{"id":11771,"date":"2026-04-01T10:06:23","date_gmt":"2026-04-01T10:06:23","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/01\/new-npm-supply-chain-attack-uses-undicy-http-to-deploy-screen-streaming-rat-and-browser-injector\/"},"modified":"2026-04-01T10:06:23","modified_gmt":"2026-04-01T10:06:23","slug":"new-npm-supply-chain-attack-uses-undicy-http-to-deploy-screen-streaming-rat-and-browser-injector","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/01\/new-npm-supply-chain-attack-uses-undicy-http-to-deploy-screen-streaming-rat-and-browser-injector\/","title":{"rendered":"New npm Supply Chain Attack Uses undicy-http to Deploy Screen-Streaming RAT and Browser Injector"},"content":{"rendered":"<p>    New npm Supply Chain Attack Uses undicy-http to Deploy Screen-Streaming RAT and Browser Injector<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A malicious npm package named\u00a0<code>undicy-http<\/code>\u00a0has surfaced inside the Node.js developer ecosystem, quietly compromising machines of developers who mistakenly install it. <\/p>\n<p>The package impersonates\u00a0<code>undici<\/code>, the official HTTP client library bundled with Node.js that handles millions of weekly downloads. Despite sharing a near-identical name,\u00a0<code>undicy-http<\/code>\u00a0contains zero HTTP client functionality. <\/p>\n<p>Instead, it launches a two-stage attack capable of stealing browser credentials, hijacking active sessions, and giving attackers live remote access to a victim\u2019s screen, microphone, and webcam.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/921bdf76-da4d-4cb8-9862-1123ac8966c6\/New-npm-Supply-Chain-Attack-Uses-undicy-http-to-Deploy-Screen-Streaming-RAT-and-Browser-Injector.pdf?AWSAccessKeyId=ASIA2F3EMEYEQ6GO6CNK&amp;Signature=tPgg0Ou9bKcpMJq1op%2FBCZERUsw%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCmEkxtwxZqXi7ur7BvTMDzn9xPbTlUtEC8TX50olYFXAIhAOxJ8wYeGGjpCFDMYejKo48i0NH4SX6ucHxwcDkEffkyKvMECFAQARoMNjk5NzUzMzA5NzA1IgyrPQJ2QQ07viQAebEq0ATPgKmfW1yCR0QJD9y%2BGx%2FL5ixoJQ48ut2KZxjdBoSl8ATsoadOZq1ZyQYI47Huic7Mgl%2Ff2hM3Zrhb%2FHyL7Xa7XeDHpq4yC1Xy8rOvNlNRCLwTnBMdPeQTl1WS9iqWgRKaPRoakif0mFfu5TuRA7RiuJRqN8KEC2QcCfLxJJxBAVpgXOOyg1B8jnYAxYapqnAlUWS%2F26CoBvoAb8N9YtJcikVheYzSbobP8DiwjQx4uD9R34yeosuYgB9wl1axaD0sT6EFQvkPo2%2BHQ%2B2%2B5OaTQqzXtDeUMS0Qp2br%2F%2B5%2FAHcqAvuvdAEX%2BDe5V0cp3eNxEBdgen%2B0iiVDzKkaat%2BDSpSOnMPqAwz6QQfBLt%2Bj5frd%2B537zDOxS4RkFYBL%2BEqn5Pl8FHsQqfSXy4fbV06arH6cqjQpIxmDaxoK6M5ruzhWbHyf%2BPTfqGSJAnc1iGzE6NGkXE%2B2B%2BodaMAdNs65g9475ikWf0jUqD%2FUj1Qa0GGPwS3fSozqvCDqa5XLXKzb0kGXxFg4mezvuRykBhsm6USAlcBdAWSQqg1BeOrdec5BZ7GgsxIlX6ZKyndkioWQyWEBj7BDU6%2By%2BOl7hZCKVFaYee1GBIOhworePiLNa05JOisZm5GvJicBrQiTOTz3ho6eS3%2FRqAwcjYh8ShM5J8Uc5hHVQv9BPNZCIV%2FVu8MgELyf2ZioHEIhRl06oGJrMkLQBiA1Ix6alCIMd0e63Fk2aU4h%2FBd95BAUfJ%2BolEHlrszUquaT68jg65%2FV8apbhdXdX22Ehycl1vIEQZ0PMJWAs84GOpcBJjJ4m5pfoX6PcxLs6CiZMeRiBSazJviVrkJ4eEduSWT3qmrGvjv8KHr0viOCJncmHmETYoISeNM7WRCAnN0L6Bhuhd9Gz1vEnVFUGJO9o%2B9BumQKOLSwZUt83NjXNgw5MZk5Tztacbm7pwYTbrsYb%2Fy361xmaprNcVSEYHipTb%2BMAg8md%2Fo4QKzKc7dNE2kPAN8rEox86g%3D%3D&amp;Expires=1775026984\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>The package (version 2.0.0) delivers two payloads that work in parallel. The first is a Node.js-based Remote Access Trojan that connects to an attacker-controlled WebSocket server, enabling remote shell execution, screen streaming, file uploads, and microphone and webcam recording. <\/p>\n<p>The second is a native Windows executable called\u00a0<code>chromelevator.exe<\/code>, which injects into browser processes at the operating system level to steal passwords, cookies, credit card numbers, IBANs, and session tokens from over 50 browsers and 90 cryptocurrency wallet extensions.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/921bdf76-da4d-4cb8-9862-1123ac8966c6\/New-npm-Supply-Chain-Attack-Uses-undicy-http-to-Deploy-Screen-Streaming-RAT-and-Browser-Injector.pdf?AWSAccessKeyId=ASIA2F3EMEYEQ6GO6CNK&amp;Signature=tPgg0Ou9bKcpMJq1op%2FBCZERUsw%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCmEkxtwxZqXi7ur7BvTMDzn9xPbTlUtEC8TX50olYFXAIhAOxJ8wYeGGjpCFDMYejKo48i0NH4SX6ucHxwcDkEffkyKvMECFAQARoMNjk5NzUzMzA5NzA1IgyrPQJ2QQ07viQAebEq0ATPgKmfW1yCR0QJD9y%2BGx%2FL5ixoJQ48ut2KZxjdBoSl8ATsoadOZq1ZyQYI47Huic7Mgl%2Ff2hM3Zrhb%2FHyL7Xa7XeDHpq4yC1Xy8rOvNlNRCLwTnBMdPeQTl1WS9iqWgRKaPRoakif0mFfu5TuRA7RiuJRqN8KEC2QcCfLxJJxBAVpgXOOyg1B8jnYAxYapqnAlUWS%2F26CoBvoAb8N9YtJcikVheYzSbobP8DiwjQx4uD9R34yeosuYgB9wl1axaD0sT6EFQvkPo2%2BHQ%2B2%2B5OaTQqzXtDeUMS0Qp2br%2F%2B5%2FAHcqAvuvdAEX%2BDe5V0cp3eNxEBdgen%2B0iiVDzKkaat%2BDSpSOnMPqAwz6QQfBLt%2Bj5frd%2B537zDOxS4RkFYBL%2BEqn5Pl8FHsQqfSXy4fbV06arH6cqjQpIxmDaxoK6M5ruzhWbHyf%2BPTfqGSJAnc1iGzE6NGkXE%2B2B%2BodaMAdNs65g9475ikWf0jUqD%2FUj1Qa0GGPwS3fSozqvCDqa5XLXKzb0kGXxFg4mezvuRykBhsm6USAlcBdAWSQqg1BeOrdec5BZ7GgsxIlX6ZKyndkioWQyWEBj7BDU6%2By%2BOl7hZCKVFaYee1GBIOhworePiLNa05JOisZm5GvJicBrQiTOTz3ho6eS3%2FRqAwcjYh8ShM5J8Uc5hHVQv9BPNZCIV%2FVu8MgELyf2ZioHEIhRl06oGJrMkLQBiA1Ix6alCIMd0e63Fk2aU4h%2FBd95BAUfJ%2BolEHlrszUquaT68jg65%2FV8apbhdXdX22Ehycl1vIEQZ0PMJWAs84GOpcBJjJ4m5pfoX6PcxLs6CiZMeRiBSazJviVrkJ4eEduSWT3qmrGvjv8KHr0viOCJncmHmETYoISeNM7WRCAnN0L6Bhuhd9Gz1vEnVFUGJO9o%2B9BumQKOLSwZUt83NjXNgw5MZk5Tztacbm7pwYTbrsYb%2Fy361xmaprNcVSEYHipTb%2BMAg8md%2Fo4QKzKc7dNE2kPAN8rEox86g%3D%3D&amp;Expires=1775026984\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p><a