Jscrambler npm Package Compromised in Supply Chain Attack
ID: 1b251667-96e5-574e-8132-5faadc87fcdb
STIX ID: report--1b251667-96e5-574e-8132-5faadc87fcdb
Feed Name: ThreatCluster
On July 11, 2026, five malicious jscrambler npm package versions were published using a compromised npm credential; they contained a preinstall hook that deployed a Rust-based infostealer targeting cloud credentials, CI tokens, and browser sessions. The attacker later modified packages to embed the payload directly to evade detection; jscrambler deprecated the malicious versions, rotated credentials, and published a clean release (8.22.0) while the investigation continues. Approximately 15,800 weekly downloads raise concern about potential exposure to users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
