Rspack supply chain attack (Incident)
ID: b50fc94c-9a7e-5d85-8fc4-dbc7af50047d
STIX ID: report--b50fc94c-9a7e-5d85-8fc4-dbc7af50047d
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-04-17
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Researchers uncovered a supply-chain attack (attributed to MUT-1692) in which a compromised Rspack maintainer published trojanized @rspack/core and @rspack/cli (v1.1.7). The malicious packages executed an obfuscated Node.js postinstall payload that downloaded and decoded a secondary payload, installed a custom-configured XMRig miner (with a fallback to the official installer), and scanned local directories to exfiltrate cloud credentials—targeting developers using Huawei, Alibaba, and Tencent cloud services; the campaign was first flagged via a typosquatted npm package (argus3-test).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