href=\"https:\/\/research.jfrog.com\/post\/lofygang-returns-a-dual-payload-npm-package\/\" id=\"https:\/\/research.jfrog.com\/post\/lofygang-returns-a-dual-payload-npm-package\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">JFrog Security researchers identified the package<\/a> on March 31, 2026, attributing it to the threat group known as LofyGang. The package\u2019s author field reads\u00a0<code>ConsoleLofy<\/code>, a direct match to LofyGang\u2019s documented alias dictionary. <\/p>\n<p>Hardcoded strings reading\u00a0<code>\"Lofygang Started\"<\/code>\u00a0and Portuguese-language log messages throughout the code confirm the group\u2019s Brazilian roots. <\/p>\n<p>This campaign marks a significant step up from previous LofyGang attacks, which used only JavaScript to steal Discord tokens and credit card data.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/921bdf76-da4d-4cb8-9862-1123ac8966c6\/New-npm-Supply-Chain-Attack-Uses-undicy-http-to-Deploy-Screen-Streaming-RAT-and-Browser-Injector.pdf?AWSAccessKeyId=ASIA2F3EMEYEQ6GO6CNK&amp;Signature=tPgg0Ou9bKcpMJq1op%2FBCZERUsw%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCmEkxtwxZqXi7ur7BvTMDzn9xPbTlUtEC8TX50olYFXAIhAOxJ8wYeGGjpCFDMYejKo48i0NH4SX6ucHxwcDkEffkyKvMECFAQARoMNjk5NzUzMzA5NzA1IgyrPQJ2QQ07viQAebEq0ATPgKmfW1yCR0QJD9y%2BGx%2FL5ixoJQ48ut2KZxjdBoSl8ATsoadOZq1ZyQYI47Huic7Mgl%2Ff2hM3Zrhb%2FHyL7Xa7XeDHpq4yC1Xy8rOvNlNRCLwTnBMdPeQTl1WS9iqWgRKaPRoakif0mFfu5TuRA7RiuJRqN8KEC2QcCfLxJJxBAVpgXOOyg1B8jnYAxYapqnAlUWS%2F26CoBvoAb8N9YtJcikVheYzSbobP8DiwjQx4uD9R34yeosuYgB9wl1axaD0sT6EFQvkPo2%2BHQ%2B2%2B5OaTQqzXtDeUMS0Qp2br%2F%2B5%2FAHcqAvuvdAEX%2BDe5V0cp3eNxEBdgen%2B0iiVDzKkaat%2BDSpSOnMPqAwz6QQfBLt%2Bj5frd%2B537zDOxS4RkFYBL%2BEqn5Pl8FHsQqfSXy4fbV06arH6cqjQpIxmDaxoK6M5ruzhWbHyf%2BPTfqGSJAnc1iGzE6NGkXE%2B2B%2BodaMAdNs65g9475ikWf0jUqD%2FUj1Qa0GGPwS3fSozqvCDqa5XLXKzb0kGXxFg4mezvuRykBhsm6USAlcBdAWSQqg1BeOrdec5BZ7GgsxIlX6ZKyndkioWQyWEBj7BDU6%2By%2BOl7hZCKVFaYee1GBIOhworePiLNa05JOisZm5GvJicBrQiTOTz3ho6eS3%2FRqAwcjYh8ShM5J8Uc5hHVQv9BPNZCIV%2FVu8MgELyf2ZioHEIhRl06oGJrMkLQBiA1Ix6alCIMd0e63Fk2aU4h%2FBd95BAUfJ%2BolEHlrszUquaT68jg65%2FV8apbhdXdX22Ehycl1vIEQZ0PMJWAs84GOpcBJjJ4m5pfoX6PcxLs6CiZMeRiBSazJviVrkJ4eEduSWT3qmrGvjv8KHr0viOCJncmHmETYoISeNM7WRCAnN0L6Bhuhd9Gz1vEnVFUGJO9o%2B9BumQKOLSwZUt83NjXNgw5MZk5Tztacbm7pwYTbrsYb%2Fy361xmaprNcVSEYHipTb%2BMAg8md%2Fo4QKzKc7dNE2kPAN8rEox86g%3D%3D&amp;Expires=1775026984\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>The attack\u2019s reach goes beyond browser data. The malware targets session data from six platforms \u2014 Roblox, Instagram, Spotify, TikTok, Steam, and Telegram. <\/p>\n<p>It also goes after 28 desktop <a href=\"https:\/\/cybersecuritynews.com\/cryptocore-cryptocurrency-scam-draining-wallets\/\" id=\"74531\" target=\"_blank\" rel=\"noreferrer noopener\">cryptocurrency wallets<\/a>, six hardware wallet integrations including Ledger and Trezor, and over 90 browser wallet extensions. <\/p>\n<p>Stolen data moves through two channels simultaneously \u2014 a Discord webhook and a Telegram bot \u2014 with large files first uploaded to gofile.io or catbox.moe before download links reach the attacker.