malware
Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT
High
Summary
A series of malicious npm packages, disguised as PostCSS tools, have been discovered delivering a Windows-based remote access trojan (RAT). These packages, published by 'abdrizak', leveraged legitimate build tooling to distribute a complex payload involving PowerShell, a ZIP archive containing a VB script and Python runtime, and a sophisticated RAT with features like credential theft and C2 communication. This highlights the risks associated with seemingly innocuous npm packages and the importance of scrutinizing dependencies within the JavaScript ecosystem.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
