Malicious Rspack and Vant Packages Exploit Stolen NPM Tokens: Protect Your Projects from Security Threats
Three popular npm packages, @rspack/core, @rspack/cli, and Vant, were hacked due to stolen npm tokens, resulting in the release of malicious versions that installed cryptominers. This supply chain attack, identified by researchers from Sonatype and Socket, deployed the XMRig miner to secretly mine Monero cryptocurrency on affected systems. The compromised code hid in specific JavaScript ...