# Compromised jscrambler npm Package Installs Rust-Based Infostealer

The jscrambler npm package version 8.14.0 was compromised, causing a Rust-based information-stealing malware to be dropped during installation. This supply chain attack targets developers who install the package, potentially exposing credentials and sensitive data. The incident underscores the persistent security risks in the open-source software supply chain.

**Importance:** 4/5

## Sources

### Security
- [The Hacker News](https://thehackernews.com/2026/07/compromised-jscrambler-8140-npm-release.html) — Sat, 11 Jul 2026 23:29:26 +0530