JFrog
Coverage of JFrog in the Nexus archive.
- 148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet
148 npm packages disguised as student web proxies were used to turn browsers into a DDoS botnet for two weeks in May, according to JFrog's research. The packages served as a booby-trapped proxy site hosted via the npm registry, targeting students rather than developers.
- North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
Threat actors linked to North Korea have created malicious npm packages named 'rollup-packages-polyfill-core' and 'rollup-runtime-polyfill-core' that mimic the legitimate 'rollup-plugin-polyfill-node' project to steal developer secrets. JFrog identified these packages as part of a scheme to facilitate remote access and data theft.
- Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer
Cybersecurity researchers discovered hijacked npm and Go packages that deploy a Python-based information stealer using VS Code tasks on Windows, Linux, and macOS systems. The attack bypasses common npm execution paths to avoid detection by security measures like those in npm v12.
- 144 Mastra npm Packages Compromised via Hijacked Contributor Account
144 npm packages under the Mastra namespace (@mastra/*) were compromised in a supply chain attack named easy-day-js. A single npm account (ehindero) was used to mass-publish malicious packages, according to findings from JFrog, SafeDep, Socket, and StepSecurity.
- NanoClaw now armed with JFrog for safer packages
NanoClaw, a secure agent framework, has partnered with JFrog to enable AI agents to fetch resources from JFrog's vetted registries, enhancing package security. The collaboration addresses risks of untrusted npm packages and introduces an 'agent factory' system to automate pull request triaging using NanoClaw agents.
- IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks
Multiple supply chain attacks targeted the npm ecosystem using malicious and poisoned versions of over 50 legitimate packages to distribute a Rust-based information stealer and a self-spreading worm. JFrog identified the information stealer as hiding behind an eBPF kernel rootkit to scrape secrets from developers' machines.