A supply chain attack targeted the Jscrambler npm package, introducing an infostealer malware in version 8.14.0. The attack affected additional versions, including 8.16, 8.17, 8.18, and 8.20, each downloaded approximately 1,479 times.
The initial malicious payload was inserted through a compromised preinstall hook, deploying native binaries on installation across Windows, macOS, and Linux platforms.
After detecting the compromise, Jscrambler swiftly deprecated the affected versions and released a clean version, 8.22. Additional security measures were implemented to prevent further breaches.
Affected users were advised to update to the latest versions to avoid potential exposure of sensitive information such as cloud credentials and cryptocurrency wallets.
The attack highlighted vulnerabilities in the package publishing process, emphasizing the need for robust security protocols. The use of compromised publishing credentials allowed attackers to insert malicious code undetected initially.
Developers using open-source components must remain vigilant as supply chain attacks become more sophisticated and frequent.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Threat actors are abusing npm and its mirroring platforms like UNPKG to host malicious HTML pages that impersonate Cloudflare CAPTCHAs, redirecting visitors to attacker-controlled websites. This technique uses npm as free, validated storage for phishing content, bypassing some security measures by serving malicious pages from legitimate domains.
Researchers discovered a campaign using 24 npm packages to host fake Cloudflare CAPTCHA pages on unpkg mirrors, redirecting users to phishing sites. This method exploits trusted npm infrastructure to deliver malicious content, posing a risk to users who encounter these mirrored links.
Cybersecurity researchers discovered 14 trojanized npm packages that install the RedC2 4.0 Linux backdoor, a cross-platform command-and-control framework. These packages masquerade as functional calendar and streak utilities but secretly deploy a Linux implant for post-exploitation activities. This development highlights ongoing supply chain risks in software development, particularly within the npm ecosystem.
Cybersecurity researchers discovered 16 typosquatted RubyGems packages designed to steal browser credentials, cryptocurrency wallets, seed phrases, and Telegram data from users. The campaign exploited RubyGems' package name reuse and unvalidated author fields, allowing attackers to republish malicious versions of yanked gems.
Nearly 800 malicious packages were published to the npm registry, distributing cross-platform malware that targets Windows, Mac, and Linux systems. This campaign uses a novel method of infection, instructing developers to use `require()` to load the packages, which then execute a downloader for a RAT and infostealer payload.
Security researchers disclosed an npm supply-chain attack that affected over 400 packages, including projects like Keyv and Cacheable, by using stolen developer credentials to publish malicious versions. This incident highlights a vulnerability where malware can operate within trusted workflows and even carry valid provenance attestations, bypassing traditional security checks.
GitHub's Dependabot now provides malware advisories for eight major package ecosystems, including PyPI, Maven, and RubyGems, by integrating data from OpenSSF's malicious-packages repository. This expansion significantly broadens Dependabot's capability to detect and alert users about malicious packages beyond its previous npm-only scope, enhancing software supply chain security for a wider range of developers.
An attacker compromised a developer's GitHub account to inject a credential-stealing worm into keyv and related npm packages, affecting over 868 packages and two billion monthly installs. This attack is significant because the malicious releases carried valid provenance signatures, demonstrating that attackers can exploit trusted supply chain mechanisms.
Cybersecurity researchers identified NullReceiver, an evolution of the EtherHiding C2 technique, which embeds command-and-control server IP addresses within the recipient addresses of empty Ethereum transfers. This method, linked to North Korean threat actors, was found in trojanized npm packages and makes C2 detection more difficult by avoiding smart contracts or transaction payload fields.
A supply chain attack named ChainDrop infected 440 NPM packages with over 2,200 malicious versions, impacting packages with over 500 million weekly downloads. The malware steals credentials from developer workstations and CI/CD environments, then uses them to self-propagate by publishing poisoned package versions and infecting GitHub repositories.
Self-propagating malware named 'ChainDrop' has infected over 1,300 packages on the npm registry, affecting popular utilities and packages from major organizations. The attack started by compromising a GitHub account and spread through malicious files pushed directly to project branches, leading to valid but poisoned package releases. This incident highlights a significant supply-chain vulnerability in the JavaScript ecosystem, potentially exposing developer and cloud credentials to attackers.
A credential-stealing npm worm, initially found in keyv@6.0.0, spread to hundreds of packages across multiple organizations on August 4, 2026. This worm uses a preinstall script to harvest sensitive credentials and can plant Claude Code and VS Code hooks, posing a significant supply chain security risk for developers and CI environments.
Cybersecurity researchers discovered 18 malicious npm packages targeting users of Alibaba developer tools with a cross-platform remote access trojan (RAT). The attack uses unscoped packages that impersonate private Alibaba packages to deliver the RAT through a dependency tree, primarily affecting developers in Chinese-speaking environments.
Beta versions of two npm packages, @joyfill/layouts and @joyfill/components, have been compromised to install a remote access trojan (RAT) linked to the DEV#POPPER malware family. The malicious code executes upon package import in Node.js and uses a multi-blockchain resolver structure for command and control, indicating a sophisticated supply chain attack.
Researchers found a trojanized version of Newtonsoft.Json on NuGet, designed to rig game results on Digitain. This trojan is notable for functioning normally for most users while targeting a specific system, representing a significant security threat in the package management ecosystem.
Five malicious AsyncAPI packages were uploaded to npm, delivering a remote access trojan. Over 2.25 million weekly downloads of these packages raise significant supply-chain security concerns in the software development community.
Four npm packages in the @asyncapi namespace have been compromised to distribute a multi-stage botnet malware identified as Miasma. This incident is significant as it highlights vulnerabilities in widely used packages and poses risks for credential theft and other malicious activities.
Jscrambler's NPM package faced a supply chain attack, compromising multiple versions that included malicious code. The affected packages exposed sensitive data from developers' machines, raising concerns about the security of open-source dependencies.
A compromised version of the Jscrambler npm package was discovered to contain information-stealing malware that executed during the installation process and was downloaded nearly 1,500 times. Jscrambler quickly deprecated the affected releases and implemented additional security measures following the incident, which was attributed to compromised npm publishing credentials.
The jscrambler npm package version 8.14.0 was compromised to execute an infostealer upon installation. This malicious version, published on July 11, 2026, targets developers' sensitive information, including cloud credentials and cryptocurrency wallets, escalating security risks for users.