Digest
CRITICAL

Compromised jscrambler npm Package Drops Rust Infostealer

The jscrambler npm package, version 8.14.0, was compromised to deliver a Rust-based infostealer. Installing this malicious version executes a preinstall hook that drops and runs a native binary tailored for Windows, macOS, or Linux. The compromise was quickly detected, highlighting the ongoing supply chain risks in software development.

← Back to the feed

Trending Tags