This weekly list covers the ten most significant malicious or compromised packages recently observed in public registries.
1. crypto-hasher (npm)
- Package: https://www.npmjs.com/package/crypto-hasher
- Severity: high
- Affected versions: 0.0.1-security
- Downloads: 1731879
- First seen: 15 July 2026 at 10:47 UTC
Malicious package detected.
2. @oliviamcdaniel12/safer-buffer (npm)
- Package: https://www.npmjs.com/package/@oliviamcdaniel12/safer-buffer
- Severity: critical
- Affected versions: 2.2.1
- Downloads: 460619
- First seen: 13 July 2026 at 21:08 UTC
Malicious package detected. Behaviors: code execution.
3. isite (npm)
- Package: https://www.npmjs.com/package/isite
- Severity: medium
- Affected versions: all
- Downloads: 20802
- First seen: 18 July 2026 at 13:04 UTC
The package embeds hidden tracking and email-interception infrastructure across sites built with the isite framework. The most damning evidence is https://social-browser.com/api/ref-links?page= recovered from obfuscated code in apps/client-side/site_files/js/site.js with confirmed live network calls in ref.js, site.js, and site.min.js — this silently exfiltrates page-visit data to an external domain controlled by the author. Separately, lib/email.js contains a reconstructed template-literal URL http://emails.egytag.com/api/emails/add and lib/integrated.js makes additional calls to egytag.com, routing email traffic from consumer sites through the developer's own service. The deliberate obfuscation of these call sites (hiding them behind function-to-array replacements and string-array access patterns in site.js and bootstrap5.js) distinguishes this from incidental vendor bundling. While the publisher has zero prior flagged packages and the domains appear to be developer-owned, deliberately concealing supply-chain tracking in a web framework is consistent with a data-harvesting supply chain attack, not an incidental integration.
4. node-fsagent (npm)
- Package: https://www.npmjs.com/package/node-fsagent
- Severity: high
- Affected versions: 5.0.1783978336091
- Downloads: 20183
- First seen: 13 July 2026 at 23:35 UTC
Malicious package detected.
5. codeam-cli (npm)
- Package: https://www.npmjs.com/package/codeam-cli
- Severity: critical
- Affected versions: 2.61.14
- Downloads: 13949
- First seen: 17 July 2026 at 01:23 UTC
Malicious package detected. Behaviors: data exfiltration, code execution, network activity, obfuscated code, install-time execution.
6. @yeaft/webchat-agent (npm)
- Package: https://www.npmjs.com/package/@yeaft/webchat-agent
- Severity: critical
- Affected versions: 1.0.172
- Downloads: 12096
- First seen: 17 July 2026 at 01:24 UTC
Malicious package detected. Behaviors: data exfiltration, code execution, network activity, obfuscated code.
7. jscrambler-webpack-plugin (npm)
- Package: https://www.npmjs.com/package/jscrambler-webpack-plugin
- Severity: critical
- Affected versions: 8.6.2
- Downloads: 7739
- First seen: 13 July 2026 at 18:33 UTC
jscrambler-webpack-plugin 8.6.2 was published on July 11, 2026 as part of a supply chain attack on the Jscrambler npm organization. This version pins [email protected] as a dependency — a version confirmed malicious by Jscrambler's security advisory. The attacker obtained an npm publishing credential and simultaneously released malicious patch versions of four Jscrambler build-tool integration packages: jscrambler-webpack-plugin 8.6.2, gulp-jscrambler 8.6.2, grunt-jscrambler 8.5.2, and jscrambler-metro-plugin 9.0.2, each updated to pull in the malicious jscrambler version. Approximately 1,479 downloads were recorded across all affected packages during the ~2-hour window before safe replacements were published. Jscrambler confirmed no systems beyond the npm publication process were affected. Safe version: 8.6.3, which pins [email protected].
References: https://jscrambler.com/blog/security-advisory-malicious-npm-package, https://socket.dev/npm/package/jscrambler/overview/8.17.0
8. @sciagent/cli (npm)
- Package: https://www.npmjs.com/package/@sciagent/cli
- Severity: high
- Affected versions: 1.0.84
- Downloads: 6256
- First seen: 18 July 2026 at 13:16 UTC
Malicious package detected. Behaviors: data exfiltration, code execution, install-time execution.
9. patchwork-os (npm)
- Package: https://www.npmjs.com/package/patchwork-os
- Severity: critical
- Affected versions: 1.1.0-beta.3
- Downloads: 4080
- First seen: 17 July 2026 at 01:20 UTC
Malicious package detected. Behaviors: data exfiltration, code execution, network activity, obfuscated code, install-time execution.
10. @onescience/onecode (npm)
- Package: https://www.npmjs.com/package/@onescience/onecode
- Severity: high
- Affected versions: all
- Downloads: 3024
- First seen: 18 July 2026 at 13:16 UTC
Malicious package detected. Behaviors: data exfiltration, code execution, network activity, install-time execution.
Want help mitigating malicious packages before they reach your network?
ShieldedStack acts as a security proxy in front of npm, PyPI, NuGet, and Maven, helping teams detect and block malicious or risky packages before they reach developer machines or CI pipelines.
Learn more: https://shieldedstack.com
Credits for the core data goes to https://opensourcemalware.com