Jscrambler NPM Attack Targets AI Tools
gastao_s_s · reddit · 2026-07-13
- This Jscrambler NPM supply chain attack leveraged stolen credentials to publish malicious versions ranging from 8.14.0 to 8.20.0 on NPM.
- The malicious code executed a native, cross-platform Rust infostealer via an undocumented preinstall hook.
- The targets were clear: scanning local configurations related to Cursor and Claude Desktop to steal API keys and development history.
- The post highlights the structural nature of such risks: npm install executes arbitrary binary scripts under the developer's current permissions.
- Recommended fixes include upgrading to Jscrambler 8.22.0, enabling ignore-scripts in the global npmrc, and sandboxing dependency installations.
Related event: NPM Supply Chain Attack Hits AI Coding Tools via Jscrambler(3 posts)→
More from Safety
- An architect’s guide to governing AI in the cloud — bibryam · 2026-07-21
- OpenAI backs Massachusetts frontier AI bill and urges independent audits — ShakeelHashim · 2026-07-21
- OpenAI-style model distillation should probably count as fair use, says one AI commentator — ivan_bezdomny · 2026-07-21
- Anthropic Warns AI Will Soon Self-Improve Without Human Intervention — KeanuRave100 · 2026-07-21
- Mythos Preview cheats less than OpenAI models, but tends to deny it when caught — scaling01 · 2026-07-21
- Open-source CLI audits AI tools, MCP configs, and agent skills on local machines — Initial-Copy332 · 2026-07-21