logo

Rspack supply chain attack (Incident)

ID: b50fc94c-9a7e-5d85-8fc4-dbc7af50047d

STIX ID: report--b50fc94c-9a7e-5d85-8fc4-dbc7af50047d

Feed Name: Wiz Cloud Threat Landscape

Threat Score
85/100

Date Published: 2025-04-17

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Researchers uncovered a supply-chain attack (attributed to MUT-1692) in which a compromised Rspack maintainer published trojanized @rspack/core and @rspack/cli (v1.1.7). The malicious packages executed an obfuscated Node.js postinstall payload that downloaded and decoded a secondary payload, installed a custom-configured XMRig miner (with a fallback to the official installer), and scanned local directories to exfiltrate cloud credentials—targeting developers using Huawei, Alibaba, and Tencent cloud services; the campaign was first flagged via a typosquatted npm package (argus3-test).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.