Threat · curated 13 Jul 2026
Unauthorized Publication of a Malicious npm Package affecting CI
First reported jscrambler.com
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
Jscrambler's npm supply-chain compromise shows attackers now explicitly target MCP configurations and AI coding assistant credentials alongside cloud and crypto secrets, expanding the blast radius of package-manager attacks into developers' AI tooling.
Jscrambler disclosed that a threat actor used compromised npm publishing credentials to publish a malicious version of its 'jscrambler' npm package (versions 8.14, 8.16, 8.17, 8.20), which ran an infostealer during the preinstall hook and was downloaded around 1,479 times in a two-hour window. Per Socket's analysis, the malware harvested developer credentials, cloud secrets, crypto wallets, browser data, and notably AI coding tool and MCP configurations (Claude, Cursor, Windsurf, VS Code, Zed), using ChaCha20-Poly1305 obfuscation to resist analysis. Jscrambler revoked credentials and released a safe version 8.22.