CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2367

As cited

Copy frozen at (site build).

threat intel

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

Version 8.14.0 of the jscrambler npm package contained a malicious preinstall hook that silently deployed a Rust-based infostealer on Windows, macOS, and Linux systems during installation. The package required no manual import or command line invocation to execute the malware. Socket security detected the compromised release approximately six minutes after its publication on July 11, 2026.

Why it matters: Developers and organizations using jscrambler are at immediate risk of information theft from their build environments; this requires urgent action to audit installations, identify compromised systems, and upgrade to a patched version.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

Version 8.14.0 of the jscrambler npm package contained a malicious preinstall hook that silently deployed a Rust-based infostealer on Windows, macOS, and Linux systems during installation. The package required no manual import or command line invocation to execute the malware. Socket security detected the compromised release approximately six minutes after its publication on July 11, 2026.

Why it matters: Developers and organizations using jscrambler are at immediate risk of information theft from their build environments; this requires urgent action to audit installations, identify compromised systems, and upgrade to a patched version.

VendorsMicrosoftApple
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary