#remotetrojan

2025-05-08

A trusted npm package, "rand-user-agent," was found hiding a remote access Trojan—putting thousands of systems at risk. How did this sneak into your code, and what can you do to stay safe?

thedefendopsdiaries.com/unders

#supplychainattack
#npmsecurity
#remotetrojan
#cybersecurity
#softwarevulnerabilities

2025-05-08

A supposedly handy Discord debug tool on PyPI was actually a sneaky RAT, amassing over 11,000 downloads before being pulled. How did this stealth attack slip into our trusted open-source supply chain?

thedefendopsdiaries.com/malici

#pypi
#discord
#cybersecurity
#remotetrojan
#softwaresecurity

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst