216.73.216.6

Rspack npm Packages Compromised with Crypto Mining Malware in Supply Chain Attack

· Published 20/12/2024 15:25 · Modified 20/12/2024 16:42

Export JSON

Essential information

Published
20/12/2024 15:25
Modified
20/12/2024 16:42
Tags
2024-12-20 crypto mining linux npm rspack xmrig
Related entities
1 observables, 9 techniques (mitre), 1 malware, 5 others

Description

Two packages, @/core and @/cli, were compromised in a supply chain attack, allowing the publication of malicious versions containing cryptocurrency mining malware. The attack targeted specific countries and aimed to execute cryptocurrency miner on hosts. The malicious versions have been unpublished, and version 1.1.8 is now considered safe. The incident highlights the need for stricter safeguards in package managers to protect developers. The project maintainers have taken steps to secure their infrastructure, including invalidating tokens and auditing source code. An investigation into the root cause of the token theft is ongoing.

External references