JFrog Security Real Time Posts
Last Updated On 4 Aug, 2026

The JFrog security research team identified a new version of the Shai-Hulud supply-chain malware spreading through compromised npm packages, starting with keyv and cacheable. The worm harvests credentials, publishes itself to every writable npm package, and plants execution hooks in GitHub repositories. If you installed a compromised version, assume your environment is affected.

The JFrog security research team recently identified a supply chain attack targeting the `xinference` package on PyPI. Versions 2.6.0, 2.6.1, and 2.6.2 were compromised and yanked by maintainers after users reported suspicious behavior. If you installed or imported these versions, you must assume your environment is compromised.

AsyncAPI npm packages previously compromised during Shai-Hulud: The Second Coming were hijacked again, this time to deliver Miasma v3. The malicious releases use valid npm provenance, execute when loaded, and install a persistent cross-platform backdoor.

We deobfuscated a massive campaign of 148 npm packages, including charlie-kirk and ilovefemboys. Disguised as student web proxies, these packages hid mutable remote code execution vectors and a high-performance Wisp-compatible WebSocket traffic generator used to conscript visitors into DDoS botnets.

Only a month after we exposed the IronWorm infostealer, an evolved variant has surfaced in compromised versions of the popular jscrambler npm package. The malware has shed its Linux-only skin, deploying a three-platform CSI container to target macOS and Windows, expanding its persistence, and automating its own propagation via direct registry PUT operations.

Attackers compromised the official Injective TypeScript SDK release line and shipped a runtime wallet-key stealer disguised as key-derivation telemetry.

JFrog Security Research identified malicious npm packages masquerading as Rollup polyfill tooling and leading to a multi-stage JavaScript payload.

JFrog Security Research identified a new Shai-Hulud/Hades npm wave affecting 20 packages in the Leo/RStreams ecosystem.

DirtyClone (CVE-2026-43503) is a CVSS 8.8 Linux kernel LPE discovered independently by JFrog Security Research and Hyunwoo Kim. Patch to Linux v7.1-rc5 or apply the full 4-CVE fix chain.

JFrog Security Research identified two hijacked npm packages, `html-to-gutenberg` and `fetch-pacage-assets`, that used a hidden VS Code task to launch a multi-stage malware chain. The payloads used blockchain transaction data as dead drops, installed JavaScript and Python runtime components, and deployed a backdoor and infostealer targeting credentials, browsers, wallets, developer tools, and environment secrets.