# Trojanized npm Packages Disguised as PostCSS Tools Deliver Multi-Stage Windows RAT


Cybersecurity researchers have uncovered a sophisticated supply chain attack leveraging malicious npm packages designed to mimic popular PostCSS build tools while delivering a fully-featured Windows remote access trojan (RAT). The discovery reveals an evolving threat landscape where attackers exploit the deep trust developers place in their dependency management systems.


## The Threat


Three malicious npm packages published under the user account "abdrizak" over the past month are currently available on the public npm registry:


  • aes-decode-runner-pro (145 downloads)
  • postcss-minify-selector (256 downloads)
  • postcss-minify-selector-parser (615 downloads)

  • All three packages share a common objective: delivering a sophisticated Windows RAT capable of stealing credentials, executing arbitrary commands, and maintaining persistent remote access to compromised systems. Despite public disclosure of the threat, the packages remain available for download at the time of writing.


    The packages deliberately mimic legitimate PostCSS ecosystem tools, with particular focus on postcss-selector-parser—a widely-used npm library with over 127 million weekly downloads. This mimicry is intentional, leveraging namespace confusion and the difficulty developers face in distinguishing between legitimate and malicious dependencies.


    ## How the Attack Works: A Multi-Stage Infection Chain


    The attack unfolds through a carefully orchestrated multi-stage payload delivery system designed to evade detection and maximize persistence.


    ### Stage 1: JavaScript Dropper

    Installation of any of the three malicious packages triggers a JavaScript-based dropper embedded in the package. This dropper executes immediately upon installation, requiring no direct user interaction.


    ### Stage 2: PowerShell Script Execution

    The JavaScript dropper writes a PowerShell script ("settings.ps1") to disk and executes it using Windows PowerShell. This stage acts as a loader, establishing communication with the attacker's infrastructure to retrieve the next-stage payload.


    ### Stage 3: External Payload Retrieval

    The PowerShell script uses curl.exe to download a ZIP archive from an attacker-controlled server ("nvidiadriver[.]net"). This domain name is deliberately chosen to blend with legitimate NVIDIA driver distribution infrastructure, adding a layer of social engineering.


    ### Stage 4: VBScript Execution

    The downloaded ZIP archive contains a Visual Basic Script ("update.vbs") that is executed using wscript.exe. The VBScript performs critical setup functions, including establishing the Python runtime environment and launching the core malware logic.


    ### Stage 5: Python-Based RAT Core

    The final stage consists of a Python environment bundled with Nuitka-compiled Python extension modules (.pyd files). These native extensions contain the actual RAT functionality and connect to a command-and-control (C2) server at 95.216.92[.]207:8080.


    ## Technical Details: The RAT Architecture


    The malware employs a sophisticated architecture leveraging compiled Python extensions, each handling specific functionality:


    | Extension Module | Function |

    |---|---|

    | config.pyd | Stores constants, command IDs, C2 URLs, and registry key names |

    | api.pyd | Manages HTTP C2 communication and packet exchange |

    | audiodriver.pyd | Controls the main RAT orchestration loop |

    | command.pyd | Executes host profiling, VM detection, file transfers, and shell commands |

    | auto.pyd | Extracts credentials from Google Chrome and steals data from extensions, bypassing app-bound encryption (ABE) protections |

    | util.pyd | Provides tar/gzip archive utilities for data exfiltration |


    This architecture demonstrates significant sophistication, with clear separation of concerns and evidence of professional development practices—suggesting either experienced threat actors or a custom malware-as-a-service offering.


