Reviewed threat campaign

jscrambler npm package compromise

Socket documented compromised jscrambler npm releases that introduced hidden native binaries and automatic execution paths, including a preinstall hook in early malicious versions and later import-time execution.

Severity highConfidence highReviewed 2026-08-09Expires 2026-09-08

Uncertainty

The attacker changed execution techniques across versions. This record summarizes the reviewed July 11 investigation and does not claim that install-hook controls cover later import-time execution.

Limitations

Timeline

  1. · jscrambler npm package compromise was first observed in the reviewed source material.
  2. · The reviewed source published or updated its defensive analysis and remediation guidance.

Publication clock: 688.9 hours from reviewed disclosure timestamp to HOL publication; 24-hour high target; historical backfill outside target.

Guard coverage and non-coverage

Defensive policy guidance

Sources