Security Briefing | July 12, 2026 - jscrambler npm Package Compromised in Supply Chain Attack, Pakistani Police Portals Targeted in Espionage Campaign, Ghost Accounts Abuse GitHub API for Mass Recon
The jscrambler npm package version 8.14.0 was compromised with a preinstall hook dropping a Rust-based infostealer on Windows, macOS, and Linux, detected by Socket just six minutes after publication. Suspected China and India-aligned threat actors spent over two years compromising Balochistan Police servers, exfiltrating sensitive criminal and citizen records. Separately, ghost accounts are actively abusing the GitHub API to map organizations, repositories, and members in what appears to be coordinated pre-attack reconnaissance.
By EACA Summit Content Team

1. Compromised jscrambler npm Package Drops Rust Infostealer
The jscrambler npm package version 8.14.0 was compromised with a preinstall hook that downloads and executes a Rust-based infostealer on Windows, macOS, and Linux. Socket detected the malicious release within six minutes of publication. Users who installed this version should treat their systems as compromised and rotate credentials immediately.
Verified Facts
- The malicious npm package jscrambler 8.14.0 was published on July 11, 2026
- The package contains a preinstall script that drops and executes a native binary infostealer
- Socket flagged the release six minutes after publication
Evidence
- The Hacker News article dated July 11, 2026
- Socket security alert referenced in article
Impact
This supply chain attack affects any developer or organization that installed the compromised package, potentially leading to credential theft and lateral movement. Immediate audit of npm dependencies is recommended.
Confidence Level: High
Sources The Hacker News
2. Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns

Suspected China and India-aligned threat actors compromised Balochistan Police servers hosting web applications with police and citizen data between February 2024 and April 2026. The campaign targeted multiple Pakistani law enforcement organizations, exfiltrating sensitive criminal and personal records over an extended period.
Verified Facts
- Compromised assets included servers hosting web applications managing police and citizen data
- The campaign involved multiple threat actor groups aligned with China and India
- The activity spanned from February 2024 to April 2026
Evidence
- The Hacker News article dated July 11, 2026
- Cybersecurity research report referenced in article
Impact
Law enforcement agencies globally should review exposure of citizen-facing portals and enforce strict access controls. This incident highlights the risk of geopolitical espionage targeting police databases.
Confidence Level: High
Sources The Hacker News
3. Ghost Accounts Abuse GitHub API in Mass Recon Campaign
Multiple campaigns are using ghost accounts to map GitHub organizations, including repositories and members, via the GitHub API. This reconnaissance activity can precede targeted attacks or supply chain compromises. Organizations should monitor for unusual API access patterns.
Verified Facts
- Ghost accounts are being used to enumerate GitHub organizations and members
- The activity is part of multiple campaigns
- The goal is mass reconnaissance
Evidence
- SecurityWeek article dated July 11, 2026
- GitHub security monitoring referenced in article
Impact
This reconnaissance can enable targeted phishing or supply chain attacks. GitHub organization owners should review API access logs and restrict token permissions.
Confidence Level: High
Sources SecurityWeek
All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.



