Npm Trojan Bypasses UAC, Installs AnyDesk with "Oscompatible" Package
ID: f60e4fe6-06d3-5198-8728-3096077c636f
STIX ID: report--f60e4fe6-06d3-5198-8728-3096077c636f
Feed Name: The Hacker News
### Executive Summary A trojanized npm package named "oscompatible" (published Jan 9, 2024) was used to deploy a sophisticated Windows RAT via a multi-stage chain that abuses DLL search-order hijacking, decrypts additional payloads, retrieves an AnyDesk installer and a remote access DLL from a hostile domain, and implements credential/evidence collection (Chrome extension manipulation, keystroke/mouse capture, disabling shutdown). The package was removed after ~380 downloads but demonstrates a notable open-source supply-chain abuse with advanced TTPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
