Product
jscrambler
- First Reported
- Jul 11, 2026
- Latest Reported
- Jul 11, 2026
Reported Context (1)
- A compromised release of the popular jscrambler npm package introduced hidden native binaries that execute automatically during npm install, exposing users to a supply chain attack before any application code runs. Compromised Jscrambler npm Releases Deliver Cross-Platform Infostealer
MITRE ATT&CK (19)
Vendors (1)
Products (36)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.