{"id":517,"date":"2026-07-14T14:00:09","date_gmt":"2026-07-14T08:30:09","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=517"},"modified":"2026-08-18T14:40:43","modified_gmt":"2026-08-18T09:10:43","slug":"compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\/","title":{"rendered":"Compromised jscrambler npm Releases Drop Rust Infostealer During Install and Runtime"},"content":{"rendered":"<p>A software supply chain attack npm users rarely expect has turned a routine dependency installation into a credential-stealing operation. Multiple compromised releases of the official jscrambler npm package introduced malware capable of stealing developer secrets from workstations and build environments.<\/p>\n<p>The attack first appeared in jscrambler 8.14.0, but it was not limited to a single release. The affected versions include 8.14.0, 8.16.0, 8.17.0, 8.18.0, and 8.20.0. Jscrambler later confirmed that the threat actor published the malicious packages using a compromised npm publishing credential.<\/p>\n<p><center>    \t\t<!-- button style scb6aaa006dc095ba618bc1777be3a12f2a -->\r\n    \t\t<style>\r\n    \t\t\t.scb6aaa006dc095ba618bc1777be3a12f2a, a.scb6aaa006dc095ba618bc1777be3a12f2a{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: ;\r\n    \t\t\t}\r\n    \t\t\t.scb6aaa006dc095ba618bc1777be3a12f2a:hover, a.scb6aaa006dc095ba618bc1777be3a12f2a:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #323232;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/uem\/\" class=\"ht-shortcodes-button scb6aaa006dc095ba618bc1777be3a12f2a  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tStrengthen Endpoint Security with Hexnode UEM<\/a>\r\n    \t\t<\/center><\/p>\n<h2>How the compromised package executed malware<\/h2>\n<p>Unlike many malicious packages that require developers to execute a script manually, the compromised jscrambler releases abused normal package installation and runtime behavior. In the earlier malicious versions, including 8.14.0, 8.16.0, and 8.17.0, the package used a preinstall script that executed automatically during npm install. Later compromised versions, including 8.18.0 and 8.20.0, moved the loader logic into the package\u2019s main module, allowing the malware to run when the package was required.<\/p>\n<p>Security researchers found malicious additions inside the package, including <code>dist\/setup.js<\/code>, which acted as the loader in the preinstall-based versions, and <code>dist\/intro.js<\/code>, a disguised binary container that stored compressed native payloads for Windows, macOS, and Linux.<\/p>\n<p>During execution, the loader identified the operating system, extracted the appropriate Rust binary into a randomly named hidden file inside the system temporary directory, marked it executable, and launched it as a detached background process. This meant affected developer workstations and build environments could be compromised during installation or package execution, depending on the malicious version used.<\/p>\n<h2>Why developer secrets are attractive targets<\/h2>\n<p>Modern developer machines contain far more than application source code. They often hold privileged credentials that provide direct access to production environments and cloud infrastructure.<\/p>\n<p>The Rust infostealer searched compromised systems for:<\/p>\n<ul>\n<li>AWS, Microsoft Azure, and Google Cloud credentials<\/li>\n<li>npm and GitHub authentication tokens<\/li>\n<li>Browser-stored passwords and session cookies<\/li>\n<li>Bitwarden vault information<\/li>\n<li>Cryptocurrency wallets<\/li>\n<li>Slack, Discord, Telegram, and Steam sessions<\/li>\n<li>Configuration files used by AI development tools including Claude Desktop, Cursor, Windsurf, VS Code, and Zed<\/li>\n<li>MCP server configuration files and related <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-an-api-key\/\">API keys<\/a><\/li>\n<\/ul>\n<p>These developer secrets allow attackers to move well beyond a single workstation. Stolen credentials can provide access to source repositories, cloud workloads, deployment pipelines, internal services, and production environments, significantly expanding the impact of a single compromised dependency.<\/p>\n<h2>Persistence and advanced capabilities<\/h2>\n<p>The malware was designed to remain active after installation.<\/p>\n<p>Researchers observed operating system-specific persistence mechanisms, including Windows Scheduled Tasks and macOS LaunchAgents. The Linux variant also included eBPF-related capability, indicating a deeper focus on long-term host visibility and persistence than typical credential-stealing malware. Windows and macOS builds additionally incorporated anti-debugging techniques to complicate analysis.<\/p>\n<p>These capabilities demonstrate that this was more than opportunistic npm malware. The attackers built a cross-platform operation specifically targeting software development environments.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode_UEM-Capability-statement-e1783572504474.png?format=webp\" class=\"resource-box__image\" alt=\"Hexnode_UEM-Capability-statement\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode_UEM-Capability-statement-e1783572504474.png?format=webp 698w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode_UEM-Capability-statement-e1783572504474-300x284.png?