Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious npm Packages Exploit PostCSS Tools for Windows RAT

Malicious npm Packages Exploit PostCSS Tools for Windows RAT

Posted on June 23, 2026 By CWS

Cybersecurity experts have identified a group of harmful npm packages masquerading as PostCSS tools, intended to deploy a Windows-based remote access trojan (RAT). The discovery highlights a significant threat within the developer ecosystem, where seemingly benign dependencies are utilized for malicious purposes.

Identified Malicious Packages

The problematic npm packages include ‘aes-decode-runner-pro,’ ‘postcss-minify-selector,’ and ‘postcss-minify-selector-parser,’ with downloads ranging from 145 to 615 times. Published by a user named ‘abdrizak’ over the past month, these packages remain accessible on the npm repository. According to JFrog, these packages pretend to be legitimate tools, although they ultimately lead to the same malware payload on Windows systems.

These packages are equipped with a JavaScript dropper that executes a PowerShell script, initiating a download from an external server ‘nvidiadriver[.]net.’ This process results in a ZIP archive containing a Visual Basic Script and other components necessary for the malware’s execution.

Functionality and Impact

The RAT is designed to collect host information, extract credentials from Google Chrome, and execute shell commands. It also facilitates file transfers to and from a command-and-control (C2) server at ‘95.216.92[.]207:8080.’ The underlying Python modules, such as ‘config.pyd’ and ‘api.pyd,’ play crucial roles in its malicious operations.

JFrog emphasized the importance of recognizing that even minor parser-like packages can conceal complex, multi-stage attacks under the guise of legitimate software tools. This situation calls for heightened vigilance among developers and cybersecurity professionals alike.

Wider Security Concerns

This discovery aligns with other ongoing campaigns impacting the npm and TypeScript ecosystems. These include packages like ‘apintergrationpost,’ which delivers a Linux RAT while masquerading as a Node.js integration tool, and ‘@withgoogle/stitch-sdk,’ which targets developer credentials.

Users who have installed any of these malicious packages are urged to promptly uninstall them and eliminate any related artifacts. Additionally, they should change credentials on affected machines to mitigate further risks.

Broader Implications and Future Outlook

The findings coincide with a broader supply chain attack targeting the ‘gonex-AI/Understand-Anything’ tool, further underscoring the complexity and reach of such threats. Moreover, there are overlaps with the North Korean campaign PolinRider, which exploits legitimate repositories to distribute malware.

These incidents illustrate how familiar tactics, when combined, can exploit detection gaps, posing significant challenges to cybersecurity defenses. As these threats evolve, continuous monitoring and proactive security measures remain crucial to safeguarding software supply chains.

The Hacker News Tags:Cybersecurity, developer security, JFrog analysis, malicious packages, NPM, PostCSS, remote access trojan, SafeDep, supply chain attack, Windows RAT

Post navigation

Previous Post: Researcher Secures $148,337 for Google Cloud Vulnerability
Next Post: Russian Brokers Exploit FortiGate Firewalls in Cyber Campaign

Related Posts

PlayPraetor Android Trojan Infects 11,000+ Devices via Fake Google Play Pages and Meta Ads PlayPraetor Android Trojan Infects 11,000+ Devices via Fake Google Play Pages and Meta Ads The Hacker News
Anthropic’s Claude Code Leak: Human Error Leads to Source Code Exposure Anthropic’s Claude Code Leak: Human Error Leads to Source Code Exposure The Hacker News
Critical Flaw in Funnel Builder Targets WooCommerce Critical Flaw in Funnel Builder Targets WooCommerce The Hacker News
CrashFix Chrome Extension Delivers ModeloRAT Using ClickFix-Style Browser Crash Lures CrashFix Chrome Extension Delivers ModeloRAT Using ClickFix-Style Browser Crash Lures The Hacker News
TA558 Uses AI-Generated Scripts to Deploy Venom RAT in Brazil Hotel Attacks TA558 Uses AI-Generated Scripts to Deploy Venom RAT in Brazil Hotel Attacks The Hacker News
Meta Rolls Out New Tools to Protect WhatsApp and Messenger Users from Scams Meta Rolls Out New Tools to Protect WhatsApp and Messenger Users from Scams The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AWS Highlights Risks of Unmonitored Outbound Cloud Traffic
  • Massive Credential Theft Targets FortiGate Firewalls Worldwide
  • Global Call for Cybersecurity Grants by Internet Society
  • Bajaj Auto Hit by Ransomware, Systems Compromised
  • Trump Boosts Post-Quantum Cryptography Efforts with New Order

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AWS Highlights Risks of Unmonitored Outbound Cloud Traffic
  • Massive Credential Theft Targets FortiGate Firewalls Worldwide
  • Global Call for Cybersecurity Grants by Internet Society
  • Bajaj Auto Hit by Ransomware, Systems Compromised
  • Trump Boosts Post-Quantum Cryptography Efforts with New Order

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark