news.mlab.sh
Back to the feed
malware

Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT

High
Image: The Hacker News
Summary

A series of malicious npm packages, disguised as PostCSS tools, have been discovered delivering a Windows-based remote access trojan (RAT). These packages, published by 'abdrizak', leveraged legitimate build tooling to distribute a complex payload involving PowerShell, a ZIP archive containing a VB script and Python runtime, and a sophisticated RAT with features like credential theft and C2 communication. This highlights the risks associated with seemingly innocuous npm packages and the importance of scrutinizing dependencies within the JavaScript ecosystem.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.