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/921bdf76-da4d-4cb8-9862-1123ac8966c6\/New-npm-Supply-Chain-Attack-Uses-undicy-http-to-Deploy-Screen-Streaming-RAT-and-Browser-Injector.pdf?AWSAccessKeyId=ASIA2F3EMEYEQ6GO6CNK&amp;Signature=tPgg0Ou9bKcpMJq1op%2FBCZERUsw%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCmEkxtwxZqXi7ur7BvTMDzn9xPbTlUtEC8TX50olYFXAIhAOxJ8wYeGGjpCFDMYejKo48i0NH4SX6ucHxwcDkEffkyKvMECFAQARoMNjk5NzUzMzA5NzA1IgyrPQJ2QQ07viQAebEq0ATPgKmfW1yCR0QJD9y%2BGx%2FL5ixoJQ48ut2KZxjdBoSl8ATsoadOZq1ZyQYI47Huic7Mgl%2Ff2hM3Zrhb%2FHyL7Xa7XeDHpq4yC1Xy8rOvNlNRCLwTnBMdPeQTl1WS9iqWgRKaPRoakif0mFfu5TuRA7RiuJRqN8KEC2QcCfLxJJxBAVpgXOOyg1B8jnYAxYapqnAlUWS%2F26CoBvoAb8N9YtJcikVheYzSbobP8DiwjQx4uD9R34yeosuYgB9wl1axaD0sT6EFQvkPo2%2BHQ%2B2%2B5OaTQqzXtDeUMS0Qp2br%2F%2B5%2FAHcqAvuvdAEX%2BDe5V0cp3eNxEBdgen%2B0iiVDzKkaat%2BDSpSOnMPqAwz6QQfBLt%2Bj5frd%2B537zDOxS4RkFYBL%2BEqn5Pl8FHsQqfSXy4fbV06arH6cqjQpIxmDaxoK6M5ruzhWbHyf%2BPTfqGSJAnc1iGzE6NGkXE%2B2B%2BodaMAdNs65g9475ikWf0jUqD%2FUj1Qa0GGPwS3fSozqvCDqa5XLXKzb0kGXxFg4mezvuRykBhsm6USAlcBdAWSQqg1BeOrdec5BZ7GgsxIlX6ZKyndkioWQyWEBj7BDU6%2By%2BOl7hZCKVFaYee1GBIOhworePiLNa05JOisZm5GvJicBrQiTOTz3ho6eS3%2FRqAwcjYh8ShM5J8Uc5hHVQv9BPNZCIV%2FVu8MgELyf2ZioHEIhRl06oGJrMkLQBiA1Ix6alCIMd0e63Fk2aU4h%2FBd95BAUfJ%2BolEHlrszUquaT68jg65%2FV8apbhdXdX22Ehycl1vIEQZ0PMJWAs84GOpcBJjJ4m5pfoX6PcxLs6CiZMeRiBSazJviVrkJ4eEduSWT3qmrGvjv8KHr0viOCJncmHmETYoISeNM7WRCAnN0L6Bhuhd9Gz1vEnVFUGJO9o%2B9BumQKOLSwZUt83NjXNgw5MZk5Tztacbm7pwYTbrsYb%2Fy361xmaprNcVSEYHipTb%2BMAg8md%2Fo4QKzKc7dNE2kPAN8rEox86g%3D%3D&amp;Expires=1775026984\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>Notably,\u00a0<code>chromelevator.exe<\/code>\u00a0matches a YARA detection rule named\u00a0<code>MAL_Browser_Stealer_Dec25_2<\/code>, associated with the broader GlassWorm Campaign attack framework. <\/p>\n<p>Since December 2025, that rule has matched over 1,750 malicious samples, with new matches recorded through March 2026.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/921bdf76-da4d-4cb8-9862-1123ac8966c6\/New-npm-Supply-Chain-Attack-Uses-undicy-http-to-Deploy-Screen-Streaming-RAT-and-Browser-Injector.pdf?AWSAccessKeyId=ASIA2F3EMEYEQ6GO6CNK&amp;Signature=tPgg0Ou9bKcpMJq1op%2FBCZERUsw%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEIf%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJIMEYCIQCmEkxtwxZqXi7ur7BvTMDzn9xPbTlUtEC8TX50olYFXAIhAOxJ8wYeGGjpCFDMYejKo48i0NH4SX6ucHxwcDkEffkyKvMECFAQARoMNjk5NzUzMzA5NzA1IgyrPQJ2QQ07viQAebEq0ATPgKmfW1yCR0QJD9y%2BGx%2FL5ixoJQ48ut2KZxjdBoSl8ATsoadOZq1ZyQYI47Huic7Mgl%2Ff2hM3Zrhb%2FHyL7Xa7XeDHpq4yC1Xy8rOvNlNRCLwTnBMdPeQTl1WS9iqWgRKaPRoakif0mFfu5TuRA7RiuJRqN8KEC2QcCfLxJJxBAVpgXOOyg1B8jnYAxYapqnAlUWS%2F26CoBvoAb8N9YtJcikVheYzSbobP8DiwjQx4uD9R34yeosuYgB9wl1axaD0sT6EFQvkPo2%2BHQ%2B2%2B5OaTQqzXtDeUMS0Qp2br%2F%2B5%2FAHcqAvuvdAEX%2BDe5V0cp3eNxEBdgen%2B0iiVDzKkaat%2BDSpSOnMPqAwz6QQfBLt%2Bj5frd%2B537zDOxS4RkFYBL%2BEqn5Pl8FHsQqfSXy4fbV06arH6cqjQpIxmDaxoK6M5ruzhWbHyf%2BPTfqGSJAnc1iGzE6NGkXE%2B2B%2BodaMAdNs65g9475ikWf0jUqD%2FUj1Qa0GGPwS3fSozqvCDqa5XLXKzb0kGXxFg4mezvuRykBhsm6USAlcBdAWSQqg1BeOrdec5BZ7GgsxIlX6ZKyndkioWQyWEBj7BDU6%2By%2BOl7hZCKVFaYee1GBIOhworePiLNa05JOisZm5GvJicBrQiTOTz3ho6eS3%2FRqAwcjYh8ShM5J8Uc5hHVQv9BPNZCIV%2FVu8MgELyf2ZioHEIhRl06oGJrMkLQBiA1Ix6alCIMd0e63Fk2aU4h%2FBd95BAUfJ%2BolEHlrszUquaT68jg65%2FV8apbhdXdX22Ehycl1vIEQZ0PMJWAs84GOpcBJjJ4m5pfoX6PcxLs6CiZMeRiBSazJviVrkJ4eEduSWT3qmrGvjv8KHr0viOCJncmHmETYoISeNM7WRCAnN0L6Bhuhd9Gz1vEnVFUGJO9o%2B9BumQKOLSwZUt83NjXNgw5MZk5Tztacbm7pwYTbrsYb%2Fy361xmaprNcVSEYHipTb%2BMAg8md%2Fo4QKzKc7dNE2kPAN8rEox86g%3D%3D&amp;Expires=1775026984\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<h2 class=\"wp-block-heading\" id=\"infection-chain-how-the-malware-hides-and-persists\"><strong>Infection Chain: How the Malware Hides and Persists<\/strong><\/h2>\n<p>When a developer installs\u00a0<code>undicy-http<\/code>, the main script (<code>index.js<\/code>) checks immediately whether it is running as a hidden process. <\/p>\n<p>If not, it writes a VBScript file to the system\u2019s temp folder and re-launches itself using\u00a0<code>wscript.exe<\/code>\u00a0with a hidden window, leaving no visible trace of execution.<\/p>\n<p>The malware then establishes three persistence mechanisms to survive system restarts. It first creates a scheduled task named\u00a0<code>ScreenLiveClient<\/code>\u00a0that launches at login with the highest available system privileges. <\/p>\n<p>If that step fails, it falls back to writing a registry run key. As a final option, it places a copy of itself in the Windows Startup folder. The VBScript launcher file is then hidden using\u00a0<code>attrib +h +s<\/code>\u00a0to avoid easy detection.