jscrambler npm Package Compromised in Supply Chain Attack
Reported 11 Jul 2026 by otx · Severity: medium
A malicious release of the jscrambler npm package (version 8.14.0) was published on July 11, 2026, introducing hidden native binaries that execute automatically during installation. The compromised package added an undocumented preinstall hook executing dist/setup.js, which deplo