On 11 July 2026, an attacker published several malicious versions of our public jscrambler npm package, the command-line tool used with our Code Integrity product. The attacker had gained write…
When OWASP surveyed 225 security practitioners for the 2025 Top 10 update, something unusual happened. Software Supply Chain Failures didn’t just make the list — it received 106 first-place votes…
Today marks one of the most essential milestones in Jscrambler’s history — and in the evolution of client-side security.We’re proud to announce that the Jscrambler PCI DSS Solution is the…
Originally posted in January 2025In light of the upcoming PCI DSS future-dated requirements deadline (March 31st, 2025), many companies are evaluating tools and solutions to help them comply with the…
On September 8th, 2025, Aikido reported a major supply chain attack affecting dozens of npm packages, including the hugely popular chalk and debug. In total, the compromised packages represent 2.6…
with David Alves and Pedro MarruchoThis research documents Jscrambler’s investigation into a stealthy web skimming campaign that infiltrated multiple Caritas Spain websites of Caritas Internationalis, a confederation of over 160…
with David Alves and Pedro MarruchoResearch Update 4/4/25 — Given some misrepresentations of the research described below, Jscrambler clarifies that it has not found any security issues with Stripe’s API…
At Jscrambler, innovation often starts with a simple conversation, and the story of our latest product, Iframe Integrity, is no different.It was October 2023, and I was attending the PCI…
with David Alves and Pedro MarruchoWe just uncovered a new batch of web skimmer infections affecting multiple websites, including casio.co.uk. So far, we have confirmed 17 victim websites, though this…
The PCI SSC announced a new Self-assessment Questionnaire A (SAQ A) version today. This update removes the new requirements introduced in PCI DSS v4 designed to combat e-skimming attacks (6.4.3…
with Pedro Marrucho and David AlvesA few weeks ago, while consulting skimming threat intel sources Jscrambler researchers stumbled across a new skimming campaign that, at first glance, stood out because…
This article was originally published on LinkedIn, on July 20th 2024. It’s been updated and reposted here, having incorporated information from the RCA report that was released by CrowdStrike.The now…
Starting OSWASP Lisboa, Portugal, is about giving back to the community. It has been almost twelve years since I first attended an OWASP event, the OWASP Summit 2011 in Portugal,…
What are the facts and the fiction behind Content Security Policy (CSP) and Magecart web skimmers?With e-commerce displaying no signs of slowing down since the start of the COVID-19 pandemic,…
In this tutorial, we explore the importance of protecting client-side application code at runtime and guide you through implementing it in your GitLab instance using the integration with Jscrambler.Development teams…
We will walk you through the risks of code dependencies when it comes to web supply chain attacks.As the demand for faster product development continues to grow, developers increasingly rely…
Today, we give you insights from a Crypto Wallet Phishing Attack.How did scammers use the source code to perpetrate a phishing attack against the cryptocurrency wallet Celsius?Celsius Email System BreachIn…
Memory protection is an extra line of defense against Spectre attacks. In this blog article, we explore why development teams need to deploy application-level mitigation measures.Even five years after the…
Hybrid mobile apps have become business assets. Perhaps you’ve heard the phrase “every company is an app company” before.Mobile apps have effectively transformed whole industries like transportation, media, retail, and…
Magecart groups have made many successful attacks on high-profile companies over the past years.In a Magecart attack, attackers covertly inject credit card skimming code into the checkout pages of e-commerce…
Close security gaps. Stay ahead of attackers and cybercriminals with source code protection.The Department of Justice and the Federal Trade Commission have been issuing more scam alerts since the pandemic…
The cybersecurity attacks on the likes of British Airways, Macy’s, and Forbes, amongst others, have been widely reported.They all had in common the fact that they were targeted by Magecart.…
Prevent Magecart refers to overcoming possible cyberattacks involving digital credit card theft by skimming online payment forms.Gaining mainstream media attention over the last year or so, their most recent high-profile…
Web supply chain attacks are a real security threat for which the enterprise is vastly unprepared.The security threats of relying on third-party code are mostly known within the scope of…
If someone at your company were to tell you that a critical database was left unprotected for the past six months, exposing the data of millions of your customers, you’d…
The recent incident with the event-stream JavaScript library has several people questioning the security of using open-source components. By falling under (legitimate) control of a developer with malicious intents, the…
This weekend, the UK’s Information Commissioner’s Office website – ICO was caught serving the CoinHive crypto miner to its users. CoinHive crypto miner is a JavaScript that can be installed…
“Companies of all shapes and sizes rely on a webpage that anchors them to the online world.Webpages represent the face of the majority of businesses and provide a first glimpse…
“JavaScript is ubiquitous. Everywhere you look, something has been created, at least in part, using JavaScript. JavaScript is so easy to learn and use, as there is a wide availability…
We have released our latest version, Jscrambler 4.0!It is a breakthrough for JavaScript Security. You will notice many improvements, from our interface to our transformations, to ensure the integrity of…
Bring your GitLab down to see how quickly you can annoy your developers. If you did that already, you know how sensitive your built environment is, and you should do…
If you work in AppSec, you already know about the paramount importance of the work being developed by the OWASP. Through the years we have benefited in countless ways, through…
Good news for the Node.js aficionados! Jscrambler now officially supports protecting the source of Node.js apps. If you have been paying attention, Node.js has undoubtedly risen.Perhaps you are already using…