Jscrambler NPM Packages Hit by Supply Chain Attack, Downloaded Nearly 1,500 Times Before Fix
Want more insights like this?
A supply chain attack hit Jscrambler's popular NPM package on July 11, after a threat actor used compromised publishing credentials to push malicious versions containing hidden malware. Versions 8.16 through 8.20 were affected, along with several dependent packages including jscrambler-webpack-plugin and gulp-jscrambler. The tainted versions were downloaded 1,479 times before being deprecated.
The malware, written in Rust, steals credentials, crypto wallet seed phrases, browser data, and cloud API keys — then exfiltrates everything over encrypted TLS connections. Jscrambler has revoked all credentials and released clean version 8.22. If you installed any affected versions, remove them immediately, scan for malware, and rotate all secrets and API keys.
Source: SecurityWeek