MIT TRACE

MIT CTL Logo
Back to Main Dashboard

Compromised Rspack npm publishing token distributes cryptomining malware

Rspack disclosed that attackers used a compromised npm token to publish malicious version 1.1.7 of @rspack/core and @rspack/cli on December 19, 2024. The malicious releases were distributed through the legitimate npm channel and contained obfuscated code designed to deploy the XMRig Monero miner when installed, creating a direct software-supply-chain integrity impact. Rspack deprecated the malicious release, reset relevant tokens and issued a clean replacement.

70

Estimated severity

70 / 100

95

Source reliability

95 / 100

Approximate Date

19/12/2024

Targeted Company

RSPACK

Targeted Company Supply Chain Impact

  1. Distribution & Fulfillment

  2. Procurement & Sourcing

  3. Production & Manufacturing

  4. Sales (Retail & Ecommerce)

  5. Warehousing

  6. Service Delivery

  7. Unrecognized Impact

Supply Chain Relations

No information

Geographic Impact

Country Targeted Company

Country visual unavailable

No information

Other Affected Countries

No other affected countries reported

Target country

No information

Affected countries

No information

Impacted regions

No information

Operational Impact

Duration

No information

Financial impact (USD M)

No information

Impact types

Supply chain data integrity impact

Affected sectors

Technology & IT Services

Affected departments

Information Technology

Attack Profile

Attack types

Use of stolen credentialsSoftware supply chain compromiseMalwareCryptocurrency mining

Attributed threat actors

No information

Sources

Please rotate your phone

MIT TRACE is optimized for landscape orientation on mobile.