    ## RAT Capabilities


    Once established on a compromised system, the malware provides attackers with extensive control capabilities:


  • Host Profiling: Gathering system information including OS version, installed software, and network configuration
  • VM Detection: Identifying virtual machines to avoid security research environments
  • Credential Theft: Extracting stored credentials from Google Chrome and other chromium-based browsers
  • Extension Exploitation: Stealing data from Chrome extensions, including API keys and authentication tokens
  • Shell Access: Executing arbitrary Windows commands with the privileges of the compromised user
  • File Operations: Uploading files to and downloading files from the C2 server
  • C2 Communication: Full bidirectional communication with attacker infrastructure

  • ## The Broader Ecosystem Under Siege


    This discovery arrives amid a wave of similar npm ecosystem attacks, revealing a coordinated—or at minimum, highly synchronized—surge in supply chain targeting of JavaScript developers.


    apintergrationpost: A malicious package distributed as a "Node.js integration client for authorized red team exercises" that deploys MYRA, a sophisticated Linux RAT. SafeDep's analysis revealed the package compiles a native C rootkit during installation, establishes three independent persistence mechanisms disguised as a systemd service, and provides interactive shell access with live screen streaming capabilities.


    @withgoogle/stitch-sdk: Impersonating Google's legitimate Stitch AI design tool, this package targets developer authentication tokens across eight separate sources including Claude Code, git configuration, SSH keys, GitHub CLI, npm config, Docker configuration, and local git credentials—then exfiltrates them to an attacker-controlled domain ("stitch-production[.]org/api/v1").


    These concurrent campaigns suggest either a coordinated attack or a competitive ecosystem where multiple threat actors are racing to compromise the JavaScript development supply chain.


    ## Implications for Developers and Organizations


    The attack pattern reveals critical vulnerabilities in how modern software development relies on trustless third-party code:


    For Individual Developers: Every npm install becomes a potential infection vector. The attack requires no user interaction beyond running a standard package installation—the very act developers perform dozens of times daily without conscious deliberation.


    For Organizations: Build systems and CI/CD pipelines are now front-line attack targets. A single compromised dependency can deliver RATs across an entire organization's engineering infrastructure, potentially creating persistent backdoors in production systems and source code repositories.


    For Enterprise Security Teams: The sophistication of these payloads—multi-stage loaders, VM detection, encryption bypassing, and fileless execution—demonstrates that npm ecosystem attacks have graduated from credential stealers to enterprise-grade remote access tools.


    ## Recommendations


    Immediate Actions:

  • Audit npm package.json files for the three identified malicious packages
  • Review npm audit logs for any installations of aes-decode-runner-pro, postcss-minify-selector, or postcss-minify-selector-parser
  • Isolate and forensically analyze any systems where these packages were installed
  • Rotate any credentials stored in Chrome or configuration files on potentially compromised systems

  • Ongoing Defenses:

  • Implement npm registry proxies that scan packages for known malicious patterns before installation
  • Require package verification and manual approval for any new or updated dependencies in CI/CD pipelines
  • Monitor build logs for unexpected PowerShell execution or external network connections
  • Establish baseline security monitoring for npm packages, tracking downloads, update frequency, and author reputation
  • Use Software Composition Analysis (SCA) tools that track supply chain risk indicators beyond simple vulnerability scanning

  • ---


    ## HackWire Analysis


    This attack encapsulates a fundamental architectural problem in modern JavaScript development: the implicit trust developers extend to the entire dependency chain. Unlike traditional software supply chains where security teams curate approved vendors, npm represents a democratized ecosystem where anyone can publish—and millions of developers depend on minimal vetting.


    The attacker's operational sophistication warrants attention. The multi-stage payload with VM detection, ABE-bypassing Chrome theft, and fileless execution suggests either experienced malware developers or a maturing malware-as-a-service ecosystem. The use of obfuscated names (postcss-minify-selector-parser vs. the legitimate postcss-selector-parser) combined with genuine download numbers (up to 615 before discovery) demonstrates that namespace confusion remains an effective obfuscation technique.


    What's particularly notable is the timing: three major npm ecosystem attacks in close succession suggests either coordinated threat actor activity or an arms race where multiple groups recognize the npm ecosystem's value as a supply chain lever. The fact that MYRA, the Linux RAT from apintergrationpost, also uses Nuitka-compiled Python extensions indicates possible shared tooling or infrastructure between campaigns