Daily Security Intel

Archives
Log in
Subscribe
July 12, 2026

[SecurityIntel] 12 Jul | Compromised Jscrambler NPM Package Drops Rust Infostealer

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Sunday, July 12, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Compromised Jscrambler NPM Package Drops Rust Infostealer

CRITICAL

5

C2 IPs

40

OTX IOCs

7

ARTICLES

■ ANALYST TLDR

Today's threat landscape is highlighted by a severe supply chain compromise of the jscrambler npm package (v8.14.0) delivering a Rust-based infostealer, alongside a critical stored XSS vulnerability in Zimbra's Classic Web Client that allows arbitrary code execution. Additionally, threat actors are leveraging a novel "Ghostcommit" prompt injection technique hidden in PNG files to exploit AI code reviewers, while global campaigns target vulnerable CMS platforms and GitHub APIs for reconnaissance.

■ CRITICAL STORIES

CRITICAL#1

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

A compromised version of a popular npm package uses preinstall hooks to execute a native Rust infostealer, representing a severe supply chain risk for JavaScript developers.

CRITICAL#2

Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions

A stored cross-site scripting (XSS) vulnerability in Zimbra's Classic Web Client allows attackers to execute arbitrary code within user sessions via malicious emails.

HIGH#3

'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets

Researchers demonstrated a novel attack vector where prompt injections are hidden inside PNG images to bypass AI reviewers like CodeRabbit and Bugbot, potentially stealing repository secrets.

INFO#4

Ghost Accounts Abuse GitHub API in Mass Recon Campaign

Threat actors are utilizing ghost accounts on GitHub to systematically map organizations, repositories, and members, highlighting automated API abuse for reconnaissance.

■ CVEs IDENTIFIED

[CVE-TBD]

jscrambler npm package (v8.14.0) — Malicious code execution via preinstall hook

Critical

[CVE-TBD]

Zimbra Classic Web Client — Stored Cross-Site Scripting (XSS) leading to Arbitrary Code Execution

Critical

[CVE-TBD]

Wireshark (pre-4.6.7) — Multiple vulnerabilities (12 bugs fixed)

High

[CVE-TBD]

Content Management Systems (CMS) & Plugins — Global exploitation of vulnerable CMS platforms

High

■ THREAT ACTORS

Suspected China-aligned actors

APT

Targeting Pakistani law enforcement organizations and Balochistan Police Portal

Suspected India-aligned actors

APT

Targeting Pakistani law enforcement organizations and Balochistan Police Portal

Unknown Actors (Ghost Accounts)

Cybercriminals

Abusing GitHub API for mass reconnaissance and organization mapping

■ ATT&CK TTPs

T1195.002
Supply Chain Compromise: Compromised Software Dependency | Compromised jscrambler npm package version 8.14.0
T1059
Command and Scripting Interpreter | Preinstall hook executing native binary in compromised npm package
T1566.001
Phishing: Spearphishing Attachment | Malicious emails targeting Zimbra Classic Web Client
T1594
Search Victim-Owned Websites | Ghost accounts abusing GitHub API to map organizations and members
T1190
Exploit Public-Facing Application | Weaponization of Balochistan Police Portal and CMS vulnerabilities
T1204.002
User Execution: Malicious File | PNG files containing hidden prompt injections ('Ghostcommit') executed by AI agents

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

jscrambler npm package (8.14.0) — Malicious preinstall hook drops Rust infostealer — [THN]

[P1 PATCH NOW]≤24h

Zimbra Classic Web Client — Stored XSS allows arbitrary code execution in user sessions — [THN]

[P2 PATCH NOW]≤72h

Wireshark — 12 vulnerabilities fixed in version 4.6.7 — [SANS]

[P2 PATCH NOW]≤72h

Content Management Systems (CMS) — Global exploitation campaign targeting vulnerable platforms and plugins — [BC]

■ RECOMMENDED ACTIONS TODAY

1[P1] Immediately audit and remove jscrambler npm package version 8.14.0 from all environments and replace with a clean version to mitigate the [CVE-TBD] malicious preinstall hook.
2[P1] Apply the latest Zimbra updates immediately to secure the Classic Web Client against the [CVE-TBD] stored XSS vulnerability.
3[P2] Update Wireshark installations to version 4.6.7 to patch the 12 identified vulnerabilities [CVE-TBD].
4[P2] Implement strict validation and sanitization of image files (PNGs) reviewed by AI coding agents (like CodeRabbit and Bugbot) to prevent 'Ghostcommit' prompt injection exploits.
5[P3] Audit GitHub API access logs for anomalous reconnaissance activity and restrict public visibility of sensitive organization repositories and member lists.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 13 Jul | RedHook Android Malware Abuses Wireless ADB Shell Older → [SecurityIntel] 11 Jul | Progress Urges Immediate ShareFile Server Shutdown
Powered by Buttondown, the easiest way to start and grow your newsletter.