logo

NPM Supply Chain Attack Uses undicy-http to Deploy RAT

ID: c167089f-1aec-5886-b13a-ffa1a97d08a9

STIX ID: report--c167089f-1aec-5886-b13a-ffa1a97d08a9

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-04-01

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

JFrog Security discovered an npm typosquatting supply-chain package (undicy-http v2.0.0) impersonating the undici HTTP client that installs a Node.js RAT and drops a native Windows injector/stealer (chromelevator.exe) attributed to LofyGang; the toolkit offers remote shell, multi-monitor screen/audio streaming, microphone/webcam capture, broad browser and wallet credential theft, layered persistence, anti-VM/anti-debugging, and exfiltration via Discord/Telegram and third-party file hosts, with active C2 and payload hosts identified and systems where the native binary executed considered fully compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.