# StreamRAT

Android banking trojan that steals credentials and enables remote control of infected devices.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## StreamRat Android malware spreads through Meta and TikTok ads

DevFeed: [StreamRat Android malware spreads through Meta and TikTok ads](<https://devfeed.tech/articles/streamrat-android-malware-spreads-through-meta-and-tiktok-ads-8441.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/news/2026/09/streamrat-android-malware-spreads-through-meta-and-tiktok-ads>)

Author: Pieter Arntz

Published: 2026-09-03T16:04:24Z

Content type: news

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [StreamRAT](<https://devfeed.tech/topics/streamrat.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [ads](<https://devfeed.tech/tags/ads.md>), [advertising](<https://devfeed.tech/tags/advertising.md>), [android](<https://devfeed.tech/tags/android.md>), [browser](<https://devfeed.tech/tags/browser.md>), [malware](<https://devfeed.tech/tags/malware.md>), [meta](<https://devfeed.tech/tags/meta.md>), [news](<https://devfeed.tech/tags/news.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [scam](<https://devfeed.tech/tags/scam.md>), [security](<https://devfeed.tech/tags/security.md>), [social-media](<https://devfeed.tech/tags/social-media.md>), [streaming](<https://devfeed.tech/tags/streaming.md>), [streamrat](<https://devfeed.tech/tags/streamrat.md>), [threat-intel](<https://devfeed.tech/tags/threat-intel.md>), [tiktok](<https://devfeed.tech/tags/tiktok.md>)

### AI overview

A malicious ad campaign used fake streaming-service promotions on Meta and TikTok to distribute the StreamRat Android banking Trojan. The campaign directed Android users to a tailored download page that coached them past security warnings and enabled credential theft and remote device control.

### Source excerpt

Social media ads for a free streaming service exposed roughly 570,000 people to StreamRat, a banking Trojan that can take control of infected phones.

## Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT

DevFeed: [Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT](<https://devfeed.tech/articles/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform-rat-7839.md>)

Original publisher: [Read original article](<https://snyk.io/blog/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform/>)

Author: Liran Tal

Published: 2026-03-30T23:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [npm](<https://devfeed.tech/topics/npm.md>), [StreamRAT](<https://devfeed.tech/topics/streamrat.md>), [cross-platform](<https://devfeed.tech/topics/cross-platform.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [ide](<https://devfeed.tech/topics/ide.md>), [client](<https://devfeed.tech/topics/client.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [c2](<https://devfeed.tech/tags/c2.md>), [ci](<https://devfeed.tech/tags/ci.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [code](<https://devfeed.tech/tags/code.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [github](<https://devfeed.tech/tags/github.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [macos](<https://devfeed.tech/tags/macos.md>), [malware](<https://devfeed.tech/tags/malware.md>), [obfuscation](<https://devfeed.tech/tags/obfuscation.md>), [payload](<https://devfeed.tech/tags/payload.md>), [remote-access-trojan](<https://devfeed.tech/tags/remote-access-trojan.md>), [security](<https://devfeed.tech/tags/security.md>), [server](<https://devfeed.tech/tags/server.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

### AI overview

The article analyzes a supply-chain attack in which malicious Axios versions published to npm through a compromised maintainer account introduced a hidden dependency. Installing the affected packages could trigger a postinstall dropper that downloaded a platform-specific remote access trojan, contacted a command-and-control server, and erased evidence after execution.

### Source excerpt

Meta description: Malicious versions of the Axios npm package (1.14.1 and 0.30.4) were published via a compromised maintainer account, injecting a hidden dependency that deploys a cross-platform remote access trojan. Here's what happened, who's affected, and how to check your exposure.