Jscrambler npm Package Compromised in Supply Chain Attack (Campaign)
ID: e6242ee5-0d7a-5409-993e-ad507f72bd04
STIX ID: report--e6242ee5-0d7a-5409-993e-ad507f72bd04
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2026-07-11
Date Updated: 2026-07-19
Author: [email protected] (Wiz Threat Research)
A malicious version of the Jscrambler npm package ([email protected]) was published on 11 July 2026 and delivered a dropper via an npm preinstall hook that extracted platform‑specific native binaries; later releases (8.18.0 and 8.20.0) removed lifecycle hooks and executed the same payload on import or CLI use to evade defenses. The native payload is a cross‑platform infostealer targeting developer workstations and CI/CD, collecting browser credentials, cloud (AWS/Azure/GCP) credentials, crypto wallets, AI development configs, Steam data and more, compressing and encrypting stolen data for exfiltration, and analysis observed network traffic to Tor infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
