Rspack npm Packages Compromised with Crypto Mining Malware in Supply Chain Attack
Two of Rspack's npm packages, @rspack/core and @rspack/cli, were hacked in a software supply chain attack, according to the developers. This gave a malevolent actor the ability to post malicious copies of the packages with bitcoin mining malware to the official package registry.
Versions 1.1.7 of both libraries have been removed from the npm registry since the discovery. 1.1.8 is the most recent secure version.
According to a study by software supply chain security company Socket, they were made public by an attacker who obtained unauthorized access to npm publishing and contain harmful scripts.
Rspack is marketed as a high-performance JavaScript bundler built in Rust that can be used as an alternative to webpack read more about Rspack npm Packages Compromised with Crypto Mining ...

