Cybersecurity experts have identified a series of harmful npm packages that have been created to deploy a Windows-based remote access trojan (RAT). These packages, which have been available for download in the last month, were uploaded by a user on npm. The identified packages include 'aes-decode-runner-pro' with 145 downloads, 'postcss-minify-selector' with 256 downloads, and 'postcss-minify-selector-parser' with 615 downloads. The malicious intent behind these packages highlights the ongoing risks associated with third-party libraries in software development. Developers are urged to exercise caution and verify the authenticity of npm packages before integrating them into their projects. This incident serves as a reminder of the importance of maintaining security practices in the open-source ecosystem.
Malicious npm Packages Masquerade as PostCSS Tools to Distribute Windows RAT
A recent investigation has uncovered several harmful npm packages that disguise themselves as PostCSS utilities to spread a Windows remote access trojan.
