HomeSecuritySupply chain attack hits npm package rand-user-agent

Supply chain attack hits npm package rand-user-agent

An npm package named 'rand-user-agent' has been compromised in a supply chain attack, with the aim of injecting camouflaged code that triggers a remote access trojan (RAT) into the user's system

See also: Malicious NPM packages target PayPal users

rand-user-agent

The 'rand-user-agent' package is a tool that generates random user-agent strings, useful for processes such as web scraping , automated testing, and cybersecurity research.

Although the package has been marked as deprecated, it remains relatively popular, with around 45,000 downloads per week. However, according to Aikido, malicious actors have exploited the fact that it was partially abandoned but still widespread to inject malicious code into unauthorized later versions, which are likely to have been downloaded from a large number of downstream projects.

Aikido discovered the breach on May 5 , 2025 , when its malware analysis system detected the new version 1.0.110 of 'rand-user-agent'. Upon deeper analysis, the researchers found camouflaged code in the 'dist/index.js' file , which was only visible if the user scrolled horizontally through the source code on the npm website.

The investigation showed that the last valid version of 'rand-user-agent' was 2.0.82, which was released 7 months. Versions 2.0.83, 2.0.84 , and also 1.0.110, which were released subsequently, were malicious and did not have corresponding versions in the GitHub repository .

See also: Malicious npm package targets Atomic Wallet and Exodus

The malicious code embedded in newer versions creates a hidden folder in the user's home directory (in ~/.node_modules ) and expands 'module.paths' , so that this custom path can be used to load dependencies, specifically the 'axios' and 'socket.io-client' packages .

Supply chain attack hits npm package rand-user-agent

The code then opens a persistent socket connection to the attacker's C2 server, at https://85.239.62[.]36:3306, and sends machine identification information, such as the computer name, username, operating system type , and a generated UUID.

The malicious versions have now been removed from the package repository on npm , so the latest available version is now safe and users are advised to revert to it.

However, if you have upgraded to versions 2.0.83 , 2.0.84 or 1.0.110 , it is important to perform a full scan of your system for any signs of compromise . Please note that rolling back to a legitimate version does not remove the RAT from your system. Additionally, you may want to consider using forks of the 'rand-user-agent' tool that are actively supported and better monitored .

See also: npm packages breached to steal developer data

Based on the above, the 'rand-user-agent' is a typical example of a software supply chain attack, where attackers exploit neglected or insufficiently maintained packages to introduce malicious code that reaches end users through perfectly legitimate channels (such as npm).

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS