cognitive cybersecurity intelligence

News and Analysis

Search

npm packages from Rspack, Vant compromised, blocked by Sonatype

The npm packages @rspack/core, @rspack/cli, and “vant” were hijacked after attackers accessed a compromised npm token. The attackers published malicious versions of the projects, which were caught by Sonatype’s automated malware detection systems. The compromised versions deployed a Monero crypto miner. Both projects detected the compromise and have since issued safe versions, advising users to upgrade and check for signs of compromise.

Source: www.sonatype.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts