All vulnerabilities
HIGHSupply chainexploited in the wild

NPM-RSPACK-VANT-2024

npm · @rspack/core, @rspack/cli, vant

Summary

On December 20, 2024, attackers used stolen npm publishing tokens to release malicious versions of @rspack/core and @rspack/cli (over 300,000 and 145,000 weekly downloads respectively) and the vant package. A postinstall script collected IP/geolocation data via ipinfo.io and downloaded and executed an XMRig cryptocurrency miner on compromised Linux hosts in targeted countries (China, Russia, Hong Kong, Belarus, Iran). The Rspack team deprecated the malicious v1.1.7, redirected the latest tag to v1.1.6 and released a clean v1.1.8.

References

Related vulnerabilities

All Supply chain →