Skip to content
Malicious npm Packages Deliver Windows RAT via PostCSS Impersonation

Malicious npm Packages Deliver Windows RAT via PostCSS Impersonation

First seen 23 Jun 2026, 09:42 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 24, 2026 at 09:31 UTC
  • Malicious npm package mimics legitimate PostCSS utility to deliver a RAT.
  • The package has over 150 million weekly downloads, increasing its risk exposure.
  • Developers using npm are the primary targets of this attack.

A malicious npm package named postcss-minify-selector-parser has been discovered, masquerading as a legitimate PostCSS utility. This package is delivering a multi-stage Windows remote access trojan (RAT). It mimics the widely used postcss-selector-parser library, which has over 150 million weekly downloads, by reusing similar keywords. The attack targets developers using npm, potentially compromising their systems. The malicious package exploits the trust placed in popular libraries, leading to significant risks for users. Current reports indicate that the package has been identified and flagged, but the full extent of the impact is still being assessed. Users are advised to check their dependencies for this malicious package.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 90d ago How this analysis works

Timeline

2026-06-22
Malicious npm package discovered
The postcss-minify-selector-parser was found to deliver a multi-stage Windows RAT, impersonating a legitimate library.
Gbhackers
2026-06-23
Further reporting on malicious npm packages
The Hacker News published additional insights into the threat posed by these malicious packages, emphasizing the risk to developers.
Thehackernews

More articles in this cluster (4)