bleeping-computer · Crawled Jul 13, 2026

Hackers backdoor Jscrambler npm package with infostealer malware

2 IoCs
Read original article ↗

AI Summary

Hackers compromised the npm publishing credentials of Jscrambler and published malicious versions of its npm package (8.14, 8.16, 8.17, 8.20), which were downloaded nearly 1,500 times. The backdoored package executed an infostealer during the 'preinstall' hook, targeting source code, credentials, cloud secrets, cryptocurrency wallets, and browser data. The malware used ChaCha20-Poly1305 encryption for obfuscation, and Jscrambler has since deprecated the affected versions and enhanced its publishing pipeline security.

AI-extracted · verify before operational use

Indicators of Compromise 2 extracted

Type Value Detail
Package jscrambler Details →
Filename preinstall Details →