Supply chain attack compromises rspack, Vant packages with XMRig cryptominer


BleepingComputer reports that high-performance JavaScript bundler Rspack and customizable Vue.js UI library Vant had a trio of widely-used npm packages discovered by Sonatype and Socket researchers to have been breached to facilitate the distribution of the XMRig cryptocurrency mining malware as part of a supply chain attack



Source link