logo

RATatouille: A Malicious Recipe Hidden in rand-user-agent (Supply Chain Compromise)

ID: ee436c38-718c-5848-bdeb-2281360d5811

STIX ID: report--ee436c38-718c-5848-bdeb-2281360d5811

Feed Name: Aikido Security's Blog

Threat Score
85/100

Date Published: 2025-05-06

Date Updated: 2026-07-24

...
...

The npm package 'rand-user-agent' (≈45k weekly downloads) was backdoored in post-release versions with heavily obfuscated JavaScript that installs a RAT: it ensures axios/socket.io-client are available in a hidden ~/.node_modules, connects to a socket.io C2 at http://85.239.62.36:3306, uploads files to http://85.239.62.36:27017/u/f, supports remote command execution and directory/file upload, and performs a Windows PATH hijack to facilitate malicious binaries. The report includes code excerpts, capabilities, and IOCs to help detection and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.