The rand-user-agent npm Supply Chain Attack
Updated 5 Oct 2026 · Incident date 5 May 2025 · npm
rand-user-agent 2.0.82 -> 2.0.83, 2.0.84 and 1.0.110dist/index.jsrand-user-agent versions 2.0.83, 2.0.84 and 1.0.110 on npm carried a remote access trojan. The last clean release is 2.0.82. The package builds random user-agent strings and has about 45,000 weekly downloads.
The bad code sits in dist/index.js. It opens a permanent connection to an attacker server that can run commands on the machine.
What happened
Attackers published three bad versions of rand-user-agent to npm in early May 2025, and the versions carried a remote access trojan. BleepingComputer reports that the attackers used an outdated automation token that had no two-factor protection. The malicious code was not in the GitHub repository. The developer, WebScrapingAPI, states that there was no breach of its source repository, build pipeline or corporate network.
The sources give different detection dates, from 5 May to 9 May 2025. Aikido, which found the problem, reports detection on 6 May 2025. The last clean version, 2.0.82, was seven months old.
Aikido reports that the code in dist/index.js was obfuscated and hidden off the edge of the screen in the npm file viewer. A package that only builds strings gained code for socket networking, folder creation and remote command execution.
The code makes a hidden folder at ~/.node_modules and extends module.paths so it can load its own copies of axios and socket.io-client. It then connects to the attacker server and sends the host name, user name, operating system and a UUID. The server can send commands. Aikido lists directory commands (cd, ss_dir, ss_fcd), file upload commands (ss_upf, ss_upd), a stop command (ss_stop) and arbitrary shell commands.
On Windows, the code puts %LOCALAPPDATA%\Programs\Python\Python3127 at the front of the system PATH. A program that sits there can replace Python commands without any warning. SecurityWeek calls this backdoor "Python3127 PATH Hijack".
Affected versions
rand-user-agent2.0.83 and 2.0.84.rand-user-agent1.0.110.- Clean: 2.0.82. Malicious versions were removed from npm.
BleepingComputer warns that a downgrade does not remove the trojan. A machine that ran a bad version needs a full scan.
Indicators of compromise
- Command and control:
85.239.62[.]36. Socket.io channel on port 3306 and file upload at port 27017 path/u/f. - A hidden folder
~/.node_modules/that holdsaxiosandsocket.io-client. - On Windows, a PATH entry for
%LOCALAPPDATA%\Programs\Python\Python3127and that folder on disk. - Obfuscated code in
dist/index.jsof the package. - RAT command names:
ss_dir,ss_fcd,ss_upf,ss_upd,ss_stop.
How to check
Look for the bad versions in your projects, then look for the traces on the machine.
npm ls --all rand-user-agent grep -n 'rand-user-agent' package-lock.json ls -la ~/.node_modules 2>/dev/null lsof -nP -i | grep '85.239.62.36'
On Windows, run $env:PATH -split ';' | Select-String Python3127 in PowerShell and look in the Python folder under your local app data. Search firewall logs for the command server address too.
What to do now
- Pin rand-user-agent to 2.0.82 or a later clean release, or move to a maintained fork.
- On any machine that installed a bad version, remove
~/.node_modulesand the PATH change. Do a full scan, since a downgrade does not clean the machine. - Rotate credentials that the machine held. The trojan could run any command and upload files.
- Block the command server address and search logs for past connections.
- Use automation tokens with two-factor protection and retire tokens that you no longer need.
- Vigilance compares a new package version with the one you trust and reports the file that gained a new capability. Here,
dist/index.jsgained socket networking and command execution in a package that only builds strings.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 49 HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. CHANGED dist/index.js It now downloads from the internet and runs other programs. It did not before.
Frequently asked questions
Which rand-user-agent versions were compromised?
Versions 2.0.83, 2.0.84 and 1.0.110. Version 2.0.82 is the last clean release.
What did the rand-user-agent malware do?
It opened a permanent connection to an attacker server and ran commands, uploaded files and, on Windows, changed the PATH to run a fake Python.
How was rand-user-agent compromised?
BleepingComputer reports that the attackers used an outdated npm automation token with no two-factor protection. The bad code never appeared in the GitHub repository.
Does downgrading remove the rand-user-agent RAT?
No. Downgrading to 2.0.82 stops new infections but does not remove the trojan. The machine needs a full scan and credential rotation.
Sources
More supply chain attacks
- @apexacc/cli Defender-blinding C2 loader 17 Sept 2026
- keyv / cacheable npm worm (Shai-Hulud third wave) 4 Aug 2026
- Mastra AI npm compromise (Sapphire Sleet) 17 Jun 2026
- TanStack npm compromise (Mini Shai-Hulud) 11 May 2026
All 111 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.