Windows RAT Uses Encrypted HTTP C2 and Registry Persistence After npm Infection
ID: 89ce126f-a0fd-5fb3-bff8-e95f58d37152
STIX ID: report--89ce126f-a0fd-5fb3-bff8-e95f58d37152
Feed Name: cybersecurityNews.com
A supply-chain malware campaign was discovered where typosquatted npm packages (notably postcss-minify-selector-parser) install a multi-stage Windows RAT on developer machines; the RAT (compiled with Nuitka) persists via a Run registry entry, communicates with an RC4-wrapped HTTP C2, supports remote shell/file operations and VM evasion, and includes a module to steal Chrome-saved credentials. JFrog published the analysis and the report contains IPs, domains, file paths, filenames, and SHA-256 hashes as IoCs and recommends removing affected packages, blocking network indicators, and rotating compromised credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
