cognitive cybersecurity intelligence

News and Analysis

Search

New Supply Chain Attack Targets Legitimate npm Package with 45,000 Weekly Downloads

New Supply Chain Attack Targets Legitimate npm Package with 45,000 Weekly Downloads

A sophisticated supply chain attack on the npm package ‘rand-user-agent’ was discovered on May 5, 2025, inserting a Remote Access Trojan (RAT) named “RATatouille.” It affects around 45,000 weekly downloads, compromising user systems by establishing covert communication with malicious servers. Users of versions post-October 2024 are urged to check for indicators of compromise and unauthorized changes.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts