Blog

Security Incident Postmortem: Malicious Versions of the jscrambler npm Package

On July 11, 2026, an attacker used a stolen npm token to publish malicious versions of the Jscrambler package. We caught it within seconds, pulled the bad versions, and shipped a clean release the same day.