The Rspack and Vant Supply Chain Attack

Updated 5 Oct 2026 · Incident date 19 Dec 2024 · npm

Package@rspack/core 1.1.6 -> 1.1.7, @rspack/cli 1.1.6 -> 1.1.7 (vant also affected)
Filedist/utils/config.js

On 19 December 2024 an attacker published @rspack/core 1.1.7 and @rspack/cli 1.1.7 to npm with a hidden cryptocurrency miner. Several vant releases were hit the same day.

The attacker used stolen npm tokens. The fixed releases are 1.1.8 for Rspack and 4.9.15 for vant. This page lists the facts from Sonatype, The Hacker News and BleepingComputer.

What happened

Attackers got npm tokens that belonged to team members and used them to publish poisoned versions. Sonatype reports that the packages held heavily obfuscated code in a config file under dist/utils/. In vant the file is support.js. BleepingComputer names support.js for @rspack/core and config.js for @rspack/cli, so the sources differ on which file sits in which package.

A postinstall script starts the code. The code looks up the machine's location and network details through the ipinfo.io service. It sends data to a remote server at 80.78.28.72. It then downloads and runs XMRig, a Monero miner. BleepingComputer adds that the miner is limited to 75 percent of the processor threads.

The Hacker News says the Rspack team unpublished the bad versions as soon as they found them. The team told users to invalidate all npm and GitHub tokens and said it was still investigating the root cause of the token theft.

Affected versions

Indicators of compromise

Sonatype tracks the issue as sonatype-2024-013290.

How to check

Find every copy of the affected packages in your projects.

npm ls @rspack/core @rspack/cli vant

On Linux hosts and CI runners, look for the miner process and the helper file.

ps aux | grep -i xmrig; ls -l /tmp/vant_helper

Search installed code for the server address.

grep -rl "80.78.28.72" node_modules/@rspack node_modules/vant

What to do now

  1. Upgrade @rspack/core and @rspack/cli to 1.1.8 or later and vant to 4.9.15 or later.
  2. Remove node_modules and reinstall from a clean lockfile.
  3. Stop and remove any miner process on machines that installed a bad version.
  4. Rotate npm and GitHub tokens that were present on those machines. The Hacker News reports that the malware also sent cloud service credentials to the remote server.
  5. Block 80.78.28.72 at your firewall.
  6. Audit repository permissions and turn on two-factor authentication for publishers.

Vigilance compares the version you trust with a new one. Here, a helper file in a build tool gained a geolocation lookup and a download-and-run step. Vigilance reports that new capability in the file.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old @rspack/core-1.1.6 --new @rspack/core-1.1.7
files scanned: 90 (1 Added)

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

NEW FILE   dist/utils/config.js
           It runs a command on its own when it is installed and downloads from the internet.

Frequently asked questions

Which Rspack versions were compromised?

@rspack/core 1.1.7 and @rspack/cli 1.1.7. Version 1.1.8 is the fixed release. Several vant versions between 2.13.3 and 4.9.14 were also compromised.

What did the Rspack malware do?

A postinstall script ran obfuscated code that looked up the machine's location, contacted a remote server and downloaded and ran the XMRig Monero miner.

How did attackers publish the bad Rspack packages?

They used stolen npm tokens that belonged to team members. The tokens gave them publishing access.

Sources

  1. sonatype.com/blog/npm-packages-rspack-vant-compromised-blocked-by-sonatype
  2. thehackernews.com/2024/12/rspack-npm-packages-compromised-with.html
  3. bleepingcomputer.com/news/security/malicious-rspack-vant-packages-published-using-stolen-npm-tokens/

More supply chain attacks

All 111 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free