The bottom line: Malware in jscrambler 8.14.0 is activated via the preinstall hook without explicit import or CLI command—installation alone is sufficient for execution.
The npm version 8.14.0 of the JavaScript obfuscator jscrambler contained an infostealer that executed automatically upon installation. Socket identified the malware minutes after release.
The npm version 8.14.0 of the jscrambler package, a widely used code obfuscation tool, was distributed with an infostealer on July 11, 2026. The malware was embedded in a preinstall hook and executed automatically during package installation—without developers needing to import the package or invoke it via the command line.
The infostealer was compiled as a native binary for Windows, macOS and Linux and was silently written to and executed on the system when the preinstall hook was invoked. These infostealers are designed to exfiltrate system data and credentials.
Security company Socket identified the compromise six minutes after the package was released. This means a critical supply chain dependency endangered all developers who installed version 8.14.0 during the window between publication and discovery.
CISOs should verify whether 8.14.0 was used in their development or build environments. The package should be immediately uninstalled and replaced with a known clean version. Additionally, forensic analysis of affected systems is recommended to assess potential exfiltration of credentials, SSH keys, or other sensitive data.
Source: thehackernews.com · Published July 11, 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.