Hijacked npm Package Drops Stealthy Info-Stealing Malware

cyb3rops · x · 2026-07-13

JFrog Security disclosed that the official jscrambler npm package was hijacked. The compromised version 8.14.0 executed a malicious script during preinstall, dropping a hidden Rust binary disguised as a .js file across Windows, macOS, and Linux.\n\nDescribed as a highly evasive credential and crypto wallet stealer, the payload includes anti-analysis tools and kernel-level eBPF monitoring. JFrog warns that anyone who installed this version should immediately assume system compromise and rotate all credentials.

Related event: NPM Supply Chain Attack Hits AI Coding Tools via Jscrambler(3 posts)→

Original post →

More from Infra

Infra channel →