Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Fake CAPTCHA Installs Malware That Kills 145 Security Processes
August 20, 2026
New Android Malware Steals Banking PINs and Relays Data Through Infected Phones
August 20, 2026
Critical Microsoft 365 Flaw Lets Attackers Bypass MFA, Hijack Mailboxes
August 20, 2026
Home/Threats/Critical npm Supply Chain Attack Uses undicy-http to Deploy RAT
Threats

Critical npm Supply Chain Attack Uses undicy-http to Deploy RAT

Key Takeaways A critical supply chain attack targeting the npm ecosystem leveraged a malicious package named undicy-http. The attack deploys a sophisticated Remote Access Trojan (RAT) capable of...

Marcus Rodriguez
Marcus Rodriguez
April 1, 2026 2 Min Read
46 0

Key Takeaways

  • A critical supply chain attack targeting the npm ecosystem leveraged a malicious package named undicy-http.
  • The attack deploys a sophisticated Remote Access Trojan (RAT) capable of evading detection and stealing sensitive information.
  • Developers using Node.js are at risk, particularly those who may have installed the compromised package.
  • Immediate action is required to remove the malicious package, terminate related processes, and secure affected systems and accounts.

Sophisticated npm Supply Chain Attack Delivers Stealthy RAT

A recent and highly concerning supply chain attack has infiltrated the npm package repository, distributing a potent Remote Access Trojan (RAT) through a malicious package identified as undicy-http. This sophisticated threat is designed for stealthy execution and extensive data exfiltration, posing a significant risk to developers and the integrity of their systems.

Table Of Content

  • Key Takeaways
  • Sophisticated npm Supply Chain Attack Delivers Stealthy RAT
  • Attack Mechanics and Evasion Techniques
  • Payload Capabilities and Data Theft
  • What You Should Do

Attack Mechanics and Evasion Techniques

The undicy-http package, once executed, initiates a multi-stage infection process. Researchers indicate that the malware actively scans for common cybersecurity analysis tools, including Wireshark, IDA Pro, and Ghidra, in an apparent attempt to detect and evade reverse engineering efforts. To further deceive victims, the payload generates a fake “missing DLL” Windows error dialog, a classic social engineering tactic designed to mask its true malicious activities which continue silently in the background.

A particularly advanced component of this attack involves a native binary, chromelevator.exe. This executable employs direct syscalls, bypassing standard ntdll.dll APIs. This technique allows it to circumvent user-mode EDR (Endpoint Detection and Response) and antivirus hooks, making detection and termination significantly more challenging for traditional security solutions.

Payload Capabilities and Data Theft

The RAT delivered by undicy-http is engineered to compromise a wide array of user data and credentials. While specific details on the range of stolen information were not fully enumerated in the source, the comprehensive cleanup steps outlined by researchers strongly suggest that the malware aims to exfiltrate session tokens, passwords, and potentially cryptocurrency wallet information.

What You Should Do

  • Immediately Uninstall: Run npm uninstall undicy-http to remove the malicious package from your development environment.
  • Terminate Processes: End all active node and wscript.exe processes on affected systems.
  • Remove Scheduled Tasks and Registry Keys: Delete the ScreenLiveClient scheduled task and its associated registry key.
  • Clean Temporary Files: Remove all VBS files from your temporary folder.
  • Reinstall Discord Clients: Reinstall all Discord clients to ensure any injected code is cleared.
  • Rotate Credentials: Urgently rotate all passwords, Discord tokens, and session credentials for critical services such as Roblox, Instagram, Spotify, TikTok, Steam, and Telegram.
  • Secure Cryptocurrency: If applicable, transfer all cryptocurrency to new wallets with freshly generated seed phrases, ideally on a verified clean machine.
  • Block C2 Infrastructure: Block the command-and-control (C2) IP address 24[.]152[.]36[.]243 and domain amoboobs[.]com at your network perimeter.
  • System Re-imaging: If chromelevator.exe was executed on a system, a complete system re-imaging is strongly advised. Manual cleanup might not guarantee the full restoration of system trust due to the advanced evasion techniques employed.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

Attack

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Critical PNG Vulnerabilities Expose Systems to Crashes, Info Leaks

Next Post

Critical Telnyx Python SDK Backdoor Steals Credentials on Windows, macOS, Linux

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Red Hat OpenShift CVE-2023-39418 Exposes Internal Services
August 20, 2026
OpenAI Pauses AI Model Training Over 0-Day Discovery Concerns
August 20, 2026
Cisco AnyConnect VPN Client Critical RCE Vulnerability CVE-2020-3556 Patched
August 20, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us