\u00a0<\/p>\n<p>To avoid <a href=\"https:\/\/cybersecuritynews.com\/best-cloud-security-tools\/\" id=\"11635\" target=\"_blank\" rel=\"noreferrer noopener\">security tools<\/a>, the malware runs ten anti-VM checks targeting MAC addresses, BIOS strings, disk names, and active processes to detect sandbox environments such as ANY.RUN, Cuckoo, and Triage. <\/p>\n<p>It also looks for analysis tools like Wireshark, IDA, and Ghidra. To deceive the victim, it pops up a fake missing-DLL Windows error dialog while the payload continues running silently in the background. <\/p>\n<p>The native binary\u00a0<code>chromelevator.exe<\/code>\u00a0goes even further by using direct syscalls that sidestep standard\u00a0<code>ntdll.dll<\/code>\u00a0APIs, bypassing EDR and antivirus hooks at the user-mode level.\u00a0<\/p>\n<p>Developers should immediately run\u00a0<code>npm uninstall undicy-http<\/code>, end all\u00a0<code>node<\/code>\u00a0and\u00a0<code>wscript.exe<\/code>\u00a0processes, and remove the\u00a0<code>ScreenLiveClient<\/code>\u00a0scheduled task and its registry key. <\/p>\n<p>Delete the VBS files from the temp folder and reinstall all Discord clients to clear injected code. Rotate all passwords, <a href=\"https:\/\/cybersecuritynews.com\/malicious-python-package-mimic-as-attacking-discord-developers\/\" id=\"105182\" target=\"_blank\" rel=\"noreferrer noopener\">Discord tokens<\/a>, and session credentials for Roblox, Instagram, Spotify, TikTok, Steam, and Telegram. <\/p>\n<p>Move cryptocurrency to new wallets with fresh seed phrases on a clean machine, and block the C2 address\u00a0<code>24[.]152[.]36[.]243<\/code>\u00a0and domain\u00a0<code>amoboobs[.]com<\/code>. Re-imaging the system is advised if\u00a0<code>chromelevator.exe<\/code>\u00a0ran, as manual cleanup alone cannot guarantee full system trust.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-npm-supply-chain-attack-uses-undicy-http\/\">New npm Supply Chain Attack Uses undicy-http to Deploy Screen-Streaming RAT and Browser Injector<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-npm-supply-chain-attack-uses-undicy-http\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New npm Supply Chain Attack Uses undicy-http to Deploy Screen-Streaming RAT and Browser Injector A malicious npm package named\u00a0undicy-http\u00a0has surfaced inside the Node.js developer ecosystem, quietly compromising machines of developers who mistakenly install it. The package impersonates\u00a0undici, the official HTTP client library bundled with Node.js that handles millions of weekly downloads. Despite sharing a near-identical [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-11771","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11771"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11771"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11771\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11771"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11771"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11771"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}