Reviewed threat campaign
jscrambler npm package compromise
Socket documented compromised jscrambler npm releases that introduced hidden native binaries and automatic execution paths, including a preinstall hook in early malicious versions and later import-time execution.
Uncertainty
The attacker changed execution techniques across versions. This record summarizes the reviewed July 11 investigation and does not claim that install-hook controls cover later import-time execution.
Limitations
- The campaign demonstrates why package-install policy cannot be represented as complete runtime malware prevention.
Timeline
- · jscrambler npm package compromise was first observed in the reviewed source material.
- · The reviewed source published or updated its defensive analysis and remediation guidance.
Publication clock: 688.9 hours from reviewed disclosure timestamp to HOL publication; 24-hour high target; historical backfill outside target.
Guard coverage and non-coverage
- partial: coverage:stable:codex — A package-install review can reduce exposure to malicious install hooks on eligible paths; import-time execution and machines where the package already ran require additional controls.
Defensive policy guidance
- Require review or explicit approval for new or changed dependency installation before an eligible package-manager action executes.
Status: available. Coverage depends on the active Guard release, package manager, harness event surface, and local policy. It is not a guarantee that every dependency path is intercepted.
Sources
- Socket: jscrambler supply-chain attack · observed 2026-08-09