- Sources: primary, analysis, discussion
- Summary: JFrog reports the August variant commits five hook files that execute when a folder is opened in VS Code or a Claude session starts. It injects a
codeql_analysis.yml workflow that serializes the Actions secrets context into a downloadable artifact and then deletes its own run, and it reads credentials from Runner.Worker process memory. Command and control addresses resolve from an Ethereum mainnet contract, with GitHub commit-message markers as fallback, and one code path is special-cased to /opensearch-js release automation. JFrog notes npm 12 and newer do not run preinstall hooks by default. The affected package list and version ranges are still expanding. - Why it matters: Removing the package is not remediation, because the worm commits hook files to writable branches, so opening the repository in VS Code or starting a Claude session re-executes the payload.
send feedback on this story