logo

Minirat’s Stealth Supply Chain Attack Targets macOS Developers

ID: d0e64786-d998-5e7d-a4ac-d5ab1c04b06d

STIX ID: report--d0e64786-d998-5e7d-a4ac-d5ab1c04b06d

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-01

Date Updated: 2026-05-01

Author: Ddos

...
...

Iru researchers discovered Minirat, a Go-written macOS RAT distributed through a compromised npm package (velora-dex-sdk) targeting developer endpoints; the malware detects sandboxes, ensures single-instance execution, establishes persistence via .zshrc and a LaunchAgent, stores AES-encrypted C2 lists (key disclosed), and supports directory exfiltration, remote command execution, and payload retrieval via JSON channels.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.