The rc npm Supply Chain Attack

Updated 5 Oct 2026 · Incident date 4 Nov 2021 · npm

Packagerc 1.2.8 -> 1.2.9 (also 1.3.9 and 2.3.9)
Filepackage.json gained a preinstall hook invoking new compile.js / compile.bat files

The npm package rc had three malicious releases in November 2021: 1.2.9, 1.3.9, and 2.3.9. GitHub rates the advisory as critical. Version 1.2.8 is the safe version to use.

The attack came the same week as a hijack of the coa package. Rapid7 reports that npm found the malware in both packages to be identical.

What happened

Attackers published three poisoned versions of rc, a library that reads configuration files, and the releases ran malware on install. The GitHub advisory GHSA-g2q5-5433-rhrf describes the releases as intentionally embedded malicious code. It says any computer that has the package installed or running is fully compromised.

The poisoned versions added an install hook in package.json that ran new files named compile.js and compile.bat. Rapid7 reports that the code ran in Windows environments and that the malware steals credentials. Rapid7 also lists sdd.dll as a file to look for.

The advisory date is 4 November 2021. Rapid7 reports that coa, version 2.0.3 and later, was hijacked on 4 November, and that rc was confirmed on 5 November. Developers first noticed strange new versions that broke their builds. The same actor family had hijacked ua-parser-js on 25 October 2021. The advisory has no CVE.

The Record covered the incident as well.

Affected versions

GitHub lists no patched version. The advice is to move to 1.2.8 or earlier. Related: coa 2.0.3 and later were also compromised, and 2.0.2 is the safe version, according to Rapid7.

Indicators of compromise

How to check

List every copy of rc in the dependency tree, including nested copies.

npm ls rc --all

Then look for the files the malware added.

find . -path '*node_modules/rc/*' ( -name compile.js -o -name compile.bat ) -print
find / -name sdd.dll 2>/dev/null

On Windows, search for sdd.dll with File Explorer or dir /s sdd.dll.

What to do now

  1. Pin rc to 1.2.8 or earlier, and coa to 2.0.2, then reinstall from a clean cache.
  2. If a machine installed an affected version, treat it as fully compromised. Rotate every credential and secret from a different, clean computer.
  3. Remove the package and delete compile.js, compile.bat, and sdd.dll. GitHub warns that removing the package does not guarantee removal of all malware, so plan a full rebuild of the machine.
  4. Check CI runners and build servers that ran npm install during the period.
  5. Pin versions in lock files to avoid automatic upgrades.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old rc-1.2.8 --new rc-1.2.9
files scanned: 65

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    package.json
           It now runs a command on its own when it is installed, downloads from the internet and reads saved passwords and access keys. It did not before.

Frequently asked questions

Which rc npm versions are malicious?

Versions 1.2.9, 1.3.9, and 2.3.9. The advisory recommends version 1.2.8 or earlier.

What files does the rc malware add?

Rapid7 lists compile.js, compile.bat, and sdd.dll as files to search for and delete.

Is removing the rc package enough after infection?

No. GitHub advises treating the computer as fully compromised, rotating all credentials from a clean machine, and noting that removing the package does not guarantee the malware is gone.

Sources

  1. github.com/advisories/GHSA-g2q5-5433-rhrf
  2. rapid7.com/blog/post/2021/11/05/new-npm-library-hijacks-coa-and-rc/

More supply chain attacks

All 111 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free