DAPSSADAPSSA

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

By DAPSSA AI Desk | 2026-07-12T05:42:02.037Z
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

Overview

The jscrambler npm package was compromised, and simply installing its 8.14.0 release runs an infostealer on your machine. Published on July 11, 2026, the malicious version carries a preinstall hook that drops and executes a native binary, one build each for Windows, macOS, and Linux. Socket flagged the release six minutes after it was published. If you or one of your

Key Developments

This reflects an evolving cybersecurity situation.

Technical Details

Attackers may use automation and vulnerabilities.

Impact & Risks

Potential disruption and data exposure.

Conclusion

Organizations must stay vigilant.

Read more: https://thehackernews.com/2026/07/compromised-jscrambler-8140-npm-release.html

Join the Discussion