RATatouille:隐藏在rand-user-agent中的恶意配方(供应链攻陷)
aikido.dev | 博客 | #supply-chain | #malware | #npm | #c2 | #supply-chain-attack | #file-exfiltration | #rat | #rand-user-agent | #npm-malware | #socket-io | #path-hijack
摘要
rand-user-agent npm包遭遇供应链攻击:2.0.82之后的版本被植入隐藏代码,部署了一个通过socket.io与C2通信、可窃取文件的RAT,并利用Python PATH劫持建立后门。
- 发布时间
- 收录时间
Skip to content