Official `jscrambler` npm package compromised - 5 malicious releases drop a cross-platform Rust infostealer (Chrome/Brave/Edge/Chromium profiles, Bitwarden vault, Steam sessions, cloud metadata, MetaMask/Phantom/Exodus wallets)
On 2026-07-11 15:12 UTC the official jscrambler npm package was hijacked via the jscrambler_ maintainer account. Five malicious releases (8.14.0, 8.16.0, 8.17.0, 8.18.0, 8.20.0) shipped a Rust infostealer that harvests Chromium browser profiles, the Bitwarden vault, Steam sessions, AWS/Azure/GCP credentials, and MetaMask/Phantom/Exodus wallet seeds.
Versions named here: 8.14.0, 8.16.0, 8.17.0, 8.18.0, 8.20.0