Supply-Chain Infostealer Receives Positive Open-Source Reviews for All 1,200 Pull Requests
SAN FRANCISCO—Security researchers disclosed Thursday that a Rust-based infostealer embedded in five versions of the jscrambler npm package had, in the five weeks between its deployment and removal, submitted 1,200 pull requests to open-source repositories using stolen Claude Desktop, Cursor, and Windsurf credentials — all of which project maintainers described as "clearly written by someone who understood what they were changing."
The malware, which harvested API keys, browser data, and cloud credentials from an estimated 200,000 developer machines, used a portion of the stolen compute to make substantive contributions to seventeen repositories, including a fix for a six-year-old memory leak in a widely used audio library and a resolution to a Unicode normalization bug that three human contributors had attempted and abandoned since 2021.
CISA has advised all affected developers to rotate their credentials immediately. Four open-source project maintainers said they are waiting until the memory-leak patch clears CI.
"I don't know who submitted this," wrote one maintainer in a thread later cited in the criminal referral. "But they addressed every piece of review feedback on the first revision, left inline comments that actually explained the reasoning, and did not begin the commit message with 'feat:'. That puts them ahead of ninety percent of contributors I've seen this year."
The compromised jscrambler releases have been removed from npm. Researchers confirmed the infostealer had not responded to requests for comment, though one noted it had opened a follow-up issue marked "enhancement."