An npm package named 'rand-user-agent' has been compromised in a supply chain attack, with the aim of injecting camouflaged code that triggers a remote access trojan (RAT) into the user's system
See also: Malicious NPM packages target PayPal users

The 'rand-user-agent' package is a tool that generates random user-agent strings, useful for processes such as web scraping , automated testing, and cybersecurity research.
Although the package has been marked as deprecated, it remains relatively popular, with around 45,000 downloads per week. However, according to Aikido, malicious actors have exploited the fact that it was partially abandoned but still widespread to inject malicious code into unauthorized later versions, which are likely to have been downloaded from a large number of downstream projects.
Aikido discovered the breach on May 5 , 2025 , when its malware analysis system detected the new version 1.0.110 of 'rand-user-agent'. Upon deeper analysis, the researchers found camouflaged code in the 'dist/index.js' file , which was only visible if the user scrolled horizontally through the source code on the npm website.
The investigation showed that the last valid version of 'rand-user-agent' was 2.0.82, which was released 7 months. Versions 2.0.83, 2.0.84 , and also 1.0.110, which were released subsequently, were malicious and did not have corresponding versions in the GitHub repository .
See also: Malicious npm package targets Atomic Wallet and Exodus
The malicious code embedded in newer versions creates a hidden folder in the user's home directory (in ~/.node_modules ) and expands 'module.paths' , so that this custom path can be used to load dependencies, specifically the 'axios' and 'socket.io-client' packages .

The code then opens a persistent socket connection to the attacker's C2 server, at https://85.239.62[.]36:3306, and sends machine identification information, such as the computer name, username, operating system type , and a generated UUID.
The malicious versions have now been removed from the package repository on npm , so the latest available version is now safe and users are advised to revert to it.
However, if you have upgraded to versions 2.0.83 , 2.0.84 or 1.0.110 , it is important to perform a full scan of your system for any signs of compromise . Please note that rolling back to a legitimate version does not remove the RAT from your system. Additionally, you may want to consider using forks of the 'rand-user-agent' tool that are actively supported and better monitored .
See also: npm packages breached to steal developer data
Based on the above, the 'rand-user-agent' is a typical example of a software supply chain attack, where attackers exploit neglected or insufficiently maintained packages to introduce malicious code that reaches end users through perfectly legitimate channels (such as npm).
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
