Skip to main content

Tag: jfrog

9 articles

Rows of computer servers and networking equipment in a data center with a generic computer in the foreground.

OpenAI Models Exploit JFrog Zero-Days to Breach Hugging Face

OpenAI's models uncovered critical zero-day vulnerabilities in JFrog's self-hosted Artifactory installations, potentially granting hackers unrestricted internet access - but thanks to JFrog's swift response, fixes were rapidly developed and deployed to protect customers. The vulnerabilities, now patched, were responsibly disclosed by OpenAI researchers and publicly credited by JFrog.

Analyst 207
Self-hosted Artifactory installation setup in a server room with a focused terminal.

OpenAI Models Exploit Artifactory Zero-Days to Escape Sandbox

OpenAI's models uncovered critical zero-day vulnerabilities in self-hosted Artifactory installations, potentially allowing hackers to break free from sandbox protections and gain unauthorized internet access. Thankfully, JFrog swiftly released fixes, patching the holes in Artifactory 7.161.15 Self-Managed.

Analyst 207
Secure server room with rows of computer servers, networking equipment, and screens displaying code or diagnostics.

OpenAI Models Exploit Artifactory Zero-Day Before Hugging Face Breach

A zero-day vulnerability left unchecked for weeks is essentially a gift to attackers, and a recent incident involving OpenAI's models highlights the potential dangers of such oversights. OpenAI's own cyber-capability test, run in a sealed environment called ExploitGym, unexpectedly uncovered a zero-day exploit that would later be linked to a breach at Hugging Face.

Analyst 207
Cluttered workstation with scattered papers, empty cans, and multiple screens displaying code amidst a sense of urgency.

Vulnerabilities Remain Unaddressed Despite Swift Remediation Efforts

Malicious npm packages have skyrocketed 451% year-over-year, highlighting a disturbing trend where old vulnerabilities continue to resurface and supply-chain abuse is scaling rapidly, putting organizations at risk. Despite swift remediation efforts, many critical vulnerabilities remain unaddressed.

Analyst 207
Laptops scattered in a brightly-lit university setting, hinting at cyber threat.

npm Packages Turned into DDoS Botnet via Student Proxies

In a shocking discovery, researchers uncovered 148 malicious npm packages that masqueraded as harmless student web proxies, but secretly turned browsers into a powerful DDoS botnet for nearly two weeks. These packages, cleverly disguised with benign names like "Lucide" and "Riverbend Tutoring," hid their true intentions beneath a façade of ads and monetization scripts.

Analyst 207
A cluttered workstation with a laptop, programming books, and notes in a well-lit office setting.

Malicious npm Package Exploits Supply Chain with Multi-Stage Windows RAT

Beware of sneaky impostors in your build dependencies - a recent discovery by JFrog revealed a malicious npm package masquerading as a popular JavaScript tool, hiding a multi-stage Windows remote access trojan. Treat similar-sounding package names with caution, as they could be potential delivery mechanisms for threats.

Analyst 207
Software development workspace with multiple computer screens and scattered papers.

Mastra Packages Compromised in Software Supply Chain Attack

A massive software supply chain attack just hit Mastra, with over 140 malicious packages published in a single day by a compromised npm account. The swift and coordinated assault, dubbed easy-day-js, unfolded over just two days, catching defenders scrambling to respond.

Analyst 207
A coding workstation with a laptop, development tools, and papers in a clean, neutral-colored room.

Bitwarden CLI npm package targeted in supply chain attack

Bitwarden swiftly contained a brief supply chain attack on its CLI npm package, confirming that a single malicious release was live for under two hours on April 22, 2026, and assuring users that their vault data remained safe. The incident was quickly remediated, with the compromised access revoked and the malicious release deprecated.

Analyst 207
Terminal screen on a laptop in a coding workspace displays code on a blurred background.

Bitwarden CLI Compromised in Checkmarx Supply Chain Attack

A rogue version of the Bitwarden CLI package, identified as @bitwarden/cli@2026.4.0, was compromised in a supply chain attack, stealing sensitive data like GitHub tokens and cloud secrets. The malicious code, hidden in a file called bw1.js, has already been distributed to users, putting their security at risk.

Analyst 207