At a Glance
- Affected package: jscrambler
- Affected products: Code Integrity
- Affected versions: 8.14/8.16/8.17/8.18/8.20
- Safe version: 8.22
- Other affected packages and versions:
- jscrambler-webpack-plugin 8.6.2
- gulp-jscrambler 8.6.2
- grunt-jscrambler 8.5.2
- jscrambler-metro-plugin 9.0.2
- Safe versions:
- jscrambler-webpack-plugin 8.6.3
- gulp-jscrambler 8.6.3
- grunt-jscrambler 8.5.3
- jscrambler-metro-plugin 9.0.3
- Time of publication: 11 July 2026, 16:12:40 BST (London) / 11:12:40 EDT (US Eastern)
- Status: Deprecated and no longer available through normal npm dependency resolution.
- Known downloads: npm reported 1479 downloads across all affected versions, all already removed by npm
- Recommended action: Do not install the affected version. If you have already installed it, remove it immediately and upgrade to a safe version (8.22 or later).
- Investigation status: Closed. Postmortem here.
Update 13th July 4 pm London time: updated number of known downloads of malicious package versions, as reported by npm
Update 13th July 2 pm London time: added dependent packages that pinned version 8.18.
Today, we identified the unauthorized publication of a malicious version of our jscrambler npm package, which is used with our Code Integrity product. This incident was limited to that package and did not affect any other Jscrambler products, including Webpage Integrity.
The published package contained malware that executed during the npm preinstall lifecycle hook. As soon as we became aware of the unauthorized publication, we activated our incident response process and immediately took steps to contain the issue.
The unauthorized publication occurred at 16:12:40 London Time (11:12:40 EDT). The publication itself immediately triggered unexpected notifications to our package maintainers, allowing us to detect the incident within seconds and begin our response without delay.
The malicious version was immediately deprecated to prevent further installations through normal npm dependency resolution. Npm reported a total of 1479 across all affected packages during that 2h window. That includes downloads that were triggered by other packages that used the affected package.
We recommend that all customers and users update their version to make sure that they are using version 8.22 or later. This version was published today at 18:12 London time (13:12 EDT).
Our investigation indicates that the attacker was able to publish the package using an npm publishing credential. We have revoked and rotated all relevant credentials, passwords, and secrets, and have implemented additional security controls around our publishing process while the investigation continues.
The affected package is a dependency of 4 other Jscrambler packages. Those versions are identified above and were also equally deprecated, and new versions were issued.
Our response has included:
- Immediate deprecation of the malicious package version.
- Revocation and rotation of publishing credentials.
- Rotation of related secrets and passwords.
- Additional hardening of our package publishing pipeline.
- A full forensic investigation to determine the root cause and confirm the scope of the incident.
Our investigation is ongoing. We are working to establish the complete sequence of events and verify whether any systems beyond the package publication process were affected.
We will continue to update this advisory as additional verified information becomes available.
We sincerely apologize for this incident. Protecting our users and maintaining the integrity of our software distribution process are responsibilities we take extremely seriously, and we are committed to being transparent throughout this investigation.