| A compromised release of the official jscrambler npm package (v8.14.0) weaponized the preinstall lifecycle hook to execute a Rust-based infostealer before the package was even used. The payload focused on harvesting developer credentials and local secrets, making both developer workstations and automated build environments potential targets. It was briefly up for a few hours before it was taken down. The article covers the attack chain, IOCs, affected versions, and recommended remediation. v8.22.0 is confirmed to be safe. Update to it asap [link] [comments] |
Intelligence View
⚡ tsecurity.de Intelligence
Official jscrambler npm package v8.14.0 compromised with a malicious preinstall script
A compromised release of the official jscrambler npm package (v8.14.0) weaponized the preinstall lifecycle hook to execute a Rust-based infostealer before the…
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege