> Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
[DATE: 11/07/2026 17:59]
[LANGUAGE: EN]
The jscrambler npm package was compromised, and simply installing its 8.14.0 release runs an infostealer on your machine. Published on July 11, 2026, the malicious version carries a preinstall hook that drops and executes a native binary, one build each for Windows, macOS, and Linux.
Socket flagged the release six minutes after it was published. If you or one of your