#jscrambler

3 posts · Last used 9d

Back to Timeline
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jul 17, 2026
#JScrambler shares a transparent postmortem on how attackers used a stolen #npm publishing token to ship #malware via its official npm package. A must-read for anyone serious about software supply chain security: #SoftwareSupplyChainSecurity 👇 https://jscrambler.com/blog/security-incident-postmortem-jscrambler
0
0
0
The New Oil @thenewoil@mastodon.thenewoil.org · Jul 14, 2026
0
0
0
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jul 13, 2026
#NPM: A compromised release of the popular #JScrambler npm package introduced hidden #malware binaries that execute automatically during npm install, exposing users to a supply chain attack before any application code runs: #SoftwareSupplyChainSecurity 👇 https://socket.dev/blog/jscrambler-supply-chain-attack
0
0
0

You've seen all posts