Skip to content
The Nexus
DossierENTITY

JFrog

Coverage of JFrog in the Nexus archive.

Earliest in view: Jun 5 · 18:05 UTCMost recent: Jul 14 · 07:08 UTC
Co-mentioned in this coverage
Recent coverage
  • SECURITYJul 14 · 07:08 UTCTHE HACKER NEWS
    148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet

    148 npm packages disguised as student web proxies were used to turn browsers into a DDoS botnet for two weeks in May, according to JFrog's research. The packages served as a booby-trapped proxy site hosted via the npm registry, targeting students rather than developers.

  • SECURITYJul 3 · 16:07 UTCTHE HACKER NEWS
    North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets

    Threat actors linked to North Korea have created malicious npm packages named 'rollup-packages-polyfill-core' and 'rollup-runtime-polyfill-core' that mimic the legitimate 'rollup-plugin-polyfill-node' project to steal developer secrets. JFrog identified these packages as part of a scheme to facilitate remote access and data theft.

  • SECURITYJun 29 · 05:36 UTCTHE HACKER NEWS
    Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer

    Cybersecurity researchers discovered hijacked npm and Go packages that deploy a Python-based information stealer using VS Code tasks on Windows, Linux, and macOS systems. The attack bypasses common npm execution paths to avoid detection by security measures like those in npm v12.

  • SECURITYJun 17 · 07:38 UTCTHE HACKER NEWS
    144 Mastra npm Packages Compromised via Hijacked Contributor Account

    144 npm packages under the Mastra namespace (@mastra/*) were compromised in a supply chain attack named easy-day-js. A single npm account (ehindero) was used to mass-publish malicious packages, according to findings from JFrog, SafeDep, Socket, and StepSecurity.

  • TECHNOLOGYJun 12 · 23:07 UTCTHE REGISTER
    NanoClaw now armed with JFrog for safer packages

    NanoClaw, a secure agent framework, has partnered with JFrog to enable AI agents to fetch resources from JFrog's vetted registries, enhancing package security. The collaboration addresses risks of untrusted npm packages and introduces an 'agent factory' system to automate pull request triaging using NanoClaw agents.

  • SECURITYJun 5 · 18:05 UTCTHE HACKER NEWS
    IronWorm and New Miasma Worm Variant Hit npm in Supply Chain Attacks

    Multiple supply chain attacks targeted the npm ecosystem using malicious and poisoned versions of over 50 legitimate packages to distribute a Rust-based information stealer and a self-spreading worm. JFrog identified the information stealer as hiding behind an eBPF kernel rootkit to scrape secrets from developers' machines.