Post #3782325
2026-07-13 10:00 UTC
Supply chain reminder from Socket: five malicious versions of the jscrambler npm package shipped a Rust infostealer via a preinstall hook.
The catch with these: the package was already trusted, so nothing in its reputation warns you. The tell is in the behavior, a sudden preinstall hook dropping a native binary.
https://socket.dev/blog/jscrambler-supply-chain-attack
#blueteam #threatintel #infosec
Replies (0)
No replies.