socket-dev · Crawled Jul 11, 2026

jscrambler npm Package Compromised in Supply Chain Attack

2 IoCs
Read original article ↗

AI Summary

The jscrambler npm package was compromised in a supply chain attack via the release of version 8.14.0 on July 11, 2026. This malicious version introduced an undocumented preinstall hook that executes dist/setup.js, which in turn runs hidden native binaries for Windows, macOS, and Linux. These binaries are embedded in an obfuscated CSI container and are automatically executed during installation, posing a risk to developer environments, CI systems, and build pipelines without requiring any explicit use of the package.

AI-extracted · verify before operational use

Indicators of Compromise 2 extracted

Type Value Detail
Filename dist/setup.js Details →
Filename dist/intro.js Details →