🚨 Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install Breach — Data Exposed
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install suffered a data breach. Here's what happened, what data was exposed, and what you should do right now.
What Happened
Version 8.14.0 of the jscrambler npm package shipped with a malicious preinstall hook that silently drops and runs a native infostealer during installation, one build each for Windows, macOS, and Linux.
Published on July 11, 2026, it needs no import and no CLI call. Installing 8.14.0 is enough to run it.
Socket flagged the release six minutes after it was
Impact
What You Should Do
If you have an account with Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install, take these steps immediately:
Is Your Website Secure?
Data breaches often exploit weak security configurations — missing Content-Security-Policy headers, misconfigured CORS, exposed API keys. These are exactly the issues ScanMyVibe detects in under 30 seconds.
[Scan your site free →](https://scanmyvibe.co/scan)
Timeline
This article is auto-generated by ScanMyVibe's breach monitoring system. Sources are verified but details may evolve as investigations progress. Last updated: 2026-07-11.
IS YOUR SITE NEXT?
Scan your website for the same vulnerabilities that cause breaches like this one.
SCAN FREE — 150+ CHECKS