How a preinstall hook silently ran malware on npm install

On July 11 2026, npm install jscrambler ran a Rust infostealer before the package finished installing. The attack anatomy and what to audit in your pipeline.

Read Original

Related