Bottom line: A compromised Jscrambler npm package containing infostealer malware was distributed by attackers in the npm registry and downloaded nearly 1,500 times.
Web security company Jscrambler has revealed that attackers published a manipulated version of its npm package, which was downloaded nearly 1,500 times. The compromise demonstrates that even ostensibly trusted repositories are vulnerable to supply chain attacks.
Jscrambler, a provider of client-side web security, has confirmed the compromise of an official npm package in its product line. A threat actor published a manipulated version containing infostealer malware in the npm registry, the standard package manager for Node.js dependencies.
According to the company, the infected package was downloaded nearly 1,500 times before Jscrambler and npm identified and responded to the discovery. This underscores a central security risk in modern software development: the intermediary layer between developer and user — the dependency chain — is a preferred attack target. Infostealer malware typically aims at exfiltrating credentials, API keys, environment variables, and other sensitive configurations present during the build process or in the development environment.
For CISOs, this incident provides concrete insight into supply chain risk: even well-known and established npm packages can become a vector for malware if the package maintainer’s access controls are weak or their account is compromised. An immediate review of installed versions of the affected package as well as logs of npm installations in CI/CD pipelines is necessary. Organizations should check whether the manipulated version (with the exact version number) exists in their dependency trees and — if so — in case of suspicion rotate credentials and secrets.
Source: www.bleepingcomputer.com · Published 13 July 2026
Lumi AI News — AI-assisted curation according to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.