MIT TRACE

MIT CTL Logo
Back to Main Dashboard

Jscrambler npm publishing compromise distributes malicious software releases

An attacker compromised a Jscrambler developer machine, obtained GitHub access and exfiltrated an npm publishing token through the company's workflow. On 11 July 2026 the attacker used Jscrambler's legitimate publishing path to release multiple malicious jscrambler versions and dependent plugins; Jscrambler reported 1,479 downloads of affected packages and no confirmed customer impact.

66

Estimated severity

66 / 100

93

Source reliability

93 / 100

Approximate Date

11/07/2026

Targeted Company

JSCRAMBLER

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

Portugal

PRT

Other Affected Countries

No other affected countries reported

Target country

Portugal

Affected countries

Portugal

Impacted regions

No information

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Supply chain data integrity impact

Affected sectors

Technology & IT Services

Affected departments

Information TechnologyEngineering & Maintenance

Attack Profile

Attack types

Software supply chain compromiseMalwareUse of stolen credentialsData exfiltrationUnauthorized access

Attributed threat actors

No information

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.