Home / Companies / Socket / Blog / Post Details
Content Deep Dive

Supply Chain Attack on Rspack npm Packages Injects Cryptojac...

Blog post from Socket

Post Details
Company
Date Published
Author
Socket Research Team
Word Count
777
Company Posts That Month
14
Language
English
Hacker News Points
-
Post removed?
No
Summary

A supply chain attack has compromised Rspack's npm packages, specifically targeting the high-performance JavaScript bundler's @rspack/core and @rspack/cli packages, by injecting cryptojacking malware. This attack potentially impacts thousands of developers, as Rspack is widely adopted by major companies like Microsoft, Amazon, and Discord. The malicious code, embedded in support.js and config.js files, retrieves data from external servers and executes the XMRig cryptocurrency mining program, exploiting system resources without user consent. This incident underscores the need for improved security measures in package managers to prevent unauthorized updates to unverified versions, as attackers increasingly compromise package publishers' credentials. Despite proposed solutions like enforcing attestation checks, the growing frequency of supply chain attacks calls for more robust, multi-layered defenses to safeguard developers against these threats.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.