Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 21, 2026 (about 3 months ago).

people · May 21, 2026

JFrog Security Reports Malicious PyPI Packages in Shai Hulud Campaign

Share the canonical public link.

Share as image

JFrog Security Research identified a new Shai Hulud wave on May 19, 2026 affecting npm and PyPI. Compromised packages include durabletask versions 1.4.1 through 1.4.3 and additional variants like @cap-js/openapi. The payload enables wormability across AWS and Kubernetes environments. JFrog flagged the malicious versions which were subsequently yanked from repositories.

Below validation threshold — auto-passed without scoring

Supporting evidence