NPM Nightmare: Year-Long Malware Attack Mines Crypto and Steals Data
A software supply chain attack on the npm package registry, active for over a year, involves a package named @0xengine/xmlrpc. It started as an innocuous library and later added code to steal data and mine cryptocurrency. With 1,790 downloads, this serves as a reminder of the need for constant vigilance in software supply chains.

Hot Take:
In the world of open-source, even your trusty XML-RPC server might turn into a sneaky crypto-mining thief. Who knew that downloading a package could be more dangerous than a trip to the dentist? It’s like opening a box of chocolates and finding out one of them is a grenade.
Key Points:
- An npm package named
@0xengine/xmlrpc
has been actively involved in a supply chain attack for over a year. - The package was initially harmless but later updated with malicious code to steal data and mine cryptocurrency.
- Distribution methods included npm installations and as a hidden dependency in a GitHub project.
- The attack has compromised at least 68 systems for Monero mining.
- Datadog Security Labs uncovered a related campaign targeting Windows users with counterfeit packages.
Already a member? Log in here