Incident case file
Sign in to watchjscrambler npm Supply Chain Attack — IronWorm Rust Infostealer
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: MISSING — no on-chain crypto attacker address disclosed. Attack chain: compromised jscrambler developer machine → GitHub SSH key exfiltration → GitHub Actions workflow abuse → npm publishing token exfiltration → direct npm registry publication via stolen token. Payload identified as IronWorm (JFrog attribution, Shai-Hulud lineage). No public attribution to a named actor or state group.
Timeline: July 11, 2026 (all times UTC): 14:51-14:53 UTC: two failed GitHub Release automation runs on employee account — first visible signs. 15:12:40 UTC: malicious 8.14.0 published to npm using stolen token. Socket.dev flags the release 6 minutes after publication with maximum suspicion score. 15:50 UTC: SSH key removed from GitHub, 8.14.0 deprecated. 17:10 UTC: clean 8.15.0 published. 17:37 UTC: attacker publishes 8.16.0 and 8.17.0 (using the stolen npm token, still active because Jscrambler had only rotated the developer's credentials). 17:45 UTC: 8.18.0 collision — Jscrambler and attacker publish simultaneously, attacker's version lands first. 17:50 UTC: 8.20.0 published by attacker. 17:55 UTC: 2FA enforced on npm publishing. 18:12 UTC: stolen npm token identified and revoked, clean 8.22.0 published. Attack ends. Active window: ~3 hours. July 13, 2026: 08:37 UTC npm removes the malicious package versions. 11:56 UTC public reports confirm 8.18.0 is also infected. 12:23 UTC the 4 downstream packages pinned to 8.18.0 identified. Jscrambler publishes official advisory + post-mortem with 4 updates through July 15. JFrog identifies payload as IronWorm (Rust infostealer, Shai-Hulud lineage) with self-propagation routine. StepSecurity, Socket.dev, Reflectiz, The Hacker News, BleepingComputer, SecurityWeek publish forensic analyses. Recommended action for affected users: treat host as compromised, move crypto assets from any wallet whose extension storage may have been accessible to a new wallet with a freshly generated seed phrase on a clean device.
Sources and coverage
- Articlejscrambler.comhttps://jscrambler.com/blog/security-incident-postmortem-jscrambler
- Articlejscrambler.comhttps://jscrambler.com/blog/security-advisory-malicious-npm-package
- Articlestepsecurity.iohttps://www.stepsecurity.io/blog/jscrambler-npm-package-publishes-malicious-preinstall-binary
- Articlesocket.devhttps://socket.dev/blog/jscrambler-supply-chain-attack
- Articlethehackernews.comhttps://thehackernews.com/2026/07/compromised-jscrambler-8140-npm-release.html
- Articlebleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/hackers-backdoor-jscrambler-npm-package-with-infostealer-malware/
- Articlesecurityweek.comhttps://www.securityweek.com/multiple-jscrambler-packages-impacted-by-supply-chain-attack/
- Articlereflectiz.comhttps://www.reflectiz.com/blog/jscrambler-supply-chain-compromise/
- Articlecsoonline.comhttps://www.csoonline.com/article/npm-ecosystem-hit-with-two-new-supply-chain-compromises
- Articlexcancel.comhttps://xcancel.com/step_security/status/2075996434948870302
- Articlehacked.slowmist.iohttps://hacked.slowmist.io/
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)