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode_UEM-Capability-statement-e1783572504474-106x100.png?format=webp 106w\" sizes=\"auto, (max-width: 698px) 100vw, 698px\" title=\"Hexnode_UEM-Capability-statement\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured Resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Hexnode UEM Capability Statement\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Discover Hexnode UEM capabilities for secure, unified endpoint management across your entire IT environment.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/brochures\/hexnode-uem-capability-statement\/'>\n                            Download the brochure\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>How Hexnode helps reduce the impact<\/h2>\n<p>While preventing every software supply-chain compromise is difficult, organizations can significantly reduce their impact through centralized endpoint management, endpoint detection, and identity-based access controls.<\/p>\n<p>Hexnode <a href=\"https:\/\/www.hexnode.com\/blogs\/what-is-unified-endpoint-management-uem\/\">UEM<\/a> helps security teams maintain visibility across managed endpoints through device, compliance, application, and patch reports; enforce required apps, app restrictions, and patch\/update controls; and use remote actions such as lock, wipe, corporate data wipe, and custom scripts.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> supports endpoint threat detection and response by correlating endpoint behavioral signals, enriching alerts with device context, mapping attack chains to <a href=\"https:\/\/www.hexnode.com\/blogs\/mitre-attack-framework\/\">MITRE ATT&amp;CK<\/a>, and enabling response actions such as endpoint isolation, process termination, file quarantine, and IOC hunting across recent process and endpoint event data.<\/p>\n<p>When integrated with Microsoft Entra Conditional Access or Okta Device Trust, Hexnode can help enforce access to protected corporate resources or applications based on device compliance and managed-device trust, subject to supported platforms and IdP configuration. This reduces the blast radius even if an attacker succeeds in stealing credentials from an individual endpoint.<\/p>\n<h2>Final thoughts<\/h2>\n<p>Developers and security teams should remove jscrambler versions from 8.14.0 through 8.20.0 from package lockfiles, dependency manifests, local caches, CI caches, and internal package mirrors. They should upgrade to jscrambler 8.22.0 or later and review package-manager logs, CI\/CD runs, and endpoint telemetry for any installation or execution of the affected releases.<\/p>\n<p>If any affected version ran on a developer workstation or build runner, teams should treat accessible secrets as compromised. This includes cloud credentials, npm and GitHub tokens, browser sessions, password-manager data, AI-tool API keys, MCP credentials, and CI\/CD secrets. Rotate credentials, revoke active sessions, inspect persistence mechanisms, and audit downstream access to repositories, cloud workloads, and deployment pipelines.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Secure Your Build Pipeline<\/h5><p>Protect developer endpoints, detect credential theft, and strengthen software supply chain security with Hexnode UEM and XDR.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Start Your Free Trial! <\/a><\/div><\/div>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What is a supply chain attack in npm?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>A supply chain attack in npm occurs when attackers compromise a legitimate package or dependency so malware is distributed through normal package installation.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What should developers do after installing malicious npm malware?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Immediately remove the affected package, rotate all exposed credentials, audit the affected system, and review CI\/CD pipelines for signs of compromise.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>A software supply chain attack npm users rarely expect has turned a routine dependency installation&#8230;<\/p>\n","protected":false},"author":6,"featured_media":518,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[13,15],"class_list":["post-517","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity-abuse","category-malware","product_category-identity-provider","tab_group-identity-and-phishing"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Jscrambler npm Supply Chain Attack Explained<\/title>\n<meta name=\"description\" content=\"Learn how the jscrambler npm compromise stole developer secrets and how to defend against npm supply chain attacks.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Jscrambler npm Supply Chain Attack Explained\" \/>\n<meta property=\"og:description\" content=\"Learn how the jscrambler npm compromise stole developer secrets and how to defend against npm supply chain attacks.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-14T08:30:09+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-18T09:10:43+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Compromised-jscrambler-npm-Releases-Drop-Rust-Infostealer-During-Install-and-Runtime.png?