New Supply Chain Attack Targets Widely Used npm Package with 45,000 Weekly Downloads
ID: b1d80ea2-63ad-5fbc-a6ad-2d7bb2bcd1f0
STIX ID: report--b1d80ea2-63ad-5fbc-a6ad-2d7bb2bcd1f0
Feed Name: Cyber Press
A supply-chain compromise was found in the npm package `rand-user-agent` (widely used, ~45k weekly downloads) where injected, heavily obfuscated code implements a Remote Access Trojan that installs hidden dependencies in ~/.node_modules, connects to a socket.io C2 at http://85.239.62.36:3306, uploads files to http://85.239.62.36:27017/u/f, executes shell commands via Node's child_process, and attempts Windows PATH hijacking; affected versions and IOCs are provided along with remediation advice.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
