Portugal
PRT
An attacker compromised a Jscrambler developer machine, obtained GitHub access and exfiltrated an npm publishing token through the company's workflow. On 11 July 2026 the attacker used Jscrambler's legitimate publishing path to release multiple malicious jscrambler versions and dependent plugins; Jscrambler reported 1,479 downloads of affected packages and no confirmed customer impact.
Estimated severity
66 / 100
Source reliability
93 / 100
Approximate Date
11/07/2026
Targeted Company
JSCRAMBLER
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
Portugal
PRT
No other affected countries reported
Target country
Portugal
Affected countries
Impacted regions
No information
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
No information
Incident Sources
Please rotate your phone