat of proc-macro2, whose build.rs downloads and executes a remote payload on cargo build.

The JFrog security research team identified a new version of the Shai-Hulud supply-chain malware spreading through compromised npm packages, starting with keyv and cacheable. The worm harvests credentials, publishes itself to every writable npm package, and plants execution hooks in GitHub repositories. If you installed a compromised version, assume your environment is affected.

The JFrog security research team recently identified a supply chain attack targeting the `xinference` package on PyPI. Versions 2.6.0, 2.6.1, and 2.6.2 were compromised and yanked by maintainers after users reported suspicious behavior. If you installed or imported these versions, you must assume your environment is compromised.

AsyncAPI npm packages previously compromised during Shai-Hulud: The Second Coming were hijacked again, this time to deliver Miasma v3. The malicious releases use valid npm provenance, execute when loaded, and install a persistent cross-platform backdoor.

We deobfuscated a massive campaign of 148 npm packages, including charlie-kirk and ilovefemboys. Disguised as student web proxies, these packages hid mutable remote code execution vectors and a high-performance Wisp-compatible WebSocket traffic generator used to conscript visitors into DDoS botnets.

Only a month after we exposed the IronWorm infostealer, an evolved variant has surfaced in compromised versions of the popular jscrambler npm package. The malware has shed its Linux-only skin, deploying a three-platform CSI container to target macOS and Windows, expanding its persistence, and automating its own propagation via direct registry PUT operations.

Attackers compromised the official Injective TypeScript SDK release line and shipped a runtime wallet-key stealer disguised as key-derivation telemetry.

JFrog Security Research identified malicious npm packages masquerading as Rollup polyfill tooling and leading to a multi-stage JavaScript payload.

JFrog Security Research identified a new Shai-Hulud/Hades npm wave affecting 20 packages in the Leo/RStreams ecosystem.