What is the jscrambler npm supply chain attack?
On July 11, 2026, attackers used a stolen npm publishing credential to push five malicious jscrambler releases over roughly three hours — 8.14.0, 8.16.0, 8.17.0, 8.18.0, and 8.20.0 — plus four compromised companion plugins. Each shipped hidden native binaries that harvested cloud, crypto-wallet, and AI coding assistant credentials, according to Rescana and Socket.
Answered in
Malware Hid Inside a Popular Obfuscation Tool — and Went Hunting for Your AI Coding Agent's CredentialsStolen npm credentials let attackers slip native-binary malware into jscrambler, hunting for Claude Desktop, Cursor, and Windsurf credentials.
Read the full analysisOther questions this article answers
More development best practices questions
- How many outage reports did Claude and ChatGPT get on July 14, 2026?
- What did Anthropic's own status page say about the July 14 Claude outage?
- Did Claude have more outages after July 14?
- What did ChatGPT's status checker say was wrong?
- Is this outage pattern actually unusual for AI providers?
- What GitHub Actions vulnerability did the attacker exploit?
- How many npm packages were compromised, and how widely were they used?
- What did the malicious payload actually do?
Every answer on Crashtech is written by the editor of the article it comes from — never auto-summarised. Browse all answers or the Development Best Practices beat.