INTEL_REPORT
The Hacker News · published 7/11/2026, 5:59:26 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install The jscrambler npm package was compromised, and simply installing its 8.14.0 release runs an infostealer on your machine. Published on July 11, 2026, the malicious version carries a preinstall hook that drops and executes a native binary, one build each for Windows, macOS, and Linux. Socket flagged the release six minutes after it was published. If you or one of your Com…
https://thehackernews.com/2026/07/compromised-jscrambler-8140-npm-release.html
sha256:082c8c782e80704fee24a937956d6d8349add7acbe2ded5ec4ec7b6e53891f58
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| sha256 | fbbcf4d8f98168f78f5c0c47a9ae56d59ec8ac84a7c9ca6b797fedfb8d62d2bd | Open → |
| sha256 | b7ca95d1b23c8e67416a25cedf741de0917c2096bbc9d24649eea7853d054903 | Open → |
| sha256 | c8fd47d36bdf7c825378593ab82ed8c24d1dc52e26b507812393e24e1d5201fd | Open → |