NPM Supply Chain Attack Uses undicy-http to Deploy RAT
ID: c167089f-1aec-5886-b13a-ffa1a97d08a9
STIX ID: report--c167089f-1aec-5886-b13a-ffa1a97d08a9
Feed Name: GBHackers
JFrog Security discovered an npm typosquatting supply-chain package (undicy-http v2.0.0) impersonating the undici HTTP client that installs a Node.js RAT and drops a native Windows injector/stealer (chromelevator.exe) attributed to LofyGang; the toolkit offers remote shell, multi-monitor screen/audio streaming, microphone/webcam capture, broad browser and wallet credential theft, layered persistence, anti-VM/anti-debugging, and exfiltration via Discord/Telegram and third-party file hosts, with active C2 and payload hosts identified and systems where the native binary executed considered fully compromised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
