Popular npm package compromised with RAT in supply chain attack

BleepingComputer reports that malicious code injected into the deprecated yet widely downloaded npm package 'rand-user-agent' as part of a supply chain attack has facilitated the deployment of a remote access trojan on systems where it has been installed.

Introduction to Malware Binary Triage (IMBT) Course

Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.

Article Link: Popular npm package compromised with RAT in supply chain attack | SC Media