Malicious jscrambler npm version 8.14.0 dropped a Rust infostealer that stole credentials and crypto wallet data during installation.
Attackers are exploiting automated CI build processes by embedding credential-harvesting code into fake updates of widely-used open source packages.
Sign in to your account
Remember me