logo

Supply chain attack hits npm package with 45,000 weekly downloads

ID: c860cba5-bac8-536c-8285-ee02fa21faa6

STIX ID: report--c860cba5-bac8-536c-8285-ee02fa21faa6

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-05-08

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

An npm package 'rand-user-agent' was compromised in a supply-chain attack: unauthorized versions (1.0.110, 2.0.83, 2.0.84) contained obfuscated code that installed a persistent remote access trojan (RAT). The malware creates a hidden ~/.node_modules directory, extends module.paths to load axios and socket.io-client, reports host details to a C2 at http://85.239.62.36:3306, and accepts commands for shell execution and file exfiltration; affected users should perform full system scans because downgrading does not remove the RAT.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.