jscrambler npm Backdoored: Rotate Your Credentials Now
The jscrambler npm package was backdoored five times in three hours on July 11, 2026, after a threat actor stole an npm publishing credential. The malicious versions (8.14.0–8.20.0, excluding 8.15.0) …