@rspack/core and @rspack/cli were compromised with an XMRig cryptominer via stolen npm publishing tokens. Simultaneously, Vant (a Vue UI library) had 10 compromised versions published. Users at Alibaba, Amazon, Discord, and Microsoft were affected.
PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Caught | PACKAGE_ACTIVE_MALWARE + PACKAGE_INSTALL_SCRIPTS |
| Socket | Caught | Behavioral analysis detects malicious payload. |
| Snyk | Missed | No malware detection capability |
| Sonatype (Nexus) | Caught | Nexus Firewall blocks known-malicious packages at ingestion |
| Black Duck | Missed | No malware detection capability |
| Endor Labs | Missed | No malware detection capability |