Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    The Rise of the 1 am Job Interview

    August 10, 2026

    The Download: AI agents for science, and the “censorship-industrial complex”

    August 10, 2026

    The AI Slop Backlash Is Actually Having an Impact

    August 10, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The Rise of the 1 am Job Interview
    • The Download: AI agents for science, and the “censorship-industrial complex”
    • The AI Slop Backlash Is Actually Having an Impact
    • These startups are chasing the next big thing in LLMs
    • Meetily Lets You Transcribe and Summarize Meetings Without a Subscription—Here’s How
    • These AI Barons Are Ready to Give Away Their Fortunes
    • This Week’s Awesome Tech Stories From Around the Web (Through August 8)
    • How to Disable Gemini in Gmail and Google Docs
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»Hackers backdoor Jscrambler npm package with infostealer malware
    Cybersecurity

    Hackers backdoor Jscrambler npm package with infostealer malware

    kirklandc008@gmail.comBy kirklandc008@gmail.comJuly 14, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Hackers backdoor Jscrambler npm package with infostealer malware
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The Jscrambler client-side web security company disclosed that a threat actor published a malicious version of its npm package that has been downloaded almost 1,500 times.

    The malicious Jscrambler package spanned releases 8.14, 8.16, 8.17, and 8.20 and included information-stealing malware that executed during the ‘preinstall’ hook.

    “Today, we identified the unauthorized publication of a malicious version of our jscrambler npm package, which is used with our Code Integrity product,” Jscrambler says in a warning on Saturday.

    “This incident was limited to that package and did not affect any other Jscrambler products, including Webpage Integrity,” the company said.

    Although Jscrambler reacted quickly, the malicious package lasted for two hours before the developer deprecated it and released the safe version 8.22.

    The affected package was a dependency for four other Jscrambler packages, which the vendor has also deprecated and replaced with new versions.

    Statistical data from Node Package Manager (npm) shows that the malicious package was downloaded 1,479 times during the two-hour window.

    Jscrambler is a commercial platform for protecting web and mobile JavaScript applications from reverse engineering and tampering.

    Its npm package has 17,000 weekly downloads and enables app developers to upload their JavaScript to Jscrambler’s service to protect the code from alteration. This helps defend against real-time modifications like injecting malicious code.

    Application-security company Socket detected the compromise and analyzed the unauthorized Jscrambler release. The researchers say that the package included an infostealer that targeted multiple types of sensitive data:

    • Source code and project files
    • Developer credentials and secrets (Git, SSH, environment variables, CI/CD tokens)
    • Cloud credentials and secret managers (AWS, Azure, GCP, Kubernetes)
    • AI coding tools and MCP configurations (Claude, Cursor, Windsurf, VS Code, Zed)
    • Cryptocurrency wallets and seed phrases (MetaMask, Phantom, Coinbase, Exodus, Trust Wallet)
    • Browser data (cookies, saved credentials)
    • Messaging and collaboration apps (Slack, Discord, Telegram)

    Socket reports that the malware used strong per-string obfuscation via the ChaCha20-Poly1305 encryption algorithm, which made it difficult to reverse-engineer the code.

    According to Jscrambler, the compromise was possible due to compromised npm publishing credentials, which the company has revoked.

    Following the incident, additional security controls have been implemented for the publishing pipeline.

    Developers who have used the malicious npm packages should treat their environments as compromised, rotate all secrets, and restore from safe backups.

    Jscrambler recommends that customers make sure that they are using the latest version of the product.

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    backdoor hackers infostealer Jscrambler malware npm package
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Ransomware in 2026: More groups, more victims, no slowdown

    July 26, 2026

    The 3 types of people who will excel in the AI agent era, according to tech leaders

    July 26, 2026

    Steam forum ClickFix attacks infect gamers with XMRig cryptominers

    July 26, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • The Rise of the 1 am Job Interview
    • The Download: AI agents for science, and the “censorship-industrial complex”
    • The AI Slop Backlash Is Actually Having an Impact
    • These startups are chasing the next big thing in LLMs
    • Meetily Lets You Transcribe and Summarize Meetings Without a Subscription—Here’s How

    The Rise of the 1 am Job Interview

    August 10, 2026

    The Download: AI agents for science, and the “censorship-industrial complex”

    August 10, 2026

    The AI Slop Backlash Is Actually Having an Impact

    August 10, 2026

    These startups are chasing the next big thing in LLMs

    August 10, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.