logo

Malicious Rspack, Vant packages published using stolen NPM tokens

ID: d4a9b339-2c2f-54e3-818c-3c0c24931187

STIX ID: report--d4a9b339-2c2f-54e3-818c-3c0c24931187

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-12-20

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Multiple popular npm packages (@rspack/core, @rspack/cli, and Vant) were compromised via stolen npm tokens allowing attackers to publish malicious releases that install the XMRig Monero miner during postinstall. The malware fetches configuration from an external server, performs reconnaissance (ipinfo.io), downloads an XMRig binary from GitHub (renamed in Vant to blend in), limits CPU use to 75% to evade detection, and affected numerous versions; maintainers have released cleaned updates and advised upgrading to safe versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.