Hackers Compromise Jscrambler npm Package with Infostealer Malware

Hackers compromise the Jscrambler npm package, injecting information-stealing malware into versions 8.14, 8.16, 8.17, and 8.20. The malicious package executes during the preinstall hook and receives approximately 1,479 downloads within a two-hour window before Jscrambler deprecates it and releases a safe version. The company confirms the incident remains limited to the npm package and does not impact other Jscrambler products.

Security firm Socket detects and analyzes the compromise, revealing that the infostealer targets a broad range of sensitive data. The malware goes after source code, developer credentials, cloud secrets from AWS, Azure, and GCP, as well as AI coding tool configurations from Claude, Cursor, and VS Code. It also harvests cryptocurrency wallets, browser credentials, and messaging app data from Slack, Discord, and Telegram.

The malware employs ChaCha20-Poly1305 encryption for string obfuscation, making reverse engineering significantly more difficult for analysts. Jscrambler reports that the attack becomes possible due to compromised npm publishing credentials. The vendor deprecates four additional packages that depend on the affected release and replaces them with clean versions, urging all users to update immediately.

Read More at the original source →