Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
A critical vulnerability in the npm package jscrambler 8.14.0 has been exploited by attackers, installing a malicious Rust-based infostealer on victims’ systems during installation. The compromised package was available for download from npm’s official registry until July 7, when it was removed after being flagged by users. The vulnerability is particularly concerning due to the … Read more