# Socket Weekly: jscrambler Supply Chain Attack, npm v12 Ships…

Canonical: https://brew.new/browse/templates/email/pt1_k97kjqsx30ynwaz90yv07wb7898e44b4

Brand: socket.dev
Category: newsletter

![Preview of Socket Weekly: jscrambler Supply Chain Attack, npm v12 Ships…](https://cdn.brew.new/email-preview-c9110dfe39cd0e8e-tracking_r57qth0b3qwqpj6ag8cb15yben8dvkb2-1789057646717.png)

## Email content

socket-weekly-new-header

Welcome to Socket Weekly. Each week, we share a short, opinionated snapshot of the most important security issues and ecosystem changes.

TOP STORY

jscrambler npm Package Compromised to Drop Infostealers on Linux, macOS, and Windows

An attacker used a stolen npm publishing credential to push five malicious jscrambler releases (8.14.0, 8.16.0, 8.17.0, 8.18.0, and 8.20.0), each dropping a Rust infostealer that targets crypto wallets, cloud credentials, and AI assistant and MCP configs. Socket flagged the first version six minutes after publication, and later releases moved the payload off the install hook so it runs on import and survives npm install --ignore-scripts.

MORE NEWS

npm v12 Ships With Install Scripts Off by Default, Begins Deprecating 2FA-Bypass Tokens

npm v12 is out, turning off install scripts by default and beginning the wind-down of 2FA-bypass publishing tokens, a real dent in the entry point behind almost every worm and credential stealer since late 2025. It doesn't touch code that only runs when a package is imported and used, as seen in the jscrambler compromise where attackers already shifted to import-time execution to route around it.

Compromised Injective SDK Steals Wallet Keys and Mnemonics Through Fake Telemetry

Attackers used a legitimate contributor's GitHub account to slip a backdoor into @injectivelabs/sdk-ts, hooking its key-derivation functions to log mnemonics and private keys and exfiltrate them through traffic that blends in with Injective's own public infrastructure. The payload runs when the library is used rather than at install time, and the actor pushed the same version across 17 more @injectivelabs packages to catch transitive users.

MORE WORTH READING

What's new in ECMAScript 2026

CISA details security lapses that led to GitHub leak of passwords, cloud access keys

Rewriting Bun in Rust

Malicious Go Module Exposes GitHub Malware Lure Network Spanning 222 Repositories

Zero Trust for AI agents

X

512x512-logo-27148

LinkedIn

bluesky

Socket Inc.

Secure your supply chain. Ship with confidence.

2810 N Church St., Suite 71517, Wilmington,DE, 19802

Book a Demo • Unsubscribe

[Open and remix this design](https://brew.new/browse/templates/email/pt1_k97kjqsx30ynwaz90yv07wb7898e44b4)

[Browse email designs](https://brew.new/browse/templates)
