c8fd47d36bdf…SHA-256 hash for the decompressed macOS Mach-O payload.bba32ddeab07…SHA-256 hash for package.json in the compromised package.fbbcf4d8f981…SHA-256 hash for the decompressed Linux ELF payload.b7ca95d1b23c…SHA-256 hash for the decompressed Windows PE payload.a742de963f14…SHA-256 hash for dist/setup.js in the compromised package.a41a523ef951…SHA-256 hash for dist/intro.js in the compromised package.
ThreatNoir Weekend Brief — July 12
Afternoon Review in IT Security — July 12, 2026
The afternoon security briefing for July 12, 2026 brings critical developments across supply chain threats, firmware vulnerabilities, and active exploitation campaigns. Multiple high-impact incidents affecting developers, cryptocurrency users, and self-hosted infrastructure deployments have emerged, requiring immediate attention and remediation efforts.
jscrambler npm Package Compromised in Supply Chain Attack
A malicious release of the popular jscrambler npm package has introduced hidden native binaries that execute automatically during installation, exposing developers and build systems to a sophisticated supply chain attack. Source: jscrambler npm Package Compromised in Supply Chain Attack
The compromised version 8.14.0, published on July 11, 2026, includes an undocumented preinstall hook that invokes dist/setup.js without requiring any user action beyond running npm install. The package introduces entirely new files absent from the previous release 8.13.0, including platform-specific binaries for Linux, macOS, and Windows embedded within an obfuscated CSI container. Socket detected the compromised package within six minutes of publication, but the malware had already achieved execution on any system where installation occurred.
The embedded payload is a Rust-built cross-platform infostealer with extensive targeting capabilities. The malware harvests cryptocurrency wallet credentials including MetaMask, Trust Wallet, Coinbase Wallet, and Phantom extension data, along with seed phrases and vault encryption keys. It also targets AI coding assistant configurations for Claude Desktop, Cursor, and Windsurf, which frequently contain API keys and Model Context Protocol credentials. Cloud credential theft encompasses GCP metadata services, AWS Secrets Manager and SSM Parameter Store, and Azure IMDS endpoints. The payload further captures browser data, Discord and Slack credentials, Telegram Desktop message history, Steam session tokens, and attempts local privilege escalation through sudo and systemd-run. All sensitive strings are individually encrypted with ChaCha20-Poly1305, with approximately 2,400 strings recovered during analysis. Network exfiltration occurs via TLS to drop servers using stolen cloud credentials for reconnaissance and lateral movement.
With approximately 15,800 weekly downloads, the jscrambler package is commonly installed as a development dependency or invoked through CI systems to process production builds. Because the malicious code executes through a preinstall hook, simply installing the compromised version is sufficient to trigger the bundled platform-specific binary, potentially exposing source code, environment variables, build credentials, and deployment tokens accessible to the npm process. Organizations should immediately remove jscrambler@8.14.0, rotate all credentials accessible to affected development and CI environments, review installation logs for execution of dist/setup.js, and pin to version 8.13.0 or another verified clean release until remediation is published.
New U-Boot Flaws Could Enable Stealthy Firmware Attacks
Six vulnerabilities in the widely used U-Boot bootloader have been discovered that could allow attackers to execute malicious code during device boot, potentially enabling stealthy firmware attacks that compromise security protections and install persistent malware. Source: New U-Boot Flaws Could Enable Stealthy Firmware Attacks
These U-Boot flaws represent a critical risk to the integrity of embedded systems and IoT devices that rely on this bootloader for initialization. Exploitation of these vulnerabilities could allow attackers to inject malicious code before the operating system loads, establishing persistence mechanisms that operate below the visibility of traditional security tools and operating system protections.
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
Unknown threat actors have compromised the Injective Labs SDK project's GitHub repository and leveraged the access to publish a malicious npm package designed to steal cryptocurrency wallet private keys and mnemonic seed phrases. Source: Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages
The compromised version @injectivelabs/sdk-ts@1.20.21 was embedded with fake telemetry functionality that exfiltrates sensitive cryptocurrency wallet data to attacker-controlled infrastructure. This incident demonstrates the ongoing threat to cryptocurrency projects and their development ecosystems, where compromised maintainer accounts can be weaponized to distribute credential-stealing payloads to downstream users and applications.
Hackers Exploit Critical Auth Bypass in Gitea Docker Image
Hackers are actively exploiting a critical vulnerability in the official Docker image for the Gitea self-hosted Git service that allows attackers to impersonate any user, including administrators. Source: Hackers Exploit Critical Auth Bypass in Gitea Docker Image
The vulnerability, tracked as CVE-2026-20896, stems from a default wildcard configuration in the Gitea Docker image deployment that permits authentication bypass. This flaw enables attackers to gain administrative access to Gitea instances, potentially compromising source code repositories, credentials, and deployment infrastructure for organizations relying on this self-hosted Git service.
The afternoon's threat landscape underscores the convergence of supply chain attacks, firmware-level compromises, and active exploitation of widely deployed open-source infrastructure. Organizations must prioritize immediate remediation of the jscrambler and Injective Labs packages, update U-Boot deployments, patch Gitea Docker instances, and conduct comprehensive audits of development and CI environments for indicators of compromise.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- @injectivelabs/sdk-tsCompromised npm package version used for wallet key exfiltration.
testnet.archival.chain.grpc-web.injective[.]networkRemote server used for exfiltrating stolen wallet data.
- Critical authentication bypass in Gitea Docker image allowing user impersonation via reverse proxy header spoofing