On 19 December 2024, the maintainers of Rspack, a JavaScript bundler originally developed at ByteDance, found that an attacker had used a compromised npm token to publish version 1.1.7 of @rspack/core and @rspack/cli. The malicious release ran a postinstall script that, according to The Hacker News, sent configuration details including cloud service credentials to a remote server and downloaded the XMRig cryptocurrency miner onto Linux hosts. The maintainers say the affected window lasted about an hour. They deprecated 1.1.7, pointed the latest tag back to 1.1.6, reset all related tokens and released a clean 1.1.8. The two packages had several hundred thousand weekly downloads between them, according to Sonatype. The popular Vue component library vant was hit the same day, and its maintainers said a team member's npm token had been stolen. Rspack has not published how its token was taken.
Key takeaways
- Rspack's maintainers say an attacker published
@rspack/coreand@rspack/cli1.1.7 with a compromised npm token, and that they found it at 02:01 UTC on 19 December 2024. - The release ran a postinstall script that installed the XMRig miner and, according to The Hacker News, sent cloud credentials and other configuration details to the attacker, targeting machines in selected countries.
- Sonatype puts weekly downloads at about 394,000 for
@rspack/coreand more than 145,000 for@rspack/cli. The same day, ten versions ofvantwere published with a stolen team member's npm token. - This was a confirmed breach of a publishing identity. Rspack reset all related tokens, and The Hacker News reports it invalidated every existing npm and GitHub token and audited its source.
- The identity lesson: a long-lived npm publish token is a skeleton key to every downstream build, and earlier research had already shown how Rspack's CI could leak one.
At a glance
| Organisations | Rspack (web-infra-dev, originally developed at ByteDance); the vant project, compromised the same day; developers and CI systems that installed the bad versions |
|---|---|
| When | Discovered 02:01 UTC, 19 December 2024; affected window about one hour; clean release and disclosure the same day |
| Attacker | Unknown. Sonatype suspects one actor behind both the Rspack and vant releases |
| Entry point | A compromised npm token with publish rights to the @rspack packages; how it was obtained has not been disclosed |
| Identities abused | Rspack's npm publishing token; cloud and configuration credentials on machines that installed 1.1.7 |
| Impact | Cryptominer installed and configuration data, including cloud credentials, sent to the attacker from affected hosts; number of victims not disclosed |
| Category | NHI. Incident class: confirmed NHI breach (stolen npm publishing token used to ship a cryptominer and credential collector) |
What happened
Rspack is a JavaScript bundler, originally developed by ByteDance, that The Hacker News describes as an alternative to webpack. Its core and command-line packages are installed in many front-end build pipelines, which means install scripts run on developer laptops and CI runners that often hold cloud and repository credentials.
According to the Rspack 1.1.8 release notes, the maintainers discovered at 02:01 UTC on 19 December 2024 that @rspack/core and @rspack/cli had been attacked. An attacker had published 1.1.7 using a compromised npm token, and the release contained malicious code that ran through the postinstall script in package.json after installation. Socket, quoted by The Hacker News, said the versions "were released by an attacker who gained unauthorized npm publishing access, and contain malicious scripts". The Hacker News reports that the code collected the victim's IP address and location, only fired on machines in certain countries including China, Russia, Hong Kong, Belarus and Iran, sent configuration details such as cloud service credentials to a remote server and downloaded XMRig on Linux. Sonatype's automated detection flagged the release and found an attempt to connect to an IP-based URL ending in /tokens.
The maintainers deprecated 1.1.7, pointed latest back to 1.1.6, reset all related tokens and released 1.1.8 as a re-release of 1.1.6. They apologised, saying, as quoted by Sonatype, "We deeply apologize for the risks caused by this incident", and promised stricter token management. The same day, vant was compromised in versions 2.13.3 to 2.13.5, 3.6.13 to 3.6.15 and 4.9.11 to 4.9.14. Its maintainers said: "We found that one of our team members' npm token was stolen and used to release multiple versions". Sonatype suspects a common actor.
How Rspack's token was stolen has not been published; The Hacker News reported that an investigation was under way. There is relevant history. In May 2024, Praetorian researchers showed that two Rspack GitHub Actions workflows, triggered by pull request comments, could be abused to steal secrets, including an npm deployment token. They wrote that "This NPM token was used to push new Rspack packages". The team fixed those workflows within an hour of disclosure, rotated secrets and confirmed no prior exploitation. No public source links that research to the December theft.
