<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Jscrambler NPM Packages Hit by Supply Chain Attack, Downloaded Nearly 1,500 Times Before Fix

Jscrambler's NPM package was hit by a supply chain attack; update to version 8.22 to protect your credentials and sensitive data.
Content Team

A supply chain attack hit Jscrambler's popular NPM package on July 11, after a threat actor used a compromised publishing credential to push malicious versions containing hidden malware. Jscrambler versions 8.16, 8.17, 8.18 and 8.20 were affected — 8.19 was not — along with jscrambler-webpack-plugin 8.6.2, gulp-jscrambler 8.6.2, grunt-jscrambler 8.5.2 and jscrambler-metro-plugin 9.0.2. The tainted versions were downloaded 1,479 times before being deprecated.

The malware, written in Rust, steals credentials, crypto wallet seed phrases, browser data and cloud API keys — and reaches further than most, pulling in AI coding assistant and MCP configurations, OS keyrings, messaging apps and Steam sessions. It exfiltrates everything over TLS and tries stolen credentials against cloud APIs.

Jscrambler has deprecated the malicious versions and released clean version 8.22. If you installed any affected version, remove it immediately, scan for malware, and rotate all secrets and API keys.

Source: SecurityWeek

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo