Malicious npm Package Masquerades as PostCSS Utility to Deliver PowerShell Downloader
ID: 2327b0e8-15e0-5bdb-a0c0-2c9fcb1754f3
STIX ID: report--2327b0e8-15e0-5bdb-a0c0-2c9fcb1754f3
Feed Name: GBHackers
A malicious npm package, masquerading as the legitimate postcss-selector-parser, was found delivering a multi-stage Windows RAT: an encoded JavaScript dropper unpacks a PowerShell downloader which retrieves a Windows bundle containing a bundled Python runtime and compiled extension modules. The RAT implements persistence, single-instance enforcement, VM checks, remote shell and file transfer capabilities, and a Chrome credential-theft module; static analysis recovered C2 infrastructure (http://95.216.92.207:8080), multiple SHA-256 IOCs, and related malicious npm packages, with remediation guidance to remove affected packages, scan dependency trees, block network indicators, and search for artifact names like %TEMP%\winPatch and chost.exe.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
