Malicious Activity Uncovered in XMLRPC npm Library: Data Theft and Crypto Mining

Reports from cybersecurity experts reveal an ongoing software supply chain breach that has been operational for more than a year within the npm package registry.

Reports from cybersecurity experts reveal an ongoing software supply chain breach that has been operational for more than a year within the npm package registry. Initially appearing as a harmless library, the attackers later injected harmful code into it to pilfer confidential information and execute cryptocurrency mining operations on compromised devices. The library, identified as @0xengine/xmlrpc, was initially released on October 2, 2023, functioning as a JavaScript-driven XML-RPC implementation.

About Author

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.