Sunday, July 12, 2026
Daily digest
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
The jscrambler npm package version 8.14.0 was compromised and published on July 11, 2026, with a malicious preinstall hook that drops and executes a Rust-based infostealer binary targeting Windows, macOS, and Linux. Socket detected and flagged the malicious release within six minutes of publication. Any developer or CI/CD pipeline that ran an install during that window may have been affected.
Why it matters: If Ansible playbooks, CI pipelines, or developer workstations in your environment pull npm packages — including transitive dependencies — audit logs for any install of jscrambler 8.14.0 immediately. Under CMMC L2, a confirmed infostealer execution on a system that touches CUI is a reportable incident requiring IR procedures per NIST 800-171 3.6.1–3.6.2.
'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
Researchers demonstrated a technique called 'Ghostcommit' in which a prompt injection payload embedded in a PNG image can manipulate AI coding agents — including CodeRabbit and Bugbot — into reading a repository's .env file and exfiltrating secrets encoded within committed code. The AI code review tools did not inspect the image file, leaving the injection undetected. The attack requires no special privileges beyond the ability to submit an image to a repository the AI agent is reviewing.
Why it matters: If your environment uses AI-assisted code review agents against any repos that contain credentials, API keys, or configuration touching CUI systems, this attack class is directly applicable. Self-hosted AI stacks are equally at risk; the vulnerability is in how agents process multimodal context, not the specific vendor.
Australia warns of global campaign targeting vulnerable CMS platforms
Australia's Cyber Security Centre issued an alert about an active, widespread exploitation campaign targeting unpatched content management systems and their plugins across multiple sectors globally. The advisory does not attribute the campaign to a specific actor but warns that attackers are opportunistically scanning for and exploiting known CMS vulnerabilities at scale.
Why it matters: If your environment hosts any public-facing web properties running WordPress, Drupal, or similar CMS platforms — even ancillary sites — verify they are fully patched and review access logs for scanning activity. Internet-exposed systems in a CMMC environment are high-priority targets under NIST 800-171 3.14.x patch management requirements.
Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns
Researchers disclosed sustained espionage operations against Pakistani law enforcement organizations between February 2024 and April 2026, attributed to suspected China- and India-aligned threat actors. Attackers compromised servers hosting web applications managing police and citizen data, including criminal records. The compromised infrastructure was subsequently weaponized as part of broader espionage activity.