Hackers compromise the Jscrambler npm package, injecting information-stealing malware into versions 8.14, 8.16, 8.17, and 8.20. The malicious package executes during the preinstall hook and receives approximately 1,479 downloads within a two-hour window before Jscrambler deprecates it and releases a safe version. The company confirms