Source |
The Hacker News |
Identifiant |
8627889 |
Date de publication |
2024-12-20 14:09:00 (vue: 2024-12-20 10:08:12) |
Titre |
Rspack npm Packages Compromised with Crypto Mining Malware in Supply Chain Attack |
Texte |
The developers of Rspack have revealed that two of their npm packages, @rspack/core and @rspack/cli, were compromised in a software supply chain attack that allowed a malicious actor to publish malicious versions to the official package registry with cryptocurrency mining malware.
Following the discovery, versions 1.1.7 of both libraries have been unpublished from the npm registry. The latest
The developers of Rspack have revealed that two of their npm packages, @rspack/core and @rspack/cli, were compromised in a software supply chain attack that allowed a malicious actor to publish malicious versions to the official package registry with cryptocurrency mining malware.
Following the discovery, versions 1.1.7 of both libraries have been unpublished from the npm registry. The latest |
Notes |
★★★
|
Envoyé |
Oui |
Condensat |
@rspack/cli @rspack/core actor allowed attack been both chain compromised crypto cryptocurrency developers discovery following from have latest libraries malicious malware mining npm official package packages publish registry revealed rspack software supply two unpublished versions |
Tags |
Malware
|
Stories |
|
Move |
|