The Rspack and Vant Supply Chain Attack
Updated 5 Oct 2026 · Incident date 19 Dec 2024 · npm
@rspack/core 1.1.6 -> 1.1.7, @rspack/cli 1.1.6 -> 1.1.7 (vant also affected)dist/utils/config.jsOn 19 December 2024 an attacker published @rspack/core 1.1.7 and @rspack/cli 1.1.7 to npm with a hidden cryptocurrency miner. Several vant releases were hit the same day.
The attacker used stolen npm tokens. The fixed releases are 1.1.8 for Rspack and 4.9.15 for vant. This page lists the facts from Sonatype, The Hacker News and BleepingComputer.
What happened
Attackers got npm tokens that belonged to team members and used them to publish poisoned versions. Sonatype reports that the packages held heavily obfuscated code in a config file under dist/utils/. In vant the file is support.js. BleepingComputer names support.js for @rspack/core and config.js for @rspack/cli, so the sources differ on which file sits in which package.
A postinstall script starts the code. The code looks up the machine's location and network details through the ipinfo.io service. It sends data to a remote server at 80.78.28.72. It then downloads and runs XMRig, a Monero miner. BleepingComputer adds that the miner is limited to 75 percent of the processor threads.
The Hacker News says the Rspack team unpublished the bad versions as soon as they found them. The team told users to invalidate all npm and GitHub tokens and said it was still investigating the root cause of the token theft.
Affected versions
- @rspack/core 1.1.7 (about 394,000 weekly downloads).
- @rspack/cli 1.1.7 (about 145,000 weekly downloads).
- vant 2.13.3, 2.13.4, 2.13.5, 3.6.13, 3.6.14, 3.6.15, 4.9.11, 4.9.12, 4.9.13, 4.9.14 (about 46,000 weekly downloads).
- Safe: 1.1.6, or 1.1.8 and later for Rspack. 4.9.15 and later for vant.
Indicators of compromise
- Remote server:
80.78.28.72(Sonatype lists the path/tokens). - Location lookup to
ipinfo.io/jsonfrom a build or install step. - Monero wallet address in the miner configuration:
475NBZygwEajj4YP2Bdu7yg6XnaphiFjxTFPkvzg5xAjLGPSakE68nyGavn8r1BYqB44xTEyKQhueeqAyGy8RaYc73URL1j - A miner file named
/tmp/vant_helperin the vant variant. - An unexpected XMRig process that uses a high share of CPU.
- A postinstall script in the installed package that you did not see before.
Sonatype tracks the issue as sonatype-2024-013290.
How to check
Find every copy of the affected packages in your projects.
npm ls @rspack/core @rspack/cli vant
On Linux hosts and CI runners, look for the miner process and the helper file.
ps aux | grep -i xmrig; ls -l /tmp/vant_helper
Search installed code for the server address.
grep -rl "80.78.28.72" node_modules/@rspack node_modules/vant
What to do now
- Upgrade @rspack/core and @rspack/cli to 1.1.8 or later and vant to 4.9.15 or later.
- Remove node_modules and reinstall from a clean lockfile.
- Stop and remove any miner process on machines that installed a bad version.
- Rotate npm and GitHub tokens that were present on those machines. The Hacker News reports that the malware also sent cloud service credentials to the remote server.
- Block 80.78.28.72 at your firewall.
- Audit repository permissions and turn on two-factor authentication for publishers.
Vigilance compares the version you trust with a new one. Here, a helper file in a build tool gained a geolocation lookup and a download-and-run step. Vigilance reports that new capability in the file.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 90 (1 Added) HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. NEW FILE dist/utils/config.js It runs a command on its own when it is installed and downloads from the internet.
Frequently asked questions
Which Rspack versions were compromised?
@rspack/core 1.1.7 and @rspack/cli 1.1.7. Version 1.1.8 is the fixed release. Several vant versions between 2.13.3 and 4.9.14 were also compromised.
What did the Rspack malware do?
A postinstall script ran obfuscated code that looked up the machine's location, contacted a remote server and downloaded and ran the XMRig Monero miner.
How did attackers publish the bad Rspack packages?
They used stolen npm tokens that belonged to team members. The tokens gave them publishing access.
Sources
More supply chain attacks
- @apexacc/cli Defender-blinding C2 loader 17 Sept 2026
- keyv / cacheable npm worm (Shai-Hulud third wave) 4 Aug 2026
- Mastra AI npm compromise (Sapphire Sleet) 17 Jun 2026
- TanStack npm compromise (Mini Shai-Hulud) 11 May 2026
All 111 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.