Supply Chain Attack Found Hiding Infostealer Malware in Jscrambler npm Package
387/69 Wednesday, July 15, 2026 Security researchers have disclosed a supply chain attack affecting the official jscrambler package on npm. Attackers published modified versions of the package containing a Rust-based infostealer, putting developer machines and CI/CD systems that installed the affected package at risk of sensitive data theft. Jscrambler stated that the issue affects package […]
