Dev.to
7/12/2026

Malicious 'jscrambler' NPM Package Versions Deploy Cross-Platform Infostealer in Sophisticated Supply Chain Attack
Short summary
A sophisticated supply chain attack compromised the jscrambler npm package, deploying a Rust-based cross-platform infostealer via malicious versions published with stolen credentials. The malware targeted cloud provider credentials, cryptocurrency wallets, and configuration files for AI coding assistants like Claude Desktop, Cursor, and VS Code. Organizations should audit dependencies, identify compromised versions, and rotate all potentially exposed secrets immediately.
- •Malicious jscrambler npm versions (8.14.0–8.20.0) deployed a Rust infostealer via compromised publishing credentials
- •Malware exfiltrated AWS/Azure/GCP credentials, crypto wallets, and AI coding tool configs (Claude Desktop, Cursor, VS Code)
- •Immediate remediation: audit dependencies, rotate secrets, hunt for intro.js payload and scheduled tasks/LaunchAgents
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



