“The discovery also follows a report from Aikido about a supply chain attack that has compromised a legitimate npm package called "rand-user-agent" to inject code that conceals a remote access trojan (RAT). Versions 2.0.83, 2.0.84, and 1.0.110 have been found to be malicious. ”