JFrog Security Real Time Posts
Last Updated On 21 Sep, 2026

The JFrog Security Team has identified a malicious npm package named eslint-verify-plugin that deploys a sophisticated multi-stage infection chain, ultimately delivering a full-featured Mythic/Apfell macOS RAT capable of credential theft, screen capture, and backdoor account creation.

The JFrog security research team recently uncovered a sophisticated malicious package called "duer-js" published on NPM by the user "luizaearlyx". After complex analysis, the package was identified as an advanced windows targeted information stealer, self-named as “bada stealer”. The package remains active as of this publication.

The JFrog Security Research team is tracking a newly disclosed OpenSSL vulnerability, CVE-2025-15467, a stack overflow issue that may lead to remote code execution (RCE).

Our research team discovered and disclosed two vulnerabilities in n8n’s sandbox mechanism leading to remote code execution.

Critical CVSS 10 vulnerabilities CVE-2025-55182 and CVE-2025-66478 lead to remote code execution in React-based web applications.

Shai-Hulud remediation guide

Shai-Hulud ongoing attack resurfaced for a second wave, compromising more than 630 packages so far

The JFrog Security Team has identified a two-component cryptocurrency stealer in the NPM repository, cleverly disguised as a benign-looking package to avoid detection.

Our team found and reported crypto packages that delivered known malware via a dependency, with a total of nearly 2K downloads

Our team found a malicious cluster of about 80,000 self-replicating malware packages in the NPM registry. This report details the capabilities of the campaign and motivation behind it.