---
answer: direct
beat: dev-practices
source: 1 article · updated: July 11, 2026
---

Which jscrambler versions were affected, and which are safe?

Malicious versions were jscrambler 8.14.0, 8.16.0, 8.17.0, 8.18.0, and 8.20.0, plus jscrambler-webpack-plugin 8.6.2, gulp-jscrambler 8.6.2, grunt-jscrambler 8.5.2, and jscrambler-metro-plugin 9.0.2. Clean releases are 8.22.0, 8.6.3, 8.6.3, 8.5.3, and 9.0.3 respectively — Rescana recommends pinning explicitly rather than trusting an automatic update.

Answered in

Malware Hid Inside a Popular Obfuscation Tool — and Went Hunting for Your AI Coding Agent's Credentials

Stolen npm credentials let attackers slip native-binary malware into jscrambler, hunting for Claude Desktop, Cursor, and Windsurf credentials.

Crashtech Editorial July 11, 2026 Development Best Practices

Read the full analysis

Other questions this article answers

More development best practices questions

Every answer on Crashtech is written by the editor of the article it comes from — never auto-summarised. Browse all answers or the Development Best Practices beat.