<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Jscrambler NPM Packages Hit by Supply Chain Attack, Downloaded Nearly 1,500 Times Before Fix

Jscrambler's NPM package was hit by a supply chain attack; update to version 8.22 to protect your credentials and sensitive data.
Content Team

A supply chain attack hit Jscrambler's popular NPM package on July 11, after a threat actor used compromised publishing credentials to push malicious versions containing hidden malware. Versions 8.16 through 8.20 were affected, along with several dependent packages including jscrambler-webpack-plugin and gulp-jscrambler. The tainted versions were downloaded 1,479 times before being deprecated.

The malware, written in Rust, steals credentials, crypto wallet seed phrases, browser data, and cloud API keys — then exfiltrates everything over encrypted TLS connections. Jscrambler has revoked all credentials and released clean version 8.22. If you installed any affected versions, remove them immediately, scan for malware, and rotate all secrets and API keys.

Source: SecurityWeek

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo