The ua-parser-js npm Supply Chain Attack
Updated 5 Oct 2026 · Incident date 22 Oct 2021 · npm
ua-parser-js 0.7.28 -> 0.7.29 (also 0.8.0 and 1.0.0)preinstall.jsOn 22 October 2021, attackers published three malicious versions of the npm package ua-parser-js: 0.7.29, 0.8.0 and 1.0.0. The package parses browser user-agent strings and is very widely used. The last safe version of the old line was 0.7.28.
The GitHub advisory states that any computer that installed or ran one of these versions must be considered fully compromised.
What happened
An attacker took over the package account and published three releases that ran a script at install time. Google Cloud (Mandiant) reports that the malicious versions went up between 16:14 and 16:25 UTC on 22 October 2021. The npm registry warning on the package said that it had been hijacked and told users to revert to 0.7.28.
Each release had a preinstall entry in package.json that ran preinstall.js. On Windows, the script downloaded two programs:
jsextension.exe, a Monero cryptocurrency miner, fetched from159.148.186[.]228.create.dll, the DanaBot banking trojan, fetched fromcitationsherbe[.]at/sdd.dlland run withregsvr32.exe -s create.dll.
On Linux, the script downloaded the same miner, named jsextension. It stopped if the machine was in Russia, Ukraine, Belarus or Kazakhstan. The script did nothing on macOS. DanaBot can run remote code, log keys, take screenshots and steal credentials.
Mandiant also lists later hijacks of coa and rc on 4 November 2021 that delivered a modified DanaBot DLL.
Vigilance compares the version you trust with the new one. These releases added a preinstall script and new files that 0.7.28 did not have. Vigilance reports the file that gained that capability. See the scan block below.
Affected versions
ua-parser-js0.7.29, 0.8.0 and 1.0.0.- Patched: 0.7.30, 0.8.1 and 1.0.1.
Related incidents that Mandiant lists:
coa2.0.3, 2.0.4, 2.1.1, 2.1.3 and 3.1.3. Safe: 2.0.2.rc1.2.9, 1.3.9 and 2.3.9. Safe: 1.2.8.
Indicators of compromise
- Files:
preinstall.js,jsextension.exe(miner),jsextension(Linux miner),create.dllandsdd.dll. - MD5 of
jsextension.exe:fc724eb2894f34a3aca4b952d2f816cd. - MD5 of
sdd.dll(DanaBot):de8b54a938ac18f15cad804d79a0e19d. - Download host:
159.148.186[.]228. Download domain:citationsherbe[.]at. - DanaBot command servers (port 443):
185.158.250[.]216,45.11.180[.]153,194.76.225[.]46,194.76.225[.]61. - For
coaandrc: the domainpastorcryptograph[.]at.
How to check
Show every copy of the package in the tree and in the npm cache.
npm ls ua-parser-js coa rc --all
grep -rEn "ua-parser-js@(0.7.29|0.8.0|1.0.0)|\"version\": \"(0.7.29|0.8.0|1.0.0)\"" package-lock.json
On a machine that possibly installed a bad version, also search for the dropped files, jsextension, jsextension.exe and create.dll.
What to do now
- Upgrade to 0.7.30, 0.8.1 or 1.0.1. Check
coaandrctoo. - If a bad version installed, treat the machine as fully compromised. Rotate every secret and key from a different, clean system.
- Remove the dropped files. The advisory warns that removing the package does not remove malware that its install script already placed.
- Run a forensic review for unauthorized access.
- Lock dependency versions and review install scripts before you update.
What Vigilance showed
Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.
files scanned: 16 (1 Added) HEADS UP 1 file can now do things the old version could not. The rest changed and gained nothing. NEW FILE preinstall.js It runs a command on its own when it is installed, downloads from the internet and reads saved passwords and access keys.
Frequently asked questions
Which versions of ua-parser-js were compromised?
Versions 0.7.29, 0.8.0 and 1.0.0 were compromised. The patched versions are 0.7.30, 0.8.1 and 1.0.1.
What did the malicious ua-parser-js versions install?
On Windows they installed a Monero miner and the DanaBot banking trojan. On Linux they installed the miner. They did nothing on macOS.
Sources
More supply chain attacks
- @apexacc/cli Defender-blinding C2 loader 17 Sept 2026
- keyv / cacheable npm worm (Shai-Hulud third wave) 4 Aug 2026
- Mastra AI npm compromise (Sapphire Sleet) 17 Jun 2026
- TanStack npm compromise (Mini Shai-Hulud) 11 May 2026
All 111 attacks in the library · npm supply chain attacks · How to prevent supply chain attacks
Check the next update before you install it
Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.