• Sources: primary, analysis, discussion
  • Summary: JFrog reports the August variant commits five hook files that execute when a folder is opened in VS Code or a Claude session starts. It injects a codeql_analysis.yml workflow that serializes the Actions secrets context into a downloadable artifact and then deletes its own run, and it reads credentials from Runner.Worker process memory. Command and control addresses resolve from an Ethereum mainnet contract, with GitHub commit-message markers as fallback, and one code path is special-cased to /opensearch-js release automation. JFrog notes npm 12 and newer do not run preinstall hooks by default. The affected package list and version ranges are still expanding.
  • Why it matters: Removing the package is not remediation, because the worm commits hook files to writable branches, so opening the repository in VS Code or starting a Claude session re-executes the payload.

send feedback on this story