Minirat’s Stealth Supply Chain Attack Targets macOS Developers
ID: d0e64786-d998-5e7d-a4ac-d5ab1c04b06d
STIX ID: report--d0e64786-d998-5e7d-a4ac-d5ab1c04b06d
Feed Name: securityonline.info
Threat Score
Iru researchers discovered Minirat, a Go-written macOS RAT distributed through a compromised npm package (velora-dex-sdk) targeting developer endpoints; the malware detects sandboxes, ensures single-instance execution, establishes persistence via .zshrc and a LaunchAgent, stores AES-encrypted C2 lists (key disclosed), and supports directory exfiltration, remote command execution, and payload retrieval via JSON channels.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
