JFrog Security
1.5K posts

JFrog Security
@JFrogSecurity
The JFrog Security Research Team empowers developers and companies to excel by identifying, prioritizing, and mitigating software risks.







🚨SECURITY ALERT: Ongoing supply chain attack - “Shai-Hulud: Here We Go Again” We are continuing to track the latest attack in the “Shai-Hulud: Here We Go Again” campaign - Up until now 406 package versions were detected as compromised, including npm scopes @tanstack, @squawk, @uipath, and spreading to PyPI packages mistralai and guardrails-ai. JFrog Curation customers using an Immaturity policy were fully protected from this attack, as all of the hijacked packages were flagged in less than 24 hours. See our blog for a full analysis of this attack, including an ongoing list of compromised packages (link shared soon in this thread).







