Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious npm Packages Exploit PostCSS Tools for Windows RAT

Malicious npm Packages Exploit PostCSS Tools for Windows RAT

Posted on June 23, 2026 By CWS

Cybersecurity experts have identified a group of harmful npm packages masquerading as PostCSS tools, intended to deploy a Windows-based remote access trojan (RAT). The discovery highlights a significant threat within the developer ecosystem, where seemingly benign dependencies are utilized for malicious purposes.

Identified Malicious Packages

The problematic npm packages include ‘aes-decode-runner-pro,’ ‘postcss-minify-selector,’ and ‘postcss-minify-selector-parser,’ with downloads ranging from 145 to 615 times. Published by a user named ‘abdrizak’ over the past month, these packages remain accessible on the npm repository. According to JFrog, these packages pretend to be legitimate tools, although they ultimately lead to the same malware payload on Windows systems.

These packages are equipped with a JavaScript dropper that executes a PowerShell script, initiating a download from an external server ‘nvidiadriver[.]net.’ This process results in a ZIP archive containing a Visual Basic Script and other components necessary for the malware’s execution.

Functionality and Impact

The RAT is designed to collect host information, extract credentials from Google Chrome, and execute shell commands. It also facilitates file transfers to and from a command-and-control (C2) server at ‘95.216.92[.]207:8080.’ The underlying Python modules, such as ‘config.pyd’ and ‘api.pyd,’ play crucial roles in its malicious operations.

JFrog emphasized the importance of recognizing that even minor parser-like packages can conceal complex, multi-stage attacks under the guise of legitimate software tools. This situation calls for heightened vigilance among developers and cybersecurity professionals alike.

Wider Security Concerns

This discovery aligns with other ongoing campaigns impacting the npm and TypeScript ecosystems. These include packages like ‘apintergrationpost,’ which delivers a Linux RAT while masquerading as a Node.js integration tool, and ‘@withgoogle/stitch-sdk,’ which targets developer credentials.

Users who have installed any of these malicious packages are urged to promptly uninstall them and eliminate any related artifacts. Additionally, they should change credentials on affected machines to mitigate further risks.

Broader Implications and Future Outlook

The findings coincide with a broader supply chain attack targeting the ‘gonex-AI/Understand-Anything’ tool, further underscoring the complexity and reach of such threats. Moreover, there are overlaps with the North Korean campaign PolinRider, which exploits legitimate repositories to distribute malware.

These incidents illustrate how familiar tactics, when combined, can exploit detection gaps, posing significant challenges to cybersecurity defenses. As these threats evolve, continuous monitoring and proactive security measures remain crucial to safeguarding software supply chains.

The Hacker News Tags:Cybersecurity, developer security, JFrog analysis, malicious packages, NPM, PostCSS, remote access trojan, SafeDep, supply chain attack, Windows RAT

Post navigation

Previous Post: Researcher Secures $148,337 for Google Cloud Vulnerability
Next Post: Russian Brokers Exploit FortiGate Firewalls in Cyber Campaign

Related Posts

npm Worm Targets Hundreds of Packages with Credential Theft npm Worm Targets Hundreds of Packages with Credential Theft The Hacker News
Google Launches DBSC Open Beta in Chrome and Enhances Patch Transparency via Project Zero Google Launches DBSC Open Beta in Chrome and Enhances Patch Transparency via Project Zero The Hacker News
XDigo Malware Exploits Windows LNK Flaw in Eastern European Government Attacks XDigo Malware Exploits Windows LNK Flaw in Eastern European Government Attacks The Hacker News
APT28 Exploits Microsoft Office Flaw in Malware Attacks APT28 Exploits Microsoft Office Flaw in Malware Attacks The Hacker News
Amazon Disrupts APT29 Watering Hole Campaign Abusing Microsoft Device Code Authentication Amazon Disrupts APT29 Watering Hole Campaign Abusing Microsoft Device Code Authentication The Hacker News
Critical Dahua Camera Flaws Enable Remote Hijack via ONVIF and File Upload Exploits Critical Dahua Camera Flaws Enable Remote Hijack via ONVIF and File Upload Exploits The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CSS Vulnerabilities Threaten Webmail Security
  • Atlassian Rovo Vulnerable to Data Exfiltration Risks
  • Critical Metabase Flaw Exploited, Urgent Patch Released
  • OpenAI Delays Astra AI Model to Address Cybersecurity Risks
  • UNC6671 Cyber Threat Intensifies with Vishing Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CSS Vulnerabilities Threaten Webmail Security
  • Atlassian Rovo Vulnerable to Data Exfiltration Risks
  • Critical Metabase Flaw Exploited, Urgent Patch Released
  • OpenAI Delays Astra AI Model to Address Cybersecurity Risks
  • UNC6671 Cyber Threat Intensifies with Vishing Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark