logo

Windows RAT Uses Encrypted HTTP C2 and Registry Persistence After npm Infection

ID: 89ce126f-a0fd-5fb3-bff8-e95f58d37152

STIX ID: report--89ce126f-a0fd-5fb3-bff8-e95f58d37152

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-06-22

Date Updated: 2026-06-23

Author: Tushar Subhra Dutta

...
...

A supply-chain malware campaign was discovered where typosquatted npm packages (notably postcss-minify-selector-parser) install a multi-stage Windows RAT on developer machines; the RAT (compiled with Nuitka) persists via a Run registry entry, communicates with an RC4-wrapped HTTP C2, supports remote shell/file operations and VM evasion, and includes a module to steal Chrome-saved credentials. JFrog published the analysis and the report contains IPs, domains, file paths, filenames, and SHA-256 hashes as IoCs and recommends removing affected packages, blocking network indicators, and rotating compromised credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.