0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

JFrog discovers malicious npm package postcss-minify-selector-parser delivering Windows RAT (infosecurity-magazine.com)

· 34d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • Typosquatting npm package postcss-minify-selector-parser mimics genuine postcss-selector-parser to deliver a multi-stage Windows RAT.
  • The attack chain uses AES-256-GCM decryption, PowerShell downloader, and a Nuitka-compiled Python RAT with persistence and data theft capabilities.
  • Two additional packages (postcss-minify-selector, aes-decode-runner-pro) linked to the same publisher abdrizak were found; package remained live on npm at time of discovery.

"JFrog security researchers identified a typosquatting npm package named postcss-minify-selector-parser, impersonating the popular postcss-selector-parser (150M+ weekly downloads). The malicious package contained an AES-256-GCM encrypted blob that decodes to a dropper, which downloads a PowerShell script from nvidiadriver[.]net, then a ZIP archive containing a Nuitka-compiled Python RAT. The RAT steals browser credentials, including defeating Google Chrome's app-bound encryption, and provides remote shell and file transfer capabilities. The package was still available on npm at time of publication. Two associated packages were also found: postcss-minify-selector and aes-decode-runner-pro, all linked to publisher abdrizak."

Discussion Matrix

0 segments

no comments yet.