Campaign · Open Source · · 1 day
Rspack and Vant shipped XMRig miners
The Rspack and Vant compromise used stolen npm publishing tokens to ship obfuscated XMRig cryptomining payloads through official packages on December 19, 2024.
Draws together 2 incidents across 3 packages
The Rspack and Vant incidents were the same small campaign, not isolated accidents. On December 19, 2024, attackers used stolen npm publishing tokens to push malicious releases for @rspack/core, @rspack/cli, and vant.
The packages arrived through the official npm registry. Their install-time code was obfuscated, fetched additional material from attacker infrastructure, and deployed XMRig to mine Monero on developer systems. The campaign also searched cloud credential paths for Alibaba Cloud, Huawei Cloud and Tencent Cloud, which made the miner more than a nuisance payload: a compromised install could burn CPU and expose cloud material from the same developer or CI environment.
Sonatype reported the shared network indicator 80.78.28.72, and later analysis tied the activity to MUT-1692. The useful boundary is still package-specific: Rspack and Vant are separate projects, but the date, payload style, infrastructure, and npm-token path make one campaign.
The record stays at campaign level. The individual package records carry versions, package names, and package-level impact.
Incidents in this campaign
Appendix · Affected packages
Samples and hashes sit on each incident page, linked above
References
- Rspack npm packages compromised with crypto mining malwarethehackernews.com
- Datadog Security Labs Q1 2025 threat roundup, attributing the activity to MUT-1692securitylabs.datadoghq.com
- npm Packages @rspack/core and vant Compromised by Attacksonatype.com
Source record: oss/campaigns/rspack-vant-cryptominer-2024/meta.yaml