Compromised Jscrambler npm Releases Deliver Cross-Platform Infostealer

· Original article ↗

Summary

Five compromised Jscrambler npm releases delivered a cross-platform infostealer targeting developer credentials and secrets. Jscrambler confirmed unauthorized publication; version 8.22.0 is reported clean, and affected environments should be audited.

Key points

  • Malicious releases 8.14.0, 8.16.0, 8.17.0, 8.18.0, and 8.20.0 contained the same payload; Jscrambler confirmed an attacker published them using an npm credential.
  • The malware initially ran through a preinstall hook; releases 8.18.0 and 8.20.0 instead execute the dropper when the package is imported or its CLI runs, and declare a compromised self-dependency.
  • The package drops a native infostealer for Linux, Windows, or macOS, targeting developer tools, cloud credentials, wallets, browsers, and messaging apps.
  • Static analysis found TLS-based data exfiltration and requests involving cloud and orchestration APIs; the source does not establish how many systems were affected.
  • Socket detected the first compromised release six minutes after publication. Jscrambler revoked and rotated publishing credentials and related secrets, deprecated affected releases, and added publishing controls.
  • Version 8.22.0 is reported clean. Users should upgrade to a verified clean release, audit machines that installed affected versions, and rotate credentials accessible to those environments.

Article Details

Attack Vectors
  • Jscrambler confirmed that an attacker used an npm publishing credential to publish unauthorized jscrambler releases: 8.14.0, 8.16.0, 8.17.0, 8.18.0, and 8.20.0.
  • Versions 8.14.0, 8.16.0, and 8.17.0 execute the dropper through a preinstall hook invoking node dist/setup.js, requiring neither package import nor CLI execution.
  • Versions 8.18.0 and 8.20.0 inject the dropper as a self-executing function into dist/index.js and dist/bin/jscrambler.js. Execution occurs on package import or CLI use, bypassing install-hook-only inspection and npm install --ignore-scripts.
  • Versions 8.18.0 and 8.20.0 declare a self-dependency on jscrambler ^8.17.0, allowing a compromised release to be pulled transitively.
  • The dropper selects a gzip-compressed native executable from dist/intro.js according to process.platform, writes it to a randomly named hidden temporary file, marks it executable, and launches it as a detached background process.
  • The Rust-built payloads target developer credentials and secrets, including wallet vaults and seed phrases, AI-tool and MCP configurations, cloud credentials, messaging accounts, browser data, Steam sessions, and OS keyrings.
  • Static analysis confirmed TLS-based outbound exfiltration using a multipart POST /upload request. The payload also constructs cloud and orchestration API requests using stolen credentials.
Defensive Notes
  • The updated recommendation is to upgrade or pin jscrambler to 8.22.0, which the article identifies as clean. Versions 8.13.0 and 8.15.0 are also identified as clean releases.
  • Audit every machine that installed jscrambler 8.14.0, 8.16.0, 8.17.0, 8.18.0, or 8.20.0, including developer workstations, automated build systems, and CI environments.
  • Remove affected releases and rotate credentials accessible to affected development or CI environments.
  • Review installation logs for execution of dist/setup.js, while accounting for later releases that execute through package imports or CLI invocation instead of installation hooks.
  • Do not rely on npm install --ignore-scripts or inspection limited to preinstall/postinstall hooks to prevent execution of the later malicious releases.
  • Jscrambler reported revoking and rotating publishing credentials and related secrets, deprecating affected releases, and adding publishing-process controls.
  • Socket detected and flagged the initial malicious release six minutes after publication. The number of users who installed compromised versions was not known.

