NPM Nightmare: Year-Long Malware Attack Mines Crypto and Steals Data

A software supply chain attack on the npm package registry, active for over a year, involves a package named @0xengine/xmlrpc. It started as an innocuous library and later added code to steal data and mine cryptocurrency. With 1,790 downloads, this serves as a reminder of the need for constant vigilance in software supply chains.

Pro Dashboard

Hot Take:

In the world of open-source, even your trusty XML-RPC server might turn into a sneaky crypto-mining thief. Who knew that downloading a package could be more dangerous than a trip to the dentist? It’s like opening a box of chocolates and finding out one of them is a grenade.

Key Points:

  • An npm package named @0xengine/xmlrpc has been actively involved in a supply chain attack for over a year.
  • The package was initially harmless but later updated with malicious code to steal data and mine cryptocurrency.
  • Distribution methods included npm installations and as a hidden dependency in a GitHub project.
  • The attack has compromised at least 68 systems for Monero mining.
  • Datadog Security Labs uncovered a related campaign targeting Windows users with counterfeit packages.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?