Timeline
| Date | Event |
|---|---|
| 31 May 2024 | Praetorian publishes research showing Rspack CI workflows could leak an npm deployment token and an admin GitHub token; the issues had already been fixed and secrets rotated. |
| 19 December 2024 | An attacker publishes @rspack/core and @rspack/cli 1.1.7 with a compromised npm token. |
| 19 December 2024 | 02:01 UTC: Rspack maintainers discover the attack, deprecate 1.1.7, reset tokens and release 1.1.8. |
| 19 December 2024 | Ten vant versions are published with a stolen team member's npm token. |
| 20 December 2024 | Sonatype and The Hacker News report both compromises. |
How it happened: the identity attack path
- Obtain a publish token. The attacker gained an npm token able to publish the
@rspackpackages. The route has not been disclosed. - Publish a poisoned release. Version 1.1.7 went straight to npm with a
postinstallhook, so the payload ran the moment the package was installed. - Run inside builds. Installs on developer machines and CI runners executed the script with whatever credentials and network access those environments had.
- Collect and mine. The script sent configuration details, including cloud credentials, to the attacker and installed XMRig on Linux hosts.
- Token reset. The maintainers reset the related tokens, deprecated the release and published a clean version.
Impact
- Confirmed: a malicious 1.1.7 of two widely used packages was published with a compromised npm token and available for about an hour, according to the maintainers.
- Reported by researchers: the payload installed a Monero miner and sent configuration details, including cloud service credentials, to a remote server, according to The Hacker News and Sonatype.
- Unknown: the number of installs during the window and whether stolen cloud credentials were later used. Neither Rspack nor the researchers have published figures.
- Wider: the same-day
vantcompromise shows stolen npm tokens being used against several popular projects at once.
What this means for NHI governance
Rspack is a clear case of a publishing identity being the attack surface. Nothing in Rspack's source changed; the attacker simply held a token that npm accepted as the project. Long-lived npm tokens are easy to copy from a CI secret store, a developer machine or a log, and once copied they work from anywhere until someone resets them. Praetorian's earlier research is a reminder that CI workflows triggered by outsiders can expose exactly these secrets.
The install side matters too. A postinstall script runs with the full rights of the build environment, so one poisoned dependency can reach cloud keys on a developer laptop or CI runner. Short-lived, trusted publishing for maintainers and minimal, short-lived credentials in build environments limit both halves of the attack. See our CI/CD Pipeline Identity Security Guide and Secrets Management Guide.
Recommendations
- Retire long-lived npm publish tokens. Publish from CI with trusted publishing and provenance so there is no static token to steal. See our CI/CD Pipeline Identity Security Guide.
- Reset every related token after a suspicious release. Rspack reset its npm and GitHub tokens; do it at once and check the registry for other releases made with them. See our Leaked Credential Response Playbook.
- Lock down workflows that outsiders can trigger. Comment- and pull-request-triggered workflows must never run untrusted code with access to publish secrets.
- Disable install scripts where you can. Run package installs with scripts disabled in CI unless a package needs them, and review those that do.
- Keep cloud credentials out of build environments. Use short-lived, workload-issued credentials on runners instead of static keys in environment variables. See our Cloud Workload Identity Guide.
- Rotate secrets on hosts that installed 1.1.7. Treat any credential on a machine that installed the bad version as exposed and check for miners.
Frequently asked questions
Which Rspack versions were malicious?
Version 1.1.7 of @rspack/core and @rspack/cli, published on 19 December 2024 with a compromised npm token. It was deprecated, and 1.1.8 was released as the safe version.
What did the malicious Rspack release do?
A postinstall script ran after installation. According to The Hacker News and Sonatype, it sent configuration details including cloud service credentials to a remote server, targeted machines in selected countries and installed the XMRig cryptocurrency miner on Linux hosts.
How did attackers get Rspack's npm token?
Rspack has not said. The maintainers confirmed a compromised npm token was used and reset all related tokens. Earlier in 2024, Praetorian showed that Rspack's CI workflows could leak an npm token, but that issue was fixed at the time and no source links it to this attack.
Related NHI Mgmt Group resources
Ultralytics PyPI compromise 2024 · Lottie Player npm compromise 2024 · Solana web3.js npm compromise 2024 · CI/CD Pipeline Identity Security Guide · Secrets Management Guide
How NHI Mgmt Group can help
Publishing tokens and CI secrets are non-human identities that rarely get an owner, an expiry date or a review. We help engineering and security teams find them, replace them with short-lived credentials and respond fast when one leaks. See our NHI and AI agent security training.
References
- Praetorian: Compromising ByteDance's Rspack using GitHub Actions Vulnerabilities (31 May 2024)
- Rspack (GitHub): v1.1.8 release notes and security incident statement (19 December 2024)
- Sonatype: npm Packages From rspack, vant Compromised, Blocked by Sonatype (20 December 2024)
- The Hacker News: Rspack npm Packages Compromised with Crypto Mining Malware in Supply Chain Attack (20 December 2024)