
The deception in the npm supply chain: so jscrambler 8.14.0 deployed an infostealer in seconds
The npm package jscrambler @ 8.14.0 published on July 11, 2026, it contained a malicious pre-installation hook that, with just running npm install, deployed and executed a native …







