Skip to content

jscrambler 8.14.0 compromised with infostealer in npm preinstall hook

The Point: The malware in jscrambler 8.14.0 is activated by the preinstall hook without explicit import or CLI command — installation alone is sufficient for execution.

The npm version 8.14.0 of the JavaScript obfuscator jscrambler contained an infostealer that was executed automatically during installation. Socket identified the malware minutes after publication.

The npm version 8.14.0 of the jscrambler package, a widely used code obfuscation tool, was distributed with an infostealer on July 11, 2026. The malware was embedded in a preinstall hook and executed automatically during package installation — without requiring developers to import the package or invoke it from the command line.

The infostealer was compiled as a native binary for Windows, macOS, and Linux and was silently written to and executed on the system when the preinstall hook was invoked. These infostealers are designed to extract system data and credentials.

Security firm Socket detected the compromise six minutes after the package was published. This means that a critical supply chain dependency existed for the period between publication and detection, placing all developers who installed version 8.14.0 during this window at risk.

CISOs should verify whether 8.14.0 was used in their development or build environments. The package should be uninstalled immediately and replaced with a known clean version. Additionally, forensic analysis of affected systems is recommended to identify any exfiltration of credentials, SSH keys, or other sensitive data.


Source: thehackernews.com · Published July 11, 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: