Compromised jscrambler npm Package Installs Rust-Based Infostealer
The jscrambler npm package version 8.14.0 was compromised, causing a Rust-based information-stealing malware to be dropped during installation. This supply chain attack targets developers who install the package, potentially exposing credentials and sensitive data. The incident underscores the persistent security risks in the open-source software supply chain.