Country visual unavailable
No information
Vant maintainers reported that a team member's token had been stolen and used to inject malicious scripts into multiple npm releases on December 19, 2024. The malicious releases were distributed through the legitimate npm channel and contained code designed to deploy XMRig cryptomining malware when installed. Maintainers deprecated the malicious releases within roughly eighty minutes and subsequently released a clean version, making this a confirmed software-supply-chain compromise rather than a vulnerability in Vant itself.
Estimated severity
68 / 100
Source reliability
95 / 100
Approximate Date
19/12/2024
Targeted Company
VANT
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
Country visual unavailable
No information
No other affected countries reported
Target country
No information
Affected countries
No information
Impacted regions
No information
Duration
0.06 days
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
No information
Incident Sources
Please rotate your phone