Jscrambler 8.14.0 malicious preinstall infostealer release
Malware Activity
Summary
Hide ▲
Show ▼
The jscrambler 8.14.0 npm release now ships a malicious preinstall hook that runs a Rust infostealer during install, putting developer and CI secrets at risk on Windows, macOS, and Linux. The package executes without any import or CLI call, so a routine dependency install is enough to trigger theft. The payload targets cloud credentials, browser sessions, wallets, password-manager data, and AI-tool API keys. The release was later replaced by a clean 8.15.0, but any system that already installed 8.14.0 may have exposed secrets.
Related Happenings
Compromised @asyncapi npm packages distributing the Miasma loader
Malware Activity
H score29
First: 15.07.2026 12:16
Last: 15.07.2026 12:16
Sources 1
About this happening:
Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....
Compromised @asyncapi npm packages distributing the Miasma loader
Malware ActivityAbout this happening: Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....
Jscrambler hit by network compromise
Incident
H score15
First: 13.07.2026 22:44
Last: 13.07.2026 22:44
Sources 1
How related:
“Today, we identified the unauthorized publication of a malicious version of our jscrambler npm package, which is used with our Code Integrity product,” Jscrambler says in a warning on Saturday.
About this happening:
The Jscrambler npm package suffered an unauthorized publication of a malicious version that exposed developers to infostealer theft risk. The bad release stayed li...
Jscrambler hit by network compromise
IncidentHow related: “Today, we identified the unauthorized publication of a malicious version of our jscrambler npm package, which is used with our Code Integrity product,” Jscrambler says in a warning on Saturday.
About this happening: The Jscrambler npm package suffered an unauthorized publication of a malicious version that exposed developers to infostealer theft risk. The bad release stayed li...
Rollup polyfill npm package malware activity for remote access and data theft
Malware Activity
H score16
First: 03.07.2026 19:07
Last: 03.07.2026 19:07
Sources 1
About this happening:
Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...
Rollup polyfill npm package malware activity for remote access and data theft
Malware ActivityAbout this happening: Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...
Hijacked npm and Go packages deploying Python infostealer via VS Code auto-run tasks
Malware Activity
H score30
First: 29.06.2026 08:36
Last: 29.06.2026 08:36
Sources 1
About this happening:
Hijacked npm and Go packages now deliver a Python infostealer through a hidden VS Code auto-run task, putting developer machines and credentials at risk across W...
Hijacked npm and Go packages deploying Python infostealer via VS Code auto-run tasks
Malware ActivityAbout this happening: Hijacked npm and Go packages now deliver a Python infostealer through a hidden VS Code auto-run task, putting developer machines and credentials at risk across W...
Mastra @mastra/* npm packages hit by network compromise
Incident
H score47
First: 17.06.2026 10:38
Last: 17.06.2026 10:38
Sources 1
About this happening:
Mastra @mastra/* npm packages were compromised in a software supply chain attack that spread through the namespace on 2026-06-17. Microsoft now attributes the acti...
Mastra @mastra/* npm packages hit by network compromise
IncidentAbout this happening: Mastra @mastra/* npm packages were compromised in a software supply chain attack that spread through the namespace on 2026-06-17. Microsoft now attributes the acti...
Latest development: 20.06.2026 17:09
Microsoft attributed the Mastra AI supply chain attack to Sapphire Sleet, also known as BlueNoroff, and said the attackers compromised the npm maintainer account ehindero, which had publishing privileges across the Mastra package environment. The June 19 update said more than 140 packages in the @mastra scope were modified to inject easy-day-js.
Timeline
-
11.07.2026 20:59 3 articles · 13d ago
jscrambler 8.14.0 ships a malicious preinstall hook
Initial DisclosureVersion 8.14.0 of the jscrambler npm package is published with a malicious preinstall hook that silently drops and runs a native infostealer during installation on Windows, macOS, and Linux, so a routine dependency install is enough to execute the payload.
Show sources
- Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install — thehackernews.com — 11.07.2026 20:59
- Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install — thehackernews.com — 11.07.2026 20:59
- Hackers backdoor Jscrambler npm package with infostealer malware — www.bleepingcomputer.com — 13.07.2026 22:44
-
11.07.2026 20:59 1 articles · 13d ago
jscrambler 8.14.0 bundles hidden native payloads in dist/
Technical Analysis UpdateThe published package adds dist/setup.js and dist/intro.js; setup.js picks the host operating system, writes the matching binary to the system temp directory under a random name, marks it executable, and launches it detached with hidden output, while intro.js is a roughly 7.8MB container packing three gzip-compressed native binaries for Linux, Windows, and macOS. StepSecurity and SafeDep find no matching commit, tag, or pull request for 8.14.0 in the GitHub repository.
Show sources
- Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install — thehackernews.com — 11.07.2026 20:59
-
11.07.2026 20:59 1 articles · 13d ago
jscrambler 8.14.0 targets cloud keys, wallets, and AI tool secrets
Victim Impact UpdateThe Rust infostealer is built to sweep a developer machine for secrets and ship them over TLS, pulling cloud credentials from AWS, Azure, and Google Cloud, browser passwords and cookies, wallet and seed-phrase data from MetaMask, Phantom, Exodus, and Bitwarden, and sessions from Discord, Slack, Telegram, and Steam. It also goes after config files for Claude Desktop, Cursor, Windsurf, VS Code, and Zed, where API keys and Model Context Protocol server credentials tend to live.
Show sources
- Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install — thehackernews.com — 11.07.2026 20:59
-
11.07.2026 20:59 1 articles · 13d ago
Socket and StepSecurity expose jscrambler 8.14.0 command-and-control traffic
Detection Ioc UpdateSocket flags the release six minutes after publication, and StepSecurity runtime monitoring catches the dropped binary reaching two hard-coded attacker IPs, 37.27.122[.]124 and 57.128.246[.]79, plus Tor infrastructure including check.torproject[.]org and archive.torproject[.]org. Those are the first network indicators published for the campaign.
Show sources
- Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install — thehackernews.com — 11.07.2026 20:59