Skip to content

jscrambler 8.14.0 Compromised with Infostealer in npm Preinstall Hook

The key point: The malware in jscrambler 8.14.0 is activated by the preinstall hook without explicit import or CLI command—installation alone is sufficient for execution.

The npm version 8.14.0 of the JavaScript obfuscator jscrambler contained an infostealer that was automatically executed during installation. Socket identified the malware minutes after its release.

The npm version 8.14.0 of the jscrambler package, a widely used code obfuscation tool, was distributed with an infostealer on July 11, 2026. The malware was embedded in a preinstall hook and executed automatically during package installation—without developers needing to import the package or invoke it via the command line.

The infostealer was compiled as a native binary for Windows, macOS, and Linux and was silently written to the system and executed during the preinstall hook invocation. These infostealers are designed to extract system data and credentials.

The security company Socket detected the compromise six minutes after the package was released. This means that a critical supply chain dependency endangered all developers who installed version 8.14.0 during the window between publication and detection.

CISOs should verify whether 8.14.0 was used in their development or build environments. The package should be immediately uninstalled and replaced with a known clean version. Additionally, forensic analysis of affected systems is recommended to check for exfiltration of credentials, SSH keys, or other sensitive data.


Source: thehackernews.com · Published July 11, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: