This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries.


1. crypto-hasher (npm)

Malicious package detected.


2. @oliviamcdaniel12/safer-buffer (npm)

Malicious package detected. Behaviors: code execution.


3. isite (npm)

The package embeds hidden tracking and email-interception infrastructure across sites built with the isite framework. The most damning evidence is https://social-browser.com/api/ref-links?page= recovered from obfuscated code in apps/client-side/site_files/js/site.js with confirmed live network calls in ref.js, site.js, and site.min.js — this silently exfiltrates page-visit data to an external domain controlled by the author. Separately, lib/email.js contains a reconstructed template-literal URL http://emails.egytag.com/api/emails/add and lib/integrated.js makes additional calls to egytag.com, routing email traffic from consumer sites through the developer's own service. The deliberate obfuscation of these call sites (hiding them behind function-to-array replacements and string-array access patterns in site.js and bootstrap5.js) distinguishes this from incidental vendor bundling. While the publisher has zero prior flagged packages and the domains appear to be developer-owned, deliberately concealing supply-chain tracking in a web framework is consistent with a data-harvesting supply chain attack, not an incidental integration.


4. node-fsagent (npm)

Malicious package detected.


5. codeam-cli (npm)

Malicious package detected. Behaviors: data exfiltration, code execution, network activity, obfuscated code, install-time execution.


6. @yeaft/webchat-agent (npm)

Malicious package detected. Behaviors: data exfiltration, code execution, network activity, obfuscated code.


7. jscrambler-webpack-plugin (npm)

jscrambler-webpack-plugin 8.6.2 was published on July 11, 2026 as part of a supply chain attack on the Jscrambler npm organization. This version pins [email protected] as a dependency — a version confirmed malicious by Jscrambler's security advisory. The attacker obtained an npm publishing credential and simultaneously released malicious patch versions of four Jscrambler build-tool integration packages: jscrambler-webpack-plugin 8.6.2, gulp-jscrambler 8.6.2, grunt-jscrambler 8.5.2, and jscrambler-metro-plugin 9.0.2, each updated to pull in the malicious jscrambler version. Approximately 1,479 downloads were recorded across all affected packages during the ~2-hour window before safe replacements were published. Jscrambler confirmed no systems beyond the npm publication process were affected. Safe version: 8.6.3, which pins [email protected].

References: https://jscrambler.com/blog/security-advisory-malicious-npm-package, https://socket.dev/npm/package/jscrambler/overview/8.17.0


8. @sciagent/cli (npm)

Malicious package detected. Behaviors: data exfiltration, code execution, install-time execution.


9. patchwork-os (npm)

Malicious package detected. Behaviors: data exfiltration, code execution, network activity, obfuscated code, install-time execution.


10. @onescience/onecode (npm)

Malicious package detected. Behaviors: data exfiltration, code execution, network activity, install-time execution.


Want help mitigating malicious packages before they reach your network?

ShieldedStack acts as a security proxy in front of npm, PyPI, NuGet, and Maven, helping teams detect and block malicious or risky packages before they reach developer machines or CI pipelines.

Learn more: https://shieldedstack.com

Credits for the core data goes to https://opensourcemalware.com