JFrog Security Research

RSS: https://research.jfrog.com/rss.xml
JFrog 安全研究团队发现的最新安全问题与漏洞!CVE、恶意软件包等。

Shai-Hulud Trinitite:新变种攻击周下载15万+的npm包

JFrog安全团队发现Shai-Hulud家族新变种Trinitite,攻击npm包@7nohe/openapi-react-query-codegen,该包周下载量超15万。攻击者通过PR评论触发发布工作流,20分钟内发布10个版本,植入worm窃取GitHub/npm/PyPI等凭证。 与8月底TeamPCP成员在澳大利亚被捕时间吻合,可能是同一团伙或新成员使用相同工具。
评论点赞收藏32 天前

crates.io 三个热门 Rust crate 被入侵,编译时静默执行恶意代码

JFrog发现上3个热门Rust crate被入侵,累计下载量近2.6亿次。arrayref、internment、append-only-vec的新版本悄悄依赖了伪造的proc-macro1(仿冒proc-macro2),利用在编译时下载并执行平台特定恶意负载。 恶意版本已从移除,但攻击窗口期内的构建可能已执行payload。建议检查Cargo.lock,回退到干净版本,扫描受影响主机。
评论点赞收藏42 天前

Shai Hulud campaign strikes NPM again

The JFrog security research team identified a new version of the Shai-Hulud supply-chain malware affecting 400+ packages across 1700+ versions. The compromise started with the `keyv` and `cacheable` n...
评论点赞收藏57 天前

SQLite"关键漏洞"CVE实为AI幻觉产物,JFrog逐一证伪

JFrog安全研究员验证了一批声称存在于SQLite中的高危CVE,发现全部为AI生成的虚假漏洞。引用的函数在目标版本中根本不存在,PoC无法复现,源码审计显示漏洞机制纯属捏造。 CVE提交流程缺乏身份验证,NVD深度审核机制2024年2月暂停后,虚假漏洞可轻易流入企业扫描器。
评论点赞收藏59 天前

Miasma Worm Returns to npm

/img/RealTimePostImage/post/miasma-worm-returns-to-npm/banner.png Four AsyncAPI npm packages previously hijacked in the Shai-Hulud: The Second Coming campaign were compromised again: @asyncapi/generat...
评论点赞收藏79 天前

IronWorm Returns as jscrambler, Rustier Than Ever

Only a month after we exposed the IronWorm infostealer, an evolved variant has surfaced in compromised versions of the popular jscrambler npm package, resembling similar behavior to Shai-Hulud; like t...
评论点赞收藏81 天前

DirtyClone (CVE-2026-43503): Linux Kernel LPE

DirtyClone at a glance What is it? DirtyClone is a high-severity local privilege escalation flaw in the Linux kernel (CVE-2026-43503, CVSS 8.8). It lets any unprivileged local user gain root access by...
评论点赞收藏98 天前

From PostCSS Masquerading to Windows RAT

/img/RealTimePostImage/post/postcss-typosquat-windows-rat.png The package name is not random. The legitimate postcss-selector-parser package is widely used across the JavaScript build ecosystem, with ...
评论点赞收藏101 天前

登录芦苇

登录后关注作者、收藏内容和参与讨论。