Thehackernews Malicious npm Packages Deliver Windows RAT via PostCSS Impersonation
Article Content
- •Malicious npm package mimics legitimate PostCSS utility to deliver a RAT.
- •The package has over 150 million weekly downloads, increasing its risk exposure.
- •Developers using npm are the primary targets of this attack.
A malicious npm package named postcss-minify-selector-parser has been discovered, masquerading as a legitimate PostCSS utility. This package is delivering a multi-stage Windows remote access trojan (RAT). It mimics the widely used postcss-selector-parser library, which has over 150 million weekly downloads, by reusing similar keywords. The attack targets developers using npm, potentially compromising their systems. The malicious package exploits the trust placed in popular libraries, leading to significant risks for users. Current reports indicate that the package has been identified and flagged, but the full extent of the impact is still being assessed. Users are advised to check their dependencies for this malicious package.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…