
Malicious Rspack, Vant packages revealed utilizing stolen NPM tokens
Three fashionable npm packages, @rspack/core, @rspack/cli, and Vant, had been compromised by stolen npm account tokens, permitting menace actors to publish malicious variations that put in cryptominers. The availability chain assault, noticed by each Sonatype and Socket researchers, deployed the XMRig cryptocurrency miner on compromised techniques for mining the hard-to-trace Monero privateness cryptocurrency. Moreover, Sonatype…