Rspack npm Packages Compromised: Crypto Mining Malware Discovered in Supply Chain Attack – Stay Informed and Protect Your Projects
On December 20, 2024, the developers of Rspack disclosed that two of their npm packages, @rspack/core and @rspack/cli, were compromised in a supply chain attack. Malicious versions containing cryptocurrency mining malware were published to the npm registry after an attacker gained unauthorized publishing access. The affected versions, 1.1.7, have been removed, with 1.1.8 now considered ...