Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

Version 8.14.0 of the jscrambler npm package shipped with a malicious preinstall hook that silently drops and runs a native infostealer during installation, one build each for Windows, macOS, and Linux.

Published on July 11, 2026, it needs no import and no CLI call. Installing 8.14.0 is enough to run it.

Socket flagged the release six minutes after it was

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

The AI Aesthetic

The AI Aesthetic Source: Hacker News

Attack Update: Top 5 Attack-IPs auf doode.info โ€“ 08.09.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 103.150.218.66 โ€” 2919 requests (recent log) 89.167.35.212 โ€” 509 requests (recent log) 65.109.35.209 โ€” 443 requests (recent

The Worst Spam Emails: Inside iLands’ AI Agent Hustle

The Worst Spam Emails: Inside iLands’ AI Agent Hustle Source: Hacker News