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Lily Anne\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lily Anne\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\\\/\"},\"author\":{\"name\":\"Lily Anne\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\"},\"headline\":\"Compromised jscrambler npm Releases Drop Rust Infostealer During Install and Runtime\",\"datePublished\":\"2026-07-14T08:30:09+00:00\",\"dateModified\":\"2026-08-18T09:10:43+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\\\/\"},\"wordCount\":861,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Compromised-jscrambler-npm-Releases-Drop-Rust-Infostealer-During-Install-and-Runtime.png?format=webp\",\"articleSection\":[\"Identity Abuse\",\"Malware\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\\\/\",\"name\":\"Jscrambler npm Supply Chain Attack Explained\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Compromised-jscrambler-npm-Releases-Drop-Rust-Infostealer-During-Install-and-Runtime.png?format=webp\",\"datePublished\":\"2026-07-14T08:30:09+00:00\",\"dateModified\":\"2026-08-18T09:10:43+00:00\",\"description\":\"Learn how the jscrambler npm compromise stole developer secrets and how to defend against npm supply chain attacks.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Compromised-jscrambler-npm-Releases-Drop-Rust-Infostealer-During-Install-and-Runtime.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/Compromised-jscrambler-npm-Releases-Drop-Rust-Infostealer-During-Install-and-Runtime.png?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"Compromised-jscrambler-npm-Releases-Drop-Rust-Infostealer-During-Install-and-Runtime\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Compromised jscrambler npm Releases Drop Rust Infostealer During Install and Runtime\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\",\"name\":\"Lily Anne\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"caption\":\"Lily Anne\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/lily-anne\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Jscrambler npm Supply Chain Attack Explained","description":"Learn how the jscrambler npm compromise stole developer secrets and how to defend against npm supply chain attacks.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\/","og_locale":"en_US","og_type":"article","og_title":"Jscrambler npm Supply Chain Attack Explained","og_description":"Learn how the jscrambler npm compromise stole developer secrets and how to defend against npm supply chain attacks.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-07-14T08:30:09+00:00","article_modified_time":"2026-08-18T09:10:43+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Compromised-jscrambler-npm-Releases-Drop-Rust-Infostealer-During-Install-and-Runtime.png?format=webp","type":"image\/png"}],"author":"Lily Anne","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Lily Anne","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\/"},"author":{"name":"Lily Anne","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa"},"headline":"Compromised jscrambler npm Releases Drop Rust Infostealer During Install and Runtime","datePublished":"2026-07-14T08:30:09+00:00","dateModified":"2026-08-18T09:10:43+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\/"},"wordCount":861,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Compromised-jscrambler-npm-Releases-Drop-Rust-Infostealer-During-Install-and-Runtime.png?format=webp","articleSection":["Identity Abuse","Malware"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\/","url":"https:\/\/www.hexnode.com\/threat-watch\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\/","name":"Jscrambler npm Supply Chain Attack Explained","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Compromised-jscrambler-npm-Releases-Drop-Rust-Infostealer-During-Install-and-Runtime.png?format=webp","datePublished":"2026-07-14T08:30:09+00:00","dateModified":"2026-08-18T09:10:43+00:00","description":"Learn how the jscrambler npm compromise stole developer secrets and how to defend against npm supply chain attacks.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Compromised-jscrambler-npm-Releases-Drop-Rust-Infostealer-During-Install-and-Runtime.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Compromised-jscrambler-npm-Releases-Drop-Rust-Infostealer-During-Install-and-Runtime.png?format=webp","width":1340,"height":700,"caption":"Compromised-jscrambler-npm-Releases-Drop-Rust-Infostealer-During-Install-and-Runtime"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/compromised-jscrambler-npm-releases-drop-rust-infostealer-during-install-and-runtime\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Compromised jscrambler npm Releases Drop Rust Infostealer During Install and Runtime"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa","name":"Lily Anne","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","caption":"Lily Anne"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/lily-anne\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/517","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=517"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/517\/revisions"}],"predecessor-version":[{"id":521,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/517\/revisions\/521"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/518"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=517"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=517"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}