Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
News Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
The Hacker News
1 month ago

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

By info@thehackernews.com (The Hacker News)

The jscrambler npm package was compromised, and simply installing its 8.14.0 release runs an infostealer on your machine. Published on July 11, 2026, the malicious version carries a preinstall hook that drops and executes a native binary, one build each for Windows, macOS, and Linux. Socket flagged the release six minutes after it was published. If you or one of your

More from The Hacker News

Leaving Threaticon

This link opens an external site that isn't part of the platform.