Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025

6 Steps to 24/7 Internal Success SoC

June 20, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Rspack npm packages compromised by crypto mining malware in supply chain attack
Global Security

Rspack npm packages compromised by crypto mining malware in supply chain attack

AdminBy AdminDecember 20, 2024No Comments3 Mins Read
Crypto Mining Malware
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


December 20, 2024Ravi LakshmananMalware / Supply chain attack

Crypto mining malware

The Rspack developers revealed that two of their npm packages, @rspack/core and @rspack/cliwere compromised in a software supply chain attack that allowed an attacker to publish malicious versions to the official cryptocurrency mining malware package registry.

After discoveryversions 1.1.7 of both libraries have been removed from the npm registry. The latest secure version is 1.1.8.

“They were released by an attacker who gained unauthorized access to an npm post and contain malicious scripts,” according to software security firm Socket. said in the analysis.

Cyber ​​security

Rspack considered as an alternative webpackoffering “a high-performance JavaScript compiler written in Rust.” Originally developed by ByteDance, it has since been adopted by several companies such as Alibaba, Amazon, Discord, and Microsoft, among others.

The npm packages in question, @rspack/core and @rspack/cli, have over 300,000 and 145,000 weekly downloads respectively, which is a testament to their popularity.

Analysis of the fake versions of the two libraries revealed that they include code to make calls to a remote server (“80.78.28(.)72”) to pass sensitive configuration details, such as cloud service credentials, as well as collect IP details -address and location by making an HTTP GET request to “ipinfo(.)io/json”.

In an interesting twist, the attack also limits the infection to machines located in a specific set of countries, such as China, Russia, Hong Kong, Belarus and Iran.

The ultimate goal of the attacks is to trigger the XMRig cryptocurrency miner to download and execute on compromised Linux hosts after installing packages using a post-installation script specified in the “package.json” file.

“The malware is launched via a post-installation script that runs automatically when the package is installed,” Sockett said. “This ensures that the malicious payload executes without any user action, embedding itself in the target environment.”

Cyber ​​security

In addition to publishing a new version of the two packages without the malicious code, the project maintainers said they invalidated all existing npm tokens and GitHub tokens, checked the permissions of the npm repository and packages, and checked the source code for any potential vulnerabilities. The root cause of the token theft is under investigation.

“This attack highlights the need for package managers to take stronger security measures to protect developers, such as enforcing attestation checks to prevent updates to unverified versions,” Sockett said. “But it’s not exactly bulletproof.”

“As can be seen in the recent Attack on Ultralytics supply chain in the Python ecosystem, attackers can still publish attested versions by hacking GitHub Actions via cache poisoning.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025

6 Steps to 24/7 Internal Success SoC

June 20, 2025

67 Trojanized GitHub repository found in the company, orientation on gamers and developers

June 20, 2025

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025

6 Steps to 24/7 Internal Success SoC

June 20, 2025

67 Trojanized GitHub repository found in the company, orientation on gamers and developers

June 20, 2025

Safe Coding Vibe: Full New Guide

June 19, 2025

Bluenoroff Deepfake Zoom AFM Hits Crypto employee with malicious MacOS software

June 19, 2025

Discover the areas hiding in trusted instruments – find out how in this free expert session

June 19, 2025

Russian APT29 operates Gmail app passwords to get around 2FA in the target phishing campaign

June 19, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Iran’s state TV is driven in the middle of his brother amid geopolitical tensions; 90 million dollars stole in the cry

June 20, 2025

A massive DDOS attack 7.3 TBPS provides 37.4 TV in 45 seconds, focusing on the hosting provider

June 20, 2025

6 Steps to 24/7 Internal Success SoC

June 20, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.