Back to feed
Dev.to
Dev.to
7/12/2026
Malicious 'jscrambler' NPM Package Versions Deploy Cross-Platform Infostealer in Sophisticated Supply Chain Attack

Malicious 'jscrambler' NPM Package Versions Deploy Cross-Platform Infostealer in Sophisticated Supply Chain Attack

Short summary

A sophisticated supply chain attack compromised the jscrambler npm package, deploying a Rust-based cross-platform infostealer via malicious versions published with stolen credentials. The malware targeted cloud provider credentials, cryptocurrency wallets, and configuration files for AI coding assistants like Claude Desktop, Cursor, and VS Code. Organizations should audit dependencies, identify compromised versions, and rotate all potentially exposed secrets immediately.

  • Malicious jscrambler npm versions (8.14.0–8.20.0) deployed a Rust infostealer via compromised publishing credentials
  • Malware exfiltrated AWS/Azure/GCP credentials, crypto wallets, and AI coding tool configs (Claude Desktop, Cursor, VS Code)
  • Immediate remediation: audit dependencies, rotate secrets, hunt for intro.js payload and scheduled tasks/LaunchAgents

Generated with AI, which can make mistakes.

Is this a good recommendation for you?

Comments

Failed to load comments. Please try again.

Explore more