jscrambler 8.14.0 npm 패키지가 해킹되어 악성코드가 배포됐다.
jscrambler npm 패키지의 8.14.0 버전이 해킹당해, 설치 시 정보 유출 악성코드가 실행되는 문제가 발생했다. 이 버전은 사전 설치 후크를 통해 Windows, macOS, Linux용 바이너리를 설치하도록 설계되었다. Socket은 이 해킹 버전을 발표 6분 만에 탐지했다.
The jscrambler 8.14.0 npm package was compromised, dropping malware during installation.
The jscrambler npm package version 8.14.0 has been compromised, running an infostealer upon installation. This malicious version utilizes a preinstall hook that drops and executes a native binary for Windows, macOS, and Linux. Socket flagged the compromised release just six minutes after it was published.