A sophisticated supply chain attack on the npm package ‘rand-user-agent’ was discovered on May 5, 2025, inserting a Remote Access Trojan (RAT) named “RATatouille.” It affects around 45,000 weekly downloads, compromising user systems by establishing covert communication with malicious servers. Users of versions post-October 2024 are urged to check for indicators of compromise and unauthorized changes.

20 Years old Proxy Botnet Network Dismantled That Exploits 1000 Unique Unpatched Devices Weekly
Lumen Technologies, in collaboration with the DOJ, FBI, and Dutch National Police, dismantled a long-running criminal proxy network that exploited IoT and end-of-life devices. This