A VPN program from China was secretly tampered with to deliver malware to unsuspecting users, according to researchers at cybersecurity vendor Fortinet. The attack targeted Windows installations for QuickFox VPN. Fortinet suspects a state-sponsored Chinese hacking group called Mustang Panda (aka Twill Typhoon) is behind it. Researchers uncovered the threat in malicious JavaScript within an "embedded Electron renderer HTML file bundled" into the legitimate QuickFox app. Fortinet adds that the malware seems to be restricted to only Windows computers, even though the malicious JavaScript was present in the Mac installer.