people · May 21, 2026
JFrog Security Research Details Shai Hulud Worm Campaign on npm and PyPI
Share the canonical public link.
JFrog Security Research published analysis of the Shai Hulud campaign on May 12, 2026. The campaign compromised over 170 npm packages and 2 PyPI packages with more than 200 million weekly downloads. It spread via GitHub release environment compromise and worm-like tarball modification. JFrog Curation flagged all malicious packages in under 24 hours protecting users with Immaturity policy.
Below validation threshold — auto-passed without scoring