Jscrambler NPM Packages Hit by Supply Chain Attack, Downloaded Nearly 1,500 Times Before Fix
Want more insights like this?
A supply chain attack hit Jscrambler's popular NPM package on July 11, after a threat actor used a compromised publishing credential to push malicious versions containing hidden malware. Jscrambler versions 8.16, 8.17, 8.18 and 8.20 were affected — 8.19 was not — along with jscrambler-webpack-plugin 8.6.2, gulp-jscrambler 8.6.2, grunt-jscrambler 8.5.2 and jscrambler-metro-plugin 9.0.2. The tainted versions were downloaded 1,479 times before being deprecated.
The malware, written in Rust, steals credentials, crypto wallet seed phrases, browser data and cloud API keys — and reaches further than most, pulling in AI coding assistant and MCP configurations, OS keyrings, messaging apps and Steam sessions. It exfiltrates everything over TLS and tries stolen credentials against cloud APIs.
Jscrambler has deprecated the malicious versions and released clean version 8.22. If you installed any affected version, remove it immediately, scan for malware, and rotate all secrets and API keys.
Source: SecurityWeek