Mumbai, you brought the energy! ðž
#EveryOpsDay 2026 was every bit the room we'd hoped for: Technology leaders India's largest enterprises, in one room, talking candidly about where software delivery is headed.
The conversations weren't about pipelines. They were about trust, #AI-generated code, the software supply chain, and what it takes to move fast without becoming the next #CVE headline.
A few things that stuck with us:
â The way enterprises ship #software in 2026 doesn't look like it did in 2024.
â #DevSecOps and AI aren't two conversations anymore. They're one.
â The hardest problems sit at the seams: security, speed, compliance, scale. The teams winning are the ones engineering them away.
To every leader, partner, and speaker who showed up, Thank You! This is what #EveryOps looks like in practice.
#SoftwareSupplyChain #JFroglife
"Shai-Hulud: Here We Go Again" update - the 2nd stage PyPI payload has changed in the last hours from a benign payload to a credential stealer with possible destructive behavior!
ðšSECURITY ALERT: Ongoing supply chain attack - âShai-Hulud: Here We Go Againâ
We are continuing to track the latest attack in the âShai-Hulud: Here We Go Againâ campaign - Up until now 406 package versions were detected as compromised, including npm scopes @tanstack, @squawk, @uipath, and spreading to PyPI packages mistralai and guardrails-ai. JFrog Curation customers using an Immaturity policy were fully protected from this attack, as all of the hijacked packages were flagged in less than 24 hours.
See our blog for a full analysis of this attack, including an ongoing list of compromised packages (link shared soon in this thread).
ðšSecurity Alert: Supply Chain Attack on SAP-Related npm Packages:
A targeted supply chain attack, "Mini Shai-Hulud," has been identified affecting several popular npm packages within the SAP developer ecosystem:
@cap-js/postgres 2.2.2
@cap-js/sqlite 2.2.2
@cap-js/db-service 2.10.1
mbt 1.2.48