Hijacked npm Package Drops Stealthy Info-Stealing Malware
cyb3rops · x · 2026-07-13
JFrog Security disclosed that the official jscrambler npm package was hijacked. The compromised version 8.14.0 executed a malicious script during preinstall, dropping a hidden Rust binary disguised as a .js file across Windows, macOS, and Linux.\n\nDescribed as a highly evasive credential and crypto wallet stealer, the payload includes anti-analysis tools and kernel-level eBPF monitoring. JFrog warns that anyone who installed this version should immediately assume system compromise and rotate all credentials.
Related event: NPM Supply Chain Attack Hits AI Coding Tools via Jscrambler(3 posts)→
More from Infra
- SkyPilot emerges from stealth with over $20M to tackle fragmented AI compute — skypilot_org · 2026-07-22
- Why a 1GW Chinese AI data center may be plausible after all — teortaxesTex · 2026-07-22
- China’s AI arms race is increasingly defined by chips, data centers, and open models — BenBajarin · 2026-07-22
- Agent search bottlenecks are now about variance, not raw latency — rohanpaul_ai · 2026-07-22
- Gavin Baker argues Nvidia may be one of open source AI’s biggest supporters — GavinSBaker · 2026-07-22
- AI Power Demand Exposes US Energy Gap, Urging Shift from Scarcity to Abundance — bradneuberg · 2026-07-22