"JavaScript library scams" primarily refer to supply chain attacks where malicious code is hidden inside popular software packages to steal data or money. These scams often target developers to gain access to their systems or use the trust of popular libraries to infect millions of end-user browsers.