Which jscrambler versions were affected, and which are safe?
Malicious versions were jscrambler 8.14.0, 8.16.0, 8.17.0, 8.18.0, and 8.20.0, plus jscrambler-webpack-plugin 8.6.2, gulp-jscrambler 8.6.2, grunt-jscrambler 8.5.2, and jscrambler-metro-plugin 9.0.2. Clean releases are 8.22.0, 8.6.3, 8.6.3, 8.5.3, and 9.0.3 respectively — Rescana recommends pinning explicitly rather than trusting an automatic update.
Answered in
Malware Hid Inside a Popular Obfuscation Tool — and Went Hunting for Your AI Coding Agent's CredentialsStolen npm credentials let attackers slip native-binary malware into jscrambler, hunting for Claude Desktop, Cursor, and Windsurf credentials.
Read the full analysisOther questions this article answers
More development best practices questions
- Why is a large-scale test framework migration usually so slow to do by hand?
- Why did retry loops with error feedback outperform carefully engineered prompts?
- When does a migration pipeline need rich prompt context instead of just retries?
- How do you migrate the last 3% of files that automation can't fully finish?
- Does this approach only work for test framework migrations?
- What is Project Polaris and how does it relate to GitHub Copilot?
- What architecture does Project Polaris use?
- How does Project Polaris perform compared to GPT-4 Turbo on coding benchmarks?
Every answer on Crashtech is written by the editor of the article it comes from — never auto-summarised. Browse all answers or the Development Best Practices beat.