people · May 21, 2026
JFrog Security Details Wormable Payload in Shai Hulud PyPI Campaign
Share the canonical public link.
JFrog Security posted details on May 19, 2026 about the Shai Hulud campaign. The payload downloads additional components like managed.pyz and rope.pyz similar to prior transformers.pyz variants. It spreads laterally via SSM on AWS and kubectl exec on Kubernetes. The post received 141 likes and 34 reposts from the JFrog Security account.
Below validation threshold — auto-passed without scoring