logo

Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

ID: 9fbcaa51-1195-5796-a1fb-d33add755299

STIX ID: report--9fbcaa51-1195-5796-a1fb-d33add755299

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-07-11

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

jscrambler's npm package was compromised and several published releases (notably 8.14.0, 8.16.0, 8.17.0, 8.18.0, 8.20.0) delivered a cross-platform Rust infostealer (IronWorm) via preinstall hooks and later via the package runtime; the payload steals cloud credentials, wallets, password vaults, AI-tool/API keys and other developer secrets, adds persistence (Windows Scheduled Task, macOS LaunchAgent), can load eBPF on Linux, reaches out to hard-coded C2 IPs and Tor, and contains routines to harvest npm tokens and propagate by publishing infected packages. Remediation guidance includes moving off malicious versions (upgrade to 8.22.0), rotating all exposed credentials and tokens, auditing CI/workstations and lockfiles, and blocking the listed C2 endpoints and indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.