Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT
ID: 56e01d9c-40fd-5c24-b65a-de81c039373d
STIX ID: report--56e01d9c-40fd-5c24-b65a-de81c039373d
Feed Name: The Hacker News
Security researchers found multiple malicious npm packages that act as a supply-chain delivery mechanism for a multi-stage Windows remote access trojan (RAT). The chain uses a JavaScript dropper to write and execute a PowerShell downloader that retrieves a ZIP containing a VBScript launcher, a bundled Python runtime, a Python loader, and native extension modules (.pyd) which implement RAT functionality (host profiling, Chrome credential and extension theft, file transfer, shell execution) communicating with hardcoded C2 servers; several other malicious npm packages and a link to a North Korean-linked supply-chain operation (PolinRider) are also described. Users are advised to remove affected packages, clean artifacts, and rotate credentials on developer machines.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
