Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

A major security flaw was discovered in the jscrambler 8.14.0 npm package, which secretly installs a dangerous infostealer during its setup process. This compromised release includes malicious code that runs automatically upon installation without requiring any additional commands. The infostealer is built for Windows, macOS, and Linux, highlighting a severe risk for developers who update to this version. The threat was identified just six minutes after the package was published, underscoring the urgency for users to avoid this release and instead revert to a safe version.

Original Source

Read the full article at Thehackernews →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.