← Radar

Incident case file

Sign in to watch

jscrambler npm Supply Chain Attack — IronWorm Rust Infostealer

Incident date July 11, 2026

0 views

Resolvedtargets MetaMaskPhantomExodusCoinbaseTrust Wallet — EthereumSolanamulti-EVMBitcoinSupply chain attack (npm) — crypto wallet infostealerCluster: JSC-SUP-2026-07

Estimated loss

$0

Victims identified

1479
Victim group joining is coming soon.

Investigation

100%

Facts and investigation

Attacker: MISSING — no on-chain crypto attacker address disclosed. Attack chain: compromised jscrambler developer machine → GitHub SSH key exfiltration → GitHub Actions workflow abuse → npm publishing token exfiltration → direct npm registry publication via stolen token. Payload identified as IronWorm (JFrog attribution, Shai-Hulud lineage). No public attribution to a named actor or state group.

Funds moved to: N/A — no confirmed direct crypto theft chain publicly traced. Payload exfiltration observed via: (a) TLS to hard-coded C2 IPs 37.27.122.124 and 57.128.246.79 (StepSecurity global block); (b) embedded Tor client (check.torproject.org, archive.torproject.org); (c) bulk data upload via temp.sh public file host (leaks victim real IP). Downstream fate of exfiltrated MetaMask/Phantom/Exodus/Coinbase/Trust Wallet seed phrases not publicly tracked. Socket.dev confirmed the malware actively used stolen
Malicious npm versions x5: jscrambler 8.14.0, 8.16.0, 8.17.0, 8.18.0, 8.20.0. 4 downstream packages pinned to 8.18.0: jscrambler-webpack-plugin 8.6.2, gulp-jscrambler 8.6.2, grunt-jscrambler 8.5.2, jscrambler-metro-plugin 9.0.2. Clean version: 8.22.0. Payload container dist/intro.js (7.8MB, magic bytes 1B 43 53 49 01) holds 3 Rust binaries (ELF Linux, PE32+ Windows, Mach-O arm64 macOS). SHA-256 hashes — dist/setup.js: a742de963f14a92d24ebcbc7b44ac867e23a20d31d1b0094a13a4f83287f4e60. dist/intro

Timeline: July 11, 2026 (all times UTC): 14:51-14:53 UTC: two failed GitHub Release automation runs on employee account — first visible signs. 15:12:40 UTC: malicious 8.14.0 published to npm using stolen token. Socket.dev flags the release 6 minutes after publication with maximum suspicion score. 15:50 UTC: SSH key removed from GitHub, 8.14.0 deprecated. 17:10 UTC: clean 8.15.0 published. 17:37 UTC: attacker publishes 8.16.0 and 8.17.0 (using the stolen npm token, still active because Jscrambler had only rotated the developer's credentials). 17:45 UTC: 8.18.0 collision — Jscrambler and attacker publish simultaneously, attacker's version lands first. 17:50 UTC: 8.20.0 published by attacker. 17:55 UTC: 2FA enforced on npm publishing. 18:12 UTC: stolen npm token identified and revoked, clean 8.22.0 published. Attack ends. Active window: ~3 hours. July 13, 2026: 08:37 UTC npm removes the malicious package versions. 11:56 UTC public reports confirm 8.18.0 is also infected. 12:23 UTC the 4 downstream packages pinned to 8.18.0 identified. Jscrambler publishes official advisory + post-mortem with 4 updates through July 15. JFrog identifies payload as IronWorm (Rust infostealer, Shai-Hulud lineage) with self-propagation routine. StepSecurity, Socket.dev, Reflectiz, The Hacker News, BleepingComputer, SecurityWeek publish forensic analyses. Recommended action for affected users: treat host as compromised, move crypto assets from any wallet whose extension storage may have been accessible to a new wallet with a freshly generated seed phrase on a clean device.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)