A malicious actor compromised the Jscrambler npm package and published several trojanized versions that included a hidden, cross-platform credential-stealing payload. The attack targeted developers, build pipelines, and CI/CD systems, where npm installations could access source code, cloud credentials, deployment tokens,…
The post Jscrambler npm Supply Chain Attack Steals Cloud Credentials and Crypto Wallet Secrets appeared first on IT Security News.
SOCIAL SHARE CARD GENERATOR