Dossier
jscrambler
Coverage of jscrambler in the Nexus archive.
- Hackers backdoor Jscrambler npm package with infostealer malware
A threat actor published a malicious version of the Jscrambler npm package, which was downloaded almost 1,500 times. Jscrambler, a client-side web security company, disclosed the breach.
- Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
The jscrambler 8.14.0 npm package included a malicious preinstall hook that deploys a Rust-based infostealer for Windows, macOS, and Linux during installation. The compromised version was published on July 11, 2026, and automatically executes the malware without requiring additional commands or imports. Security firm Socket detected and flagged the release six minutes after publication.