The rc npm Supply Chain Attack
Updated 5 Oct 2026 · Incident date 4 Nov 2021 · npm
rc 1.2.8 -> 1.2.9 (also 1.3.9 and 2.3.9)package.json gained a preinstall hook invoking new compile.js / compile.bat filesThe npm package rc had three malicious releases in November 2021: 1.2.9, 1.3.9, and 2.3.9. GitHub rates the advisory as critical. Version 1.2.8 is the safe version to use.
The attack came the same week as a hijack of the coa package. Rapid7 reports that npm found the malware in both packages to be identical.
What happened
Attackers published three poisoned versions of rc, a library that reads configuration files, and the releases ran malware on install. The GitHub advisory GHSA-g2q5-5433-rhrf describes the releases as intentionally embedded malicious code. It says any computer that has the package installed or running is fully compromised.
The poisoned versions added an install hook in package.json that ran new files named compile.js and compile.bat. Rapid7 reports that the code ran in Windows environments and that the malware steals credentials. Rapid7 also lists sdd.dll as a file to look for.
The advisory date is 4 November 2021. Rapid7 reports that coa, version 2.0.3 and later, was hijacked on 4 November, and that rc was confirmed on 5 November. Developers first noticed strange new versions that broke their builds. The same actor family had hijacked ua-parser-js on 25 October 2021. The advisory has no CVE.
The Record covered the incident as well.
Affected versions
- rc 1.2.9 (malicious)
- rc 1.3.9 (malicious)
- rc 2.3.9 (malicious)
- rc 1.2.8 and earlier (safe)
GitHub lists no patched version. The advice is to move to 1.2.8 or earlier. Related: coa 2.0.3 and later were also compromised, and 2.0.2 is the safe version, according to Rapid7.
Indicators of compromise
compile.jsandcompile.batinside the rc package folder.sdd.dllon the machine.- A
preinstallscript in thepackage.jsonof rc at 1.2.9, 1.3.9, or 2.3.9.
How to check
List every copy of rc in the dependency tree, including nested copies.
npm ls rc --all
Then look for the files the malware added.
find . -path '*node_modules/rc/*' ( -name compile.js -o -name compile.bat ) -print find / -name sdd.dll 2>/dev/null
On Windows, search for sdd.dll with File Explorer or dir /s sdd.dll.
What to do now
- Pin rc to 1.2.8 or earlier, and coa to 2.0.2, then reinstall from a clean cache.
- If a machine installed an affected version, treat it as fully compromised. Rotate every credential and secret from a different, clean computer.
- Remove the package and delete
compile.js,compile.bat, andsdd.dll. GitHub warns that removing the package does not guarantee removal of all malware, so plan a full rebuild of the machine. - Check CI runners and build servers that ran
npm installduring the period. - Pin versions in lock files to avoid automatic upgrades.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 65 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED package.json It now runs a command on its own when it is installed, downloads from the internet and reads saved passwords and access keys. It did not before.
Frequently asked questions
Which rc npm versions are malicious?
Versions 1.2.9, 1.3.9, and 2.3.9. The advisory recommends version 1.2.8 or earlier.
What files does the rc malware add?
Rapid7 lists compile.js, compile.bat, and sdd.dll as files to search for and delete.
Is removing the rc package enough after infection?
No. GitHub advises treating the computer as fully compromised, rotating all credentials from a clean machine, and noting that removing the package does not guarantee the malware is gone.
Sources
More supply chain attacks
- @apexacc/cli Defender-blinding C2 loader 17 Sept 2026
- keyv / cacheable npm worm (Shai-Hulud third wave) 4 Aug 2026
- Mastra AI npm compromise (Sapphire Sleet) 17 Jun 2026
- TanStack npm compromise (Mini Shai-Hulud) 11 May 2026
All 111 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.