Campaign · Open Source · · 1 day
Rspack and Vant shipped XMRig miners
The Rspack and Vant compromise used stolen npm publishing tokens to ship obfuscated XMRig cryptomining payloads through official packages on December 19, 2024.
Draws together 2 incidents across 3 packages
The Rspack and Vant incidents were the same small campaign, not isolated accidents. On December 19, 2024, attackers used stolen npm publishing tokens to push malicious releases for @rspack/core, @rspack/cli, and vant.
The packages arrived through the official npm registry. Their install-time code was obfuscated, fetched additional material from attacker infrastructure, and deployed XMRig to mine Monero on developer and CI systems. The campaign also searched cloud credential paths, which made the miner more than a nuisance payload: a compromised install could burn CPU and expose cloud material from the same developer or CI environment.
Sonatype reported the shared network indicator 80.78.28.72, and later analysis tied the activity to MUT-1692. The useful boundary is still package-specific: Rspack and Vant are separate projects, but the date, payload style, infrastructure, and npm-token path make one campaign.
The record stays at campaign level. The individual package records carry versions, package names, and package-level impact.
Incidents in this campaign
Appendix · Affected packages
Samples and hashes sit on each incident page, linked above
References
Source record: oss/campaigns/rspack-vant-cryptominer-2024/meta.yaml