Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

All-Round for Work & Play: KTC Dual-Mode Monitor H27P6 Adapts to Full-Scenario Needs

June 6, 2026

FishWar Partners With RATGPT To Enhance Web3 Gaming Experience With Decentralized AI Network

June 6, 2026

Bitcoin reclaims $61,000 after dipping below $60,000 in an AI-led rout

June 6, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Cryptomining Malware Found in Popular Open Source Packages
Cryptomining Malware Found in Popular Open Source Packages
Security and Privacy

Cryptomining Malware Found in Popular Open Source Packages

December 23, 2024No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A series of high-profile compromises targeting popular open source packages have been uncovered, exposing the growing risk of malicious code infiltration in widely used software tools. 

Threat actors implanted cryptomining malware in packages associated with rspack, a JavaScript bundler, and vant, a Vue UI library for mobile web apps. Together, these tools see hundreds of thousands of weekly downloads from npm, a major package manager.

The breaches, discovered by security researchers at ReversingLabs, affected @rspack/core and @rspack/cli versions 1.1.7, which were swiftly removed and replaced with clean versions (1.1.8), according to rspack maintainers.

Similarly, vant’s compromised versions (spanning 2.13.3 to 4.9.14) were patched with a malware-free update (version 4.9.15). The malicious code used in these packages included the XMRig cryptominer, a recurring tool in recent supply chain attacks.

String of Open Source Threats

These incidents are part of a broader trend in open source software compromises. Just weeks earlier, malicious actors targeted @lottiefiles/lottie-player, an animation plugin with over 100,000 weekly downloads, embedding crypto wallet-stealing malware. Another attack on a Solana blockchain library jeopardized user wallets, while the ultralytics Python package was exploited to distribute the XMRig cryptominer.

Read more on cryptocurrency threats: Crypto-Hackers Steal $2.2bn as North Koreans Dominate

ReversingLabs explained that the rspack and vant breaches stemmed from stolen npm tokens, enabling attackers to upload tainted versions. In the ultralytics case, GitHub Actions Script Injection and a stolen PyPI API token facilitated the attack. Each incident showcased tell-tale signs, such as obfuscated code and unauthorized communication with external servers.

Spotting and Preventing Compromises

Differential analysis played a critical role in uncovering these breaches. By comparing clean and malicious versions, researchers detected new files, obfuscated JavaScript and suspicious external URLs. 

See also  NY County IT Supervisor Charged with Crypto-Mining

“By performing differential analysis between two versions of software, differential policies can detect behaviors and changes characteristic for known software supply chain attacks, thus perhaps avoiding those attacks before they happen,” said ReversingLabs software threat researcher Lucija Valentić.

Differential analysis is just one of several methods to combat such attacks. Other approaches include implementing strict access controls to prevent unauthorized changes, routinely scanning software dependencies for vulnerabilities and using automated tools to monitor for suspicious behavior in package updates.

Source link

Cryptomining Malware open Packages Popular source
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Infosecurity Europe: AI-Powered Cybercrime Tools Surge on Dark Web

June 3, 2026

Open Transaction Layer Goes Live

May 31, 2026

Fireblocks, Robinhood, MetaMask join crypto giants to launch Open Transaction Layer

May 30, 2026

Ethereum Flashes A Rare Signal As Open Interest Reaches Highest Level Since 2019

May 30, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Alchemy Pay Partners with Kontos for zk-Powered Omnichain Infrastructure

May 29, 2024

Ransomware Payments Fall by 40% in 2022

May 31, 2023

SLNH Up 94% in a Single Day

September 29, 2025

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

All-Round for Work & Play: KTC Dual-Mode Monitor H27P6 Adapts to Full-Scenario Needs

June 6, 2026

FishWar Partners With RATGPT To Enhance Web3 Gaming Experience With Decentralized AI Network

June 6, 2026

Bitcoin reclaims $61,000 after dipping below $60,000 in an AI-led rout

June 6, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$60,957.00-2.79%
  • ethereumEthereum(ETH)$1,571.45-5.64%
  • tetherTether(USDT)$1.000.04%
  • binancecoinBNB(BNB)$577.00-1.96%
  • usd-coinUSDC(USDC)$1.00-0.02%
  • rippleXRP(XRP)$1.09-3.09%
  • solanaSolana(SOL)$62.76-4.31%
  • tronTRON(TRX)$0.320771-1.17%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.030.95%
  • HyperliquidHyperliquid(HYPE)$59.92-2.40%