The jscrambler npm compromise on July 11, 2026, delivered a sophisticated Rust-based infostealer to developer machines through a compromised publisher account. Five malicious versions were pushed to npm over three hours, each carrying a cross-platform payload that targets cloud credentials, cryptocurrency wallets, browser sessions, and AI coding tool configurations.
What Happened
Socket flagged version 8.14.0 as malicious just six minutes after it appeared on npm. The compromised release added two files not present in the prior version: setup.js, a small loader script, and intro.js, a roughly 7.8 MB container packing gzip-compressed native binaries for Linux, Windows, and macOS.
During installation, a preinstall hook triggers setup.js, which selects the binary for the host operating system, writes it under a random name in the system temp directory, marks it executable, and launches it detached with output hidden. None of these files exist in jscrambler's public GitHub repository, where the latest tag remains 8.13.0. The version was pushed directly to npm through a compromised maintainer account, either a stolen npm publishing credential or a compromised build pipeline.
Technical Analysis
The Rust Infostealer
The payload is a cross-platform Rust infostealer targeting developer environments:
- Cloud credentials -- AWS, Azure, and Google Cloud API keys and secrets, including metadata endpoints used by CI runners
- Cryptocurrency wallets -- seed phrases and wallet files from MetaMask, Phantom, and Exodus
- Password managers -- Bitwarden vault contents
- Browser data -- saved passwords and session cookies
- Communication sessions -- Discord, Slack, Telegram, and Steam authentication tokens
- AI coding tools -- configuration files for Claude Desktop, Cursor, Windsurf, VS Code, and Zed, where API keys and MCP server credentials are stored
Advanced Capabilities
On Linux, the binary links the kernel's BPF library and can load an eBPF program into kernel memory from userspace, establishing a kernel-level foothold invisible to standard file-based detection. The Windows build includes anti-debugging checks. Both the Windows and macOS versions install persistence mechanisms: a hidden scheduled task on Windows that relaunches every minute, and a macOS LaunchAgent that reloads on login.
Command-and-control traffic routes through two hard-coded IP addresses and Tor infrastructure, according to StepSecurity's runtime monitoring.
Evolving Delivery Methods
The attacker published five malicious versions: 8.14.0, 8.16.0, 8.17.0, 8.18.0, and 8.20.0. The delivery method changed over time:
| Version | Delivery Method | Mitigation |
|---|---|---|
| 8.14.0 | Preinstall hook (setup.js) | --ignore-scripts blocks it |
| 8.16.0 | Preinstall hook | --ignore-scripts blocks it |
| 8.17.0 | Preinstall hook | --ignore-scripts blocks it |
| 8.18.0 | Main code / CLI entry point | --ignore-scripts does NOT block it |
| 8.20.0 | Main code / CLI entry point | --ignore-scripts does NOT block it |
Versions 8.18.0 and 8.20.0 moved the dropper into the package's main code, meaning it fires when the package is imported or run. This bypasses npm's --ignore-scripts flag entirely and represents a significant escalation in the attack methodology.
Company Response
Jscrambler confirmed the cause was a compromised npm publishing credential. The company revoked and rotated its publishing credentials and secrets, hardened its publishing pipeline, and deprecated all malicious releases. However, deprecation still leaves them installable by pinned version. Version 8.22.0 is the current clean release.
Version 8.15.0, published between the first two malicious releases, appears clean on both Socket's and Jscrambler's lists.
Why This Matters to Developers
jscrambler is a build-time tool installed as a development dependency or run from CI pipelines. Those environments hold the most sensitive credentials an organization has: cloud deployment keys, npm publishing tokens, GitHub access tokens, and source code. The package sees roughly 15,800 weekly downloads -- smaller than the packages hit in major npm supply chain attacks, but the targeting is precise and the access value is high.
The timing is particularly notable. npm 12 shipped on July 8, 2026, with dependency install scripts disabled by default. On npm 12, a preinstall hook like the one in early malicious versions requires explicit user approval. However, older npm clients still run them automatically, and the later variant embedding the payload in main code bypasses the protection entirely.
What Security Teams Should Do
Immediate remediation:
- Upgrade to [email protected] or pin to 8.13.0
- Audit all lockfiles and package-manager logs for jscrambler 8.14.0 through 8.20.0
- Check CI/CD records for execution of
dist/setup.jsor unexpected child processes fromnpm installon July 11 or later - Inspect Windows Task Scheduler for hidden tasks and macOS
~/Library/LaunchAgentsfor unfamiliar plist files
Credential rotation (if any affected version ran):
- Rotate all cloud provider API keys (AWS, Azure, GCP)
- Regenerate npm tokens and GitHub personal access tokens
- Revoke Discord, Slack, browser, and Bitwarden sessions
- Rotate AI tool and MCP API keys
- Transfer cryptocurrency from wallets on compromised hosts
Frequently Asked Questions
Were the malicious versions removed from npm? No. They remain on npm with deprecated tags, meaning any lockfile or command pinned to an affected version continues to install the compromised package.
How can I detect if the malware ran on my machine?
The payload writes to the system temp directory under a random dotted name (.{random} or .{random}.exe on Windows). Check for unexpected temp-directory file executions and child processes spawned by npm install around July 11. On Windows, check Task Scheduler for hidden tasks. On macOS, inspect LaunchAgents for unfamiliar entries.
Does npm 12 protect against this attack? Partially. npm 12 disables install scripts by default, blocking the preinstall hook variant. However, versions 8.18.0 and 8.20.0 moved the payload into the main package code, so importing or running the package triggers the malware regardless of npm version.
Were jscrambler plugins affected? No. The plugins for webpack, gulp, Metro, and grunt were not compromised and remain on their clean June releases.
Does jscrambler confirm this was a credential compromise? Yes. Jscrambler confirmed the malicious packages were published using a compromised npm publishing credential and stated the intrusion was limited to the jscrambler Code Integrity package.
Key Takeaways
- Five malicious versions of jscrambler (8.14.0 through 8.20.0) were pushed to npm through a compromised publisher account
- The Rust infostealer targets cloud credentials, crypto wallets, browser data, and AI tool configurations
- Later variants bypass
--ignore-scriptsby embedding the payload in the main package code - Upgrade to 8.22.0 immediately and audit all systems that may have installed an affected version
- Treat any machine where a malicious version ran as fully compromised and rotate all accessible credentials
Automated Transmission
This entry was synthesized and populated dynamically using native API integrations.