Crypto Chaos: Rspack’s npm Packages Infiltrated with Mining Malware!

Rspack’s npm packages were hijacked, delivering a crypto miner to unsuspecting users. The rogue versions collected sensitive info and targeted specific countries. Developers quickly unpublished the malicious versions. Socket advises stricter safeguards, but admits nothing’s bullet-proof—just like trying to keep a toddler away from a cookie jar!

Pro Dashboard

Hot Take:

Looks like Rspack’s npm packages just got a side gig as crypto miners! Maybe they should get a raise—or at least some antivirus software. When software supply chain attacks start dressing up as Robin Hood, you know it’s time to lock the gates and maybe throw away the key. “You get a miner! You get a miner!” said no developer ever. Sorry, Oprah.

Key Points:

  • Rspack’s npm packages @rspack/core and @rspack/cli were compromised, hosting cryptocurrency mining malware.
  • Versions 1.1.7 of the packages were unpublished; version 1.1.8 is safe.
  • The attack targeted machines in specific countries, hinting at a selective hacker with a geopolitical agenda.
  • Malware executed via a postinstall script, sneakily mining XMRig cryptocurrency on Linux hosts.
  • Rspack has taken measures to secure its packages, but the possibility of future attacks remains a concern.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?