NPM Supply Chain Attack Hits AI Coding Tools via Jscrambler
The official jscrambler NPM package was compromised to deploy Rust-based info-stealing malware. The attack targeted crypto wallets, AI coding tools, and cloud credentials, with later variants bypassing install scripts.
2026-07-13 ~ 2026-07-13 · 3 related posts
- Hijacked npm Package Drops Stealthy Info-Stealing Malware — cyb3rops · 2026-07-13
- Jscrambler NPM Attack Targets AI Tools — gastao_s_s · 2026-07-13
- NPM Package Poisoning Hits AI Coding Tools — TechNadu · 2026-07-13