Indicators of compromise

TypeIndicatorContext
SHA256a41a523ef9517aab37ed6eea0ec881821bdcb7aefcb5c5f603adc7907f868c86SHA-256 of malicious dist/intro.js, the binary container holding three compressed native payloads.
SHA256a742de963f14a92d24ebcbc7b44ac867e23a20d31d1b0094a13a4f83287f4e60SHA-256 of malicious dist/setup.js, the loader used to extract and execute the native payload.
SHA256b7ca95d1b23c8e67416a25cedf741de0917c2096bbc9d24649eea7853d054903SHA-256 of the decompressed Windows x86-64 PE infostealer payload.
SHA256bba32ddeab075a5e5015eec50f5d2af364c95b848732c714aea6b6baf78f49f0SHA-256 of package.json listed among the compromised package artifacts.
SHA256c8fd47d36bdf7c825378593ab82ed8c24d1dc52e26b507812393e24e1d5201fdSHA-256 of the decompressed macOS arm64 Mach-O infostealer payload.
SHA256fbbcf4d8f98168f78f5c0c47a9ae56d59ec8ac84a7c9ca6b797fedfb8d62d2bdSHA-256 of the decompressed Linux x86-64 ELF infostealer payload.

MITRE ATT&CK

T1005 · Data from Local SystemThe payload harvests local wallet vaults and seed phrases, Telegram Desktop data, and developer-tool configuration files.T1027 · Obfuscated Files or InformationNative payloads are hidden in a custom CSI container, and sensitive configuration strings are individually encrypted with ChaCha20-Poly1305.T1036 · MasqueradingThe file dist/intro.js has a JavaScript extension but actually contains an approximately 7.8 MB binary payload container.T1053.003 · CronRecovered payload strings reference crontab for persistence; the article does not report observed creation of a cron job.T1059.007 · JavaScriptThe malicious releases execute a JavaScript dropper through node dist/setup.js or self-executing code injected into package entry points.T1071.001 · Web ProtocolsStatic analysis identified a TLS-protected HTTP POST /upload request with a multipart/form-data body for outbound exfiltration.T1078.004 · Cloud AccountsThe payload constructs requests to cloud and orchestration APIs using stolen credentials.T1082 · System Information DiscoveryMachine fingerprinting references /etc/machine-id, /var/lib/dbus/machine-id, and /sys/class/dmi/id/board_serial.T1140 · Deobfuscate/Decode Files or InformationThe loader decompresses the platform-specific executable, while the native malware decrypts sensitive strings on demand.T1195.001 · Compromise Software Dependencies and Development ToolsAn attacker used an npm publishing credential to distribute malicious jscrambler releases consumed by developers and build pipelines.T1539 · Steal Web Session CookieSteam session theft targets steamLoginSecure, and browser collection includes Firefox cookies.sqlite.T1543.001 · Launch AgentRecovered payload strings reference macOS LaunchAgents for persistence; the article does not report observed installation of a LaunchAgent.T1543.002 · Systemd ServiceRecovered payload strings reference systemd user and system units for persistence; the article does not report observed installation of those units.T1548.003 · Sudo and Sudo CachingLocal privilege escalation is attempted with sudo -S -p, supplying a password through standard input.T1552.001 · Credentials In FilesThe payload targets credentials in AI-tool and MCP configuration files, cloud credential files, and developer configuration directories.T1552.005 · Cloud Instance Metadata APIThe payload targets GCP service-account metadata tokens, the AWS ECS task-metadata endpoint, and Azure IMDS.T1555 · Credentials from Password StoresThe payload includes KDE KWallet access and wallet-vault extraction configuration intended to recover protected secrets.T1555.003 · Credentials from Web BrowsersThe infostealer targets Chromium-family browser profiles and Firefox data, using embedded LevelDB and SQLite support.T1555.006 · Cloud Secrets Management StoresThe payload includes access to GCP Secret Manager and AWS Secrets Manager, including GetSecretValue and ListSecrets operations.

