The JFrog security research team identified a new version of the Shai-Hulud supply-chain malware affecting 400+ packages across 1700+ versions. The compromise started with the `keyv` and `cacheable` n...
Summary Kimi Code is vulnerable to a FetchURL SSRF Protection Bypass via DNS-resolving Hostnames and Redirects ## Component @moonshot-ai/kimi-code (Kimi Code) ## Affected versions < 0.27.0 ## Descript...
Summary NoteGen is vulnerable to Chat Preview XSS via Unsanitized AI/Skill HTML Rendering ## Component note-gen (NoteGen) ## Affected versions < 0.32.0 ## Description NoteGen before 0.32.0 renders AI ...
The JFrog Security Research team has discovered and disclosed a typosquatted NuGet package named. Note the double t and the.Net suffix. This package has been masquerading as the popular Newtonsoft.Jso...
/img/RealTimePostImage/post/miasma-worm-returns-to-npm/banner.png Four AsyncAPI npm packages previously hijacked in the Shai-Hulud: The Second Coming campaign were compromised again: @asyncapi/generat...
We deobfuscated a massive campaign of 148 npm packages, including ilovefemboys, miguelphonk, and charlie-kirk. Disguised as student web proxies under names like Riverbend Tutoring, these packages hid ...
Only a month after we exposed the IronWorm infostealer, an evolved variant has surfaced in compromised versions of the popular jscrambler npm package, resembling similar behavior to Shai-Hulud; like t...
The JFrog Security Research team analyzed the compromised @injectivelabs/sdk-ts npm package version 1.20.21, an official Injective Labs TypeScript SDK release that briefly shipped a wallet-key stealer...
The JFrog Security research team identified a malicious npm package cluster masquerading as Rollup polyfill tooling. The two entry packages, rollup-packages-polyfill-core and rollup-runtime-polyfill-c...
DirtyClone at a glance What is it? DirtyClone is a high-severity local privilege escalation flaw in the Linux kernel (CVE-2026-43503, CVSS 8.8). It lets any unprivileged local user gain root access by...
JFrog Security Research identified a new Shai-Hulud/Hades npm wave affecting 20 packages in the Leo/RStreams ecosystem. The malicious packages belong to a legitimate package family used for AWS-native...
/img/RealTimePostImage/post/vscode-blockchain-npm/image1.png Update 25/06/2026 - Following our report, Nextron Research identified an additional 16 Go packages containing the same malware. Most appear...
/img/RealTimePostImage/post/postcss-typosquat-windows-rat.png The package name is not random. The legitimate postcss-selector-parser package is widely used across the JavaScript build ecosystem, with ...
Summary FFmpeg is vulnerable to a Heap Out-of-Bounds Write in the MagicYUV Decoder (PixelSmash) ## Component ffmpeg (libavcodec/magicyuv.c) ## Affected versions < 8.1.2 ## Description A heap-based out...
JFrog Security Research analyzed a supply chain campaign that targeted Mastra npm packages by adding a malicious production dependency named easy-day-js. The affected Mastra package code was left larg...
Summary The Reachy Mini Wireless image is vulnerable to a Local Privilege Escalation via an Unrestricted sudo systemctl Grant ## Component reachy-mini-os ## Affected versions < 0.2.4 ## Description Th...
Summary The Reachy Mini daemon is vulnerable to an Unrestricted File Upload in the Media Sounds Upload API ## Component reachy-mini (reachy_mini daemon) ## Affected versions < 1.8.2 ## Description The...