Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install
2026-07-13T01:24:09Z•c9a67d8c7c1b169b9a7205d4aee9b082406e397a0e343264f98e192bfbfd0a2f
backdoorbootloadercryptocurrency-theftfirmwaregithub-compromisegrpchardware-attackincident-responseinfostealermalicious-install-scriptsmodbeaconnpmransomwareremote-code-executionsharefilestorage-zone-controllersupply-chaintangemu-bootunpatched-vulnerabilitywallet-securityxquicxr-ingxsszimbra
What happened
This feed describes multiple high-risk supply-chain compromises, critical vulnerabilities, and active espionage/malware campaigns. Key incidents: the jscrambler npm package (v8.14.0) was hijacked and its preinstall hook drops and executes a native Rust infostealer on Windows, macOS, and Linux; Injective Labs' GitHub repo was abused to publish @injectivelabs/sdk-ts@1.20.21 that steals crypto wallet keys/seed phrases; Zimbra Classic Web Client has a critical stored XSS allowing arbitrary script execution in user sessions (no CVE yet); Progress/ShareFile advised customers to shut down StorageZone
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- c9a67d8c7c1b169b9a7205d4aee9b082406e397a0e343264f98e192bfbfd0a2f
- Enrichment time
- 2026-07-13T01:24:09Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.