Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 21, 2026 (about 3 months ago).

people · May 21, 2026

JFrog Security Research Details Shai Hulud Worm Campaign on npm and PyPI

Share the canonical public link.

Share as image

JFrog Security Research published analysis of the Shai Hulud campaign on May 12, 2026. The campaign compromised over 170 npm packages and 2 PyPI packages with more than 200 million weekly downloads. It spread via GitHub release environment compromise and worm-like tarball modification. JFrog Curation flagged all malicious packages in under 24 hours protecting users with Immaturity policy.

Below validation threshold — auto-passed without scoring

Supporting evidence