Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Massive Android fraud operations are detected: iconade, kaleidoscope, malicious SMS software, NFC scams

July 3, 2025

Chinese hackers operate Ivanti CSA Zero-Days in attacks on the French government, telecommunications

July 3, 2025

More than 40 malicious Firefox extensions target cryptocurrency wallets, steel assets

July 3, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Rspack npm packages compromised by crypto mining malware in supply chain attack
Global Security

Rspack npm packages compromised by crypto mining malware in supply chain attack

AdminBy AdminDecember 20, 2024No Comments3 Mins Read
Crypto Mining Malware
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


December 20, 2024Ravi LakshmananMalware / Supply chain attack

Crypto mining malware

The Rspack developers revealed that two of their npm packages, @rspack/core and @rspack/cliwere compromised in a software supply chain attack that allowed an attacker to publish malicious versions to the official cryptocurrency mining malware package registry.

After discoveryversions 1.1.7 of both libraries have been removed from the npm registry. The latest secure version is 1.1.8.

“They were released by an attacker who gained unauthorized access to an npm post and contain malicious scripts,” according to software security firm Socket. said in the analysis.

Cyber ​​security

Rspack considered as an alternative webpackoffering “a high-performance JavaScript compiler written in Rust.” Originally developed by ByteDance, it has since been adopted by several companies such as Alibaba, Amazon, Discord, and Microsoft, among others.

The npm packages in question, @rspack/core and @rspack/cli, have over 300,000 and 145,000 weekly downloads respectively, which is a testament to their popularity.

Analysis of the fake versions of the two libraries revealed that they include code to make calls to a remote server (“80.78.28(.)72”) to pass sensitive configuration details, such as cloud service credentials, as well as collect IP details -address and location by making an HTTP GET request to “ipinfo(.)io/json”.

In an interesting twist, the attack also limits the infection to machines located in a specific set of countries, such as China, Russia, Hong Kong, Belarus and Iran.

The ultimate goal of the attacks is to trigger the XMRig cryptocurrency miner to download and execute on compromised Linux hosts after installing packages using a post-installation script specified in the “package.json” file.

“The malware is launched via a post-installation script that runs automatically when the package is installed,” Sockett said. “This ensures that the malicious payload executes without any user action, embedding itself in the target environment.”

Cyber ​​security

In addition to publishing a new version of the two packages without the malicious code, the project maintainers said they invalidated all existing npm tokens and GitHub tokens, checked the permissions of the npm repository and packages, and checked the source code for any potential vulnerabilities. The root cause of the token theft is under investigation.

“This attack highlights the need for package managers to take stronger security measures to protect developers, such as enforcing attestation checks to prevent updates to unverified versions,” Sockett said. “But it’s not exactly bulletproof.”

“As can be seen in the recent Attack on Ultralytics supply chain in the Python ecosystem, attackers can still publish attested versions by hacking GitHub Actions via cache poisoning.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Massive Android fraud operations are detected: iconade, kaleidoscope, malicious SMS software, NFC scams

July 3, 2025

Chinese hackers operate Ivanti CSA Zero-Days in attacks on the French government, telecommunications

July 3, 2025

More than 40 malicious Firefox extensions target cryptocurrency wallets, steel assets

July 3, 2025

CISCO’s critical vulnerability in uniform grants on root access to static credentials

July 3, 2025

North Korean Hackers Target Web3 with malicious NIM software and use Clickfix in Babyshark

July 2, 2025

Hackers using PDFs to get yourself for Microsoft, Docusign and more in phishing campaigns return call

July 2, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Massive Android fraud operations are detected: iconade, kaleidoscope, malicious SMS software, NFC scams

July 3, 2025

Chinese hackers operate Ivanti CSA Zero-Days in attacks on the French government, telecommunications

July 3, 2025

More than 40 malicious Firefox extensions target cryptocurrency wallets, steel assets

July 3, 2025

CISCO’s critical vulnerability in uniform grants on root access to static credentials

July 3, 2025

North Korean Hackers Target Web3 with malicious NIM software and use Clickfix in Babyshark

July 2, 2025

Hackers using PDFs to get yourself for Microsoft, Docusign and more in phishing campaigns return call

July 2, 2025

This network traffic looks legal but it can hide a serious threat

July 2, 2025

US Sanctions of Russia

July 2, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Massive Android fraud operations are detected: iconade, kaleidoscope, malicious SMS software, NFC scams

July 3, 2025

Chinese hackers operate Ivanti CSA Zero-Days in attacks on the French government, telecommunications

July 3, 2025

More than 40 malicious Firefox extensions target cryptocurrency wallets, steel assets

July 3, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.