OSS in the crosshairs: Cryptomining hacks highlight key new threat
ID: bfb14d8f-553a-5140-b8de-28619e03ca5b
STIX ID: report--bfb14d8f-553a-5140-b8de-28619e03ca5b
Feed Name: ReversingLabs Blog
Date Published: 2024-12-20
Date Updated: 2026-04-29
Author: [email protected] (Carolynn van Arsdale)
**Executive Summary:** Multiple popular open-source packages (notably rspack and vant) were compromised to deliver the XMRig cryptominer via malicious updates; attackers leveraged stolen publishing credentials and GitHub Actions/script injection, added obfuscated files and external C2 communications, and forced maintainers to remove affected versions and publish clean releases, underscoring the growing trend of supply-chain attacks and the value of differential analysis for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
