logo

UNC3379 npm supply chain attacks (Campaign)

ID: 09236867-6f04-538a-89d0-ecc3f0163627

STIX ID: report--09236867-6f04-538a-89d0-ecc3f0163627

Feed Name: Wiz Cloud Threat Landscape

Threat Score
85/100

Date Published: 2021-12-15

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Mandiant attributes npm supply-chain compromises of ua-parser-js, coa, and rc to UNC3379; the malicious packages installed a Monero cryptocurrency miner and the DANABOT banking trojan depending on the operating system, representing a high-risk supply-chain malware campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.