logo

New npm Supply Chain Attack Uses undicy-http to Deploy Screen-Streaming RAT and Browser Injector

ID: 691c38ed-4751-5aab-b65a-424bb1640cae

STIX ID: report--691c38ed-4751-5aab-b65a-424bb1640cae

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-04-01

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A malicious npm package, "undicy-http", impersonating the legitimate Node.js HTTP client "undici", delivers a two-stage attack: a Node.js RAT providing remote shell, screen/microphone/webcam access and persistence, and a native Windows stealer "chromelevator.exe" that injects into browsers to exfiltrate passwords, cookies, session tokens, credit cards, and crypto wallet data. The campaign, attributed to LofyGang, includes anti-analysis and EDR-bypass techniques, uploads exfiltrated data to services (gofile.io, catbox.moe), and uses Discord and Telegram for data exfiltration and command-and-control (C2 IP 24.152.36.243, domain amoboobs.com); remediation steps and YARA rule linkage are provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.