🚨 Compromised Rust crate on https://t.co/uizCPE7vvM!
The Packages arrayref (~245M downloads) v0.3.10, append-only-vec v0.1.9, and internment v0.8.7 have been compromised!
They all silently pulled in proc-macro1, a typosquat of proc-macro2. Its https://t.co/3uW8p6zLXL downloads a remote payload and executes it on any machine that runs cargo build - nothing from the crate even needs to be called.
Check your Cargo.lock for the compromised packages or any proc-macro1 entry.
CVSS 10.0, but the evidence doesn't add up.
CVE-2026-51302 in SQLite claims critical impact, but:
❌The supplied PoC does not reproduce
❌The source code does not match the claims
And it's not an isolated case: JFrog found the same issues in 54 of 55 CVEs published by the same GitHub repository in just 4 days, and informed in the proper CVE channels.
⚠️Don't blindly trust newly published CVEs. Validate the advisory, PoC, and source before prioritizing or patching.
🚨 A single typo concealed a targeted betting-fraud Trojan.
JFrog Security Research uncovered https://t.co/NqFCNi3vuA, a NuGet typosquat impersonating the popular Newtonsoft.Json (more than 100M monthly downloads!). Its trojanized fork silently patched Digitain’s crash-game backend to rig results. Later versions exfiltrated manipulated rounds to attacker infrastructure.
The package worked normally outside its intended environment, helping it evade detection. Seven malicious versions were published before it was unlisted.
Affected package: [email protected]–11.0.11
Full analysis: https://t.co/xkgNmCIC8I
⚠️False Positive Alert: OSV advisory MAL-2026-10726 has incorrectly flagged [email protected] (3M weekly downloads) as malicious.
The claims of "typosquatting" are incorrect. These are legitimate dependencies with an established history and normal PR reviews. Astro is 100% safe.
Advisory: https://t.co/FiezFRasEU
🚨 NPM SUPPLY CHAIN ATTACK ALERT 🚨
For the second time, packages in the AsyncAPI ecosystem have been compromised. After being targeted by the massive "Shai-Hulud: The Second Coming" worm attack, @asyncapi/generator (100k weekly downloads) and its sub-packages have been poisoned again.
@asyncapi/generator (3.3.1)
@asyncapi/generator-helpers (1.1.1)
@asyncapi/generator-components (0.7.1)
Check your build pipelines and dependencies immediately! 🛡️
⚠️ Students visiting "Riverbend Tutoring" to bypass school Wi-Fi and play games didn't realize their browsers were being conscripted into a DDoS botnet.
We deobfuscated a massive campaign of 150+ npm packages (under names like charlie-kirk and ilovefemboys) acting as a free CDN for malicious student web proxies.
Our deep-dive recovered active payloads: a mutable remote loader and a custom Wisp-protocol WebSocket generator that attacked a nursing school's website at 2MB/s per visitor.
How the Lucide campaign weaponized student proxies:
https://t.co/RZy3ZQHCBy
🚨 The Miasma worm has returned to npm! Four AsyncAPI packages were recently compromised to deliver the new Miasma v3 variant.
Read our full technical analysis:
https://t.co/hc106t5hTA
🚨 IronWorm returns! Shai-Hulud's rustier cousin has struck again, and it’s more sophisticated than ever. 🐛
An evolved variant of the infostealer has been discovered hiding in compromised versions of the popular jscrambler npm package (15k weekly downloads).
Read the full technical deep dive from the JFrog Security Research team: https://t.co/xCgDXk3wbL
🚨SUPPLY CHAIN ALERT
The official jscrambler npm package (15K weekly downloads) has been hijacked! Version 8.14.0 includes a malicious preinstall script that drops a hidden Rust binary disguised as a .js file on Windows, macOS, and Linux.
The payload is a highly evasive credential and crypto-wallet stealer, featuring advanced anti-analysis tools and kernel-level eBPF instrumentation.
If you installed v8.14.0, consider your system compromised. Immediately rotate all of your credentials!
XRAY-1025905
🚨 Only 3 commands are needed to exploit CVE-2026-53605, a local privilege escalation vulnerability affecting home robots.
JFrog researchers found that versions <0.2.4 of Pollen Robotics' Reachy Mini SDK allow attackers to gain root access in seconds.
Camera. Microphone. Motors.
All attacker-controlled.
Update immediately.
🚨 Multiple recent Axios CVEs aren't as severe as they seem.
JFrog researchers found that some Prototype Pollution gadget vulnerabilities in Axios are scored based on the impact of an already-compromised application, even though exploitation requires a separate Prototype Pollution vulnerability (as you can see in this PoC).
Read our blog (in the first comment) to understand why context matters more than the score.
🚨 Lazarus-linked npm malware is masquerading as widely used Rollup polyfills (~295K weekly downloads)
🔎 The @JFrogSecurity research team has identified a malicious npm package cluster masquerading as Rollup polyfill tooling.
Bypassing standard detection with no obvious install-script triggers, the threat actors wait until import-time to pull a multi-stage payload built for broad file collection, crypto wallet theft, and full interactive remote access.
Read the full breakdown in our analysis: https://t.co/EHStBr34Ci
🚨 Lazarus-linked npm malware is masquerading as widely used Rollup polyfills (~295K weekly downloads)
Bypassing standard detection with no obvious install-script triggers, the threat actors wait until import-time to pull a multi-stage payload built for broad file collection, crypto wallet theft, and full interactive remote access.
Read the full breakdown in our blog post (link in the thread)
🚨 CAMPAIGN UPDATE 🚨
We have detected additional compromised packages and versions associated with the ongoing malicious campaign targeting Backstage plugins.
If you are using @immobiliarelabs plugins within your environment (10K weekly downloads), audit your dependencies immediately. The newly identified compromised packages and versions are:
@ immobiliarelabs/backstage-plugin-gitlab 1.0.1, 2.1.2, 3.0.3, 4.0.2, 5.2.1, 6.13.1, 7.0.2
@ immobiliarelabs/backstage-plugin-gitlab-backend 3.0.3, 4.0.2, 5.2.1, 6.13.1, 7.0.2
@ immobiliarelabs/backstage-plugin-ldap-auth 1.1.4, 2.0.5, 3.0.2, 4.3.2, 5.2.1
@ immobiliarelabs/backstage-plugin-ldap-auth-backend 1.1.3, 2.0.5, 3.0.2, 4.3.2, 5.2.1
Secure your software supply chain by ensuring these specific versions are blocked. More updates to follow as our research continues. 👇
🚨 SECURITY ALERT 🚨
A new supply chain attack has been detected. A Shai Hulud worm variant dubbed "Alright Lets See If This Works" has hijacked 20 LeoPlatform npm packages, including "leo-logger", which impacts over 3.5K weekly downloads.
Audit your dependencies immediately. Full analysis and mitigation details will be live soon on our blog: https://t.co/dDYb74DYyE
🚨 Open a VS Code workspace. Get infected.
JFrog researchers analyzed 2 hijacked npm packages that abuse hidden VS Code "folderOpen" tasks and blockchain dead drops to deploy an infostealer.
The malware steals credentials, browser cookies, crypto wallets, and other sensitive data.
Affected packages:
• [email protected]
• [email protected]
Check your environment and remove them immediately if found.
Full analysis: https://t.co/5P1e5VbWbW
⚠️ Watch out for postcss-minify-selector-parser!
Our latest research uncovers how this malicious npm package masquerades as a popular PostCSS tool (150M weekly downloads) to deploy a Windows RAT.
Learn how it targets Chrome credentials and how you can protect your environment:
https://t.co/nWdjuABwx1