# Trojanized npm Packages Disguised as PostCSS Tools Deliver Multi-Stage Windows RAT
Cybersecurity researchers have uncovered a sophisticated supply chain attack leveraging malicious npm packages designed to mimic popular PostCSS build tools while delivering a fully-featured Windows remote access trojan (RAT). The discovery reveals an evolving threat landscape where attackers exploit the deep trust developers place in their dependency management systems.
## The Threat
Three malicious npm packages published under the user account "abdrizak" over the past month are currently available on the public npm registry:
All three packages share a common objective: delivering a sophisticated Windows RAT capable of stealing credentials, executing arbitrary commands, and maintaining persistent remote access to compromised systems. Despite public disclosure of the threat, the packages remain available for download at the time of writing.
The packages deliberately mimic legitimate PostCSS ecosystem tools, with particular focus on postcss-selector-parser—a widely-used npm library with over 127 million weekly downloads. This mimicry is intentional, leveraging namespace confusion and the difficulty developers face in distinguishing between legitimate and malicious dependencies.
## How the Attack Works: A Multi-Stage Infection Chain
The attack unfolds through a carefully orchestrated multi-stage payload delivery system designed to evade detection and maximize persistence.
### Stage 1: JavaScript Dropper
Installation of any of the three malicious packages triggers a JavaScript-based dropper embedded in the package. This dropper executes immediately upon installation, requiring no direct user interaction.
### Stage 2: PowerShell Script Execution
The JavaScript dropper writes a PowerShell script ("settings.ps1") to disk and executes it using Windows PowerShell. This stage acts as a loader, establishing communication with the attacker's infrastructure to retrieve the next-stage payload.
### Stage 3: External Payload Retrieval
The PowerShell script uses curl.exe to download a ZIP archive from an attacker-controlled server ("nvidiadriver[.]net"). This domain name is deliberately chosen to blend with legitimate NVIDIA driver distribution infrastructure, adding a layer of social engineering.
### Stage 4: VBScript Execution
The downloaded ZIP archive contains a Visual Basic Script ("update.vbs") that is executed using wscript.exe. The VBScript performs critical setup functions, including establishing the Python runtime environment and launching the core malware logic.
### Stage 5: Python-Based RAT Core
The final stage consists of a Python environment bundled with Nuitka-compiled Python extension modules (.pyd files). These native extensions contain the actual RAT functionality and connect to a command-and-control (C2) server at 95.216.92[.]207:8080.
## Technical Details: The RAT Architecture
The malware employs a sophisticated architecture leveraging compiled Python extensions, each handling specific functionality:
| Extension Module | Function |
|---|---|
| config.pyd | Stores constants, command IDs, C2 URLs, and registry key names |
| api.pyd | Manages HTTP C2 communication and packet exchange |
| audiodriver.pyd | Controls the main RAT orchestration loop |
| command.pyd | Executes host profiling, VM detection, file transfers, and shell commands |
| auto.pyd | Extracts credentials from Google Chrome and steals data from extensions, bypassing app-bound encryption (ABE) protections |
| util.pyd | Provides tar/gzip archive utilities for data exfiltration |
This architecture demonstrates significant sophistication, with clear separation of concerns and evidence of professional development practices—suggesting either experienced threat actors or a custom malware-as-a-service offering.
## RAT Capabilities
Once established on a compromised system, the malware provides attackers with extensive control capabilities:
## The Broader Ecosystem Under Siege
This discovery arrives amid a wave of similar npm ecosystem attacks, revealing a coordinated—or at minimum, highly synchronized—surge in supply chain targeting of JavaScript developers.
apintergrationpost: A malicious package distributed as a "Node.js integration client for authorized red team exercises" that deploys MYRA, a sophisticated Linux RAT. SafeDep's analysis revealed the package compiles a native C rootkit during installation, establishes three independent persistence mechanisms disguised as a systemd service, and provides interactive shell access with live screen streaming capabilities.
@withgoogle/stitch-sdk: Impersonating Google's legitimate Stitch AI design tool, this package targets developer authentication tokens across eight separate sources including Claude Code, git configuration, SSH keys, GitHub CLI, npm config, Docker configuration, and local git credentials—then exfiltrates them to an attacker-controlled domain ("stitch-production[.]org/api/v1").
These concurrent campaigns suggest either a coordinated attack or a competitive ecosystem where multiple threat actors are racing to compromise the JavaScript development supply chain.
## Implications for Developers and Organizations
The attack pattern reveals critical vulnerabilities in how modern software development relies on trustless third-party code:
For Individual Developers: Every npm install becomes a potential infection vector. The attack requires no user interaction beyond running a standard package installation—the very act developers perform dozens of times daily without conscious deliberation.
For Organizations: Build systems and CI/CD pipelines are now front-line attack targets. A single compromised dependency can deliver RATs across an entire organization's engineering infrastructure, potentially creating persistent backdoors in production systems and source code repositories.
For Enterprise Security Teams: The sophistication of these payloads—multi-stage loaders, VM detection, encryption bypassing, and fileless execution—demonstrates that npm ecosystem attacks have graduated from credential stealers to enterprise-grade remote access tools.
## Recommendations
Immediate Actions:
Ongoing Defenses:
---
## HackWire Analysis
This attack encapsulates a fundamental architectural problem in modern JavaScript development: the implicit trust developers extend to the entire dependency chain. Unlike traditional software supply chains where security teams curate approved vendors, npm represents a democratized ecosystem where anyone can publish—and millions of developers depend on minimal vetting.
The attacker's operational sophistication warrants attention. The multi-stage payload with VM detection, ABE-bypassing Chrome theft, and fileless execution suggests either experienced malware developers or a maturing malware-as-a-service ecosystem. The use of obfuscated names (postcss-minify-selector-parser vs. the legitimate postcss-selector-parser) combined with genuine download numbers (up to 615 before discovery) demonstrates that namespace confusion remains an effective obfuscation technique.
What's particularly notable is the timing: three major npm ecosystem attacks in close succession suggests either coordinated threat actor activity or an arms race where multiple groups recognize the npm ecosystem's value as a supply chain lever. The fact that MYRA, the Linux RAT from apintergrationpost, also uses Nuitka-compiled Python extensions indicates possible shared tooling or infrastructure between campaigns.
For defenders, the painful reality is this: npm's decentralized nature means 100% prevention is mathematically impossible. The practical defense shifts from "never install malicious packages" to "assume compromise and monitor for its indicators." Organizations should treat any npm installation in their build pipeline as a potential C2 channel and implement corresponding network segmentation and monitoring.
— HackWire Editorial
## Related Coverage