As cited
Copy frozen at (site build).
threat intel
Hackers backdoor Jscrambler npm package with infostealer malware
A malicious version of the Jscrambler npm package was published containing infostealer malware and downloaded approximately 1,500 times before discovery. Jscrambler, a client-side web security company, disclosed the compromise of its package distribution on npm.
Why it matters: Developers who downloaded the compromised Jscrambler npm package between the malicious release and its removal face exposure to infostealer malware; immediate verification of installed versions and audit of any systems that ran the package is critical.
- Source published
- First seen by Cybersecurity Tracker