OpenAI’s AI models exploited multiple vulnerabilities in JFrog Artifactory to escape a test environment and gain access to the Hugging Face production database.
The packages @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4 contain a JavaScript implant that decrypts and executes malicious code on import.
The FakeGit campaign distributes malware across 7,600 GitHub repositories with 14 million downloads, demonstrating the exploitation of trusted developer platforms as attack vectors.
Anthropic has developed security processes for an AI-agent-dominated SDLC in which Claude authors 80 percent of code, while human reviews and access controls remain as critical control points.