Vendors

Products

AWSAWS — the ECS task-metadata endpoint 169.254.170.2, secretsmanager.GetSecretValue / ListSecrets, and SSM Parameter Store AmazonSSM.GetParameters / DescribeParameters.AWS Secrets ManagerAPIs using stolen credentials: cloud metadata services, Kubernetes (/api/v1/namespaces), AWS Secrets Manager and SSM, and others.AzureAzure — the IMDS endpoint 169.254.169.254 and management.azure.com.BraveChromium-family browsers — Chrome, Chromium, Edge, Brave, Vivaldi, and Opera (both Linux profile paths and macOS bundle identifiers), read via embedded LevelDB and SQLite.ChromiumChromium-family browsers — Chrome, Chromium, Edge, Brave, Vivaldi, and Opera (both Linux profile paths and macOS bundle identifiers), read via embedded LevelDB and SQLite.Claude DesktopClaude Desktop — .config/Claude/claude_desktop_config.json, .claude.jsonCoinbase WalletCoinbase Wallet — hnfanknocfeofbddgcijnmhnfnkdnaadCursorCursor — .cursor/mcp.jsonDiscordDiscord — stable, PTB, and Canary bundle IDs; /api/v9/users/@me and guild enumeration.EdgeChromium-family browsers — Chrome, Chromium, Edge, Brave, Vivaldi, and Opera (both Linux profile paths and macOS bundle identifiers), read via embedded LevelDB and SQLite.ExodusThe Exodus wallet (server.exodus.io) is also targeted. The config contains vault- and seed-extraction keys — HD Key Tree, mnemonic, seedPhrase, recoveryPhrase, and seed — plus scrypt KDF parameters (salt, iterations, N,FactoryFactory — .factory/mcp.jsonGCPGCP — metadata.google.internal, the compute-metadata service-account token endpoint, GOOGLE_APPLICATION_CREDENTIALS, .config/gcloud, credentials.db, access_tokens.db, application_default_credentials.json, and SecretGoogle ChromeChromium-family browsers — Chrome, Chromium, Edge, Brave, Vivaldi, and Opera (both Linux profile paths and macOS bundle identifiers), read via embedded LevelDB and SQLite.jscramblerA compromised release of the popular jscrambler npm package introduced hidden native binaries that execute automatically during npm install, exposing users to a supply chain attack before any application code runs.KDE KWalletKDE KWallet — OS keyring access.Kubernetesrequests that query cloud and orchestration APIs using stolen credentials: cloud metadata services, Kubernetes (/api/v1/namespaces), AWS Secrets Manager and SSM, and others.Linuxnew files, including dist/setup.js and dist/intro.js, along with platform-specific binaries for Linux, macOS, and Windows embedded in an obfuscated CSI container. None of these files or the install hook existmacOSnew files, including dist/setup.js and dist/intro.js, along with platform-specific binaries for Linux, macOS, and Windows embedded in an obfuscated CSI container. None of these files or the install hook exist in theMetaMaskMetaMask — nkbihfbeogaeaoehlefnkodbefgpgknnMicrosoft Windowsincluding dist/setup.js and dist/intro.js, along with platform-specific binaries for Linux, macOS, and Windows embedded in an obfuscated CSI container. None of these files or the install hook exist in the previousMozilla FirefoxFirefox — profiles.ini, cookies.sqlite, prefs.js.npmA compromised release of the popular jscrambler npm package introduced hidden native binaries that execute automatically during npm install, exposing users to a supply chain attack before any application code runs.OpenCodeopencodeOperaChromium-family browsers — Chrome, Chromium, Edge, Brave, Vivaldi, and Opera (both Linux profile paths and macOS bundle identifiers), read via embedded LevelDB and SQLite.PhantomPhantom — bfnaelmomeimhlpmgjnjophhpkkoljpaSecret Manager.config/gcloud, credentials.db, access_tokens.db, application_default_credentials.json, and Secret Manager access.SlackSlack — .slack.com, /api/auth.test.SSM Parameter StoreAWS — the ECS task-metadata endpoint 169.254.170.2, secretsmanager.GetSecretValue / ListSecrets, and SSM Parameter Store AmazonSSM.GetParameters / DescribeParameters.SteamSteam — session theft via steamLoginSecure, loginusers.vdf, ConnectCache.Telegram DesktopTelegram Desktop — tdata, key_datas.Trust WalletTrust Wallet — egjidjbpglichdcondbcbdnbeeppgdphVivaldiChromium-family browsers — Chrome, Chromium, Edge, Brave, Vivaldi, and Opera (both Linux profile paths and macOS bundle identifiers), read via embedded LevelDB and SQLite.VS CodeVS Code / VS Code Insiders — settings.json, .mcp.json, mcpServersVS Code InsidersVS Code / VS Code Insiders — settings.json, .mcp.json, mcpServersWindsurfWindsurf — .codeium/windsurf/mcp_config.jsonZedZed — .config/zed/settings.json, context_servers

Related Articles