logo

Npm Trojan Bypasses UAC, Installs AnyDesk with "Oscompatible" Package

ID: f60e4fe6-06d3-5198-8728-3096077c636f

STIX ID: report--f60e4fe6-06d3-5198-8728-3096077c636f

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2024-01-19

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

### Executive Summary A trojanized npm package named "oscompatible" (published Jan 9, 2024) was used to deploy a sophisticated Windows RAT via a multi-stage chain that abuses DLL search-order hijacking, decrypts additional payloads, retrieves an AnyDesk installer and a remote access DLL from a hostile domain, and implements credential/evidence collection (Chrome extension manipulation, keystroke/mouse capture, disabling shutdown). The package was removed after ~380 downloads but demonstrates a notable open-source supply-chain abuse with advanced TTPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.