logo

Researchers Uncover RAT-Dropping npm Package Targeting Gulp Users

ID: 3bd7fae4-181e-57ff-8cb8-b130bab192ea

STIX ID: report--3bd7fae4-181e-57ff-8cb8-b130bab192ea

Feed Name: The Hacker News

Threat Score
65/100

Date Published: 2024-06-03

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Researchers discovered a malicious npm package, glup-debugger-log, that masquerades as a gulp logger and has been downloaded ~175 times. The package contains obfuscated scripts that perform environmental checks (Windows NT, network interfaces, Desktop item count) to avoid VMs, download additional malware, and establish persistence by launching an HTTP server on port 3004 to receive and execute commands, effectively providing RAT capabilities to attackers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.