CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

jscrambler npm supply-chain compromise (2026-07)

incident · incident:jscrambler-npm-supply-chain-2026

Stolen-credential/compromised-pipeline compromise of the jscrambler npm package (v8.14.0 through 8.20.0, 2026-07-11) pushing a Rust infostealer via an undocumented preinstall hook, later relocated to a self-executing dist/index.js function to evade install-script scanners; detected by Socket six minutes after publication, v8.22.0 clean (Socket / The Hacker News, 2026-07-11).

Coverage
0
first 2026-07-12 → last –
no data
Latest activity
–
no entry about it yet
Peak priority
·
no entry about it yet
Targets
·
no sector or region stated
Sources cited
0
0 hosts

Story timeline

No published entries reference this entity yet.

Entries about jscrambler npm supply-chain compromise (2026-07)

No published entry is about this entity yet · an entry attaches by registry key, by the entity's name or a public alias in its title or body, or (for CVE entities) by exact CVE id.

explore in graph