Müzakirə

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

Başladan The Hacker News · 11 iyl 2026 21:50 · 23 Baxış · 0 Cavablar
Mövzunu Açan #0
Version 8.14.0 of the jscrambler npm package shipped with a malicious preinstall hook that silently drops and runs a native infostealer during installation, one build each for Windows, macOS, and Linux.

Published on July 11, 2026, it needs no import and no CLI call. Installing 8.14.0 is enough to run it.

Socket flagged the release six minutes after it was

Okumaya devam et...

Cavab vermək üçün daxil olmalısınız.

0 sitat seçildi