Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

2026-07-13T01:24:09Zc9a67d8c7c1b169b9a7205d4aee9b082406e397a0e343264f98e192bfbfd0a2f
backdoorbootloadercryptocurrency-theftfirmwaregithub-compromisegrpchardware-attackincident-responseinfostealermalicious-install-scriptsmodbeaconnpmransomwareremote-code-executionsharefilestorage-zone-controllersupply-chaintangemu-bootunpatched-vulnerabilitywallet-securityxquicxr-ingxsszimbra

What happened

This feed describes multiple high-risk supply-chain compromises, critical vulnerabilities, and active espionage/malware campaigns. Key incidents: the jscrambler npm package (v8.14.0) was hijacked and its preinstall hook drops and executes a native Rust infostealer on Windows, macOS, and Linux; Injective Labs' GitHub repo was abused to publish @injectivelabs/sdk-ts@1.20.21 that steals crypto wallet keys/seed phrases; Zimbra Classic Web Client has a critical stored XSS allowing arbitrary script execution in user sessions (no CVE yet); Progress/ShareFile advised customers to shut down StorageZone

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
c9a67d8c7c1b169b9a7205d4aee9b082406e397a0e343264f98e192bfbfd0a2f
Enrichment time
2026-07-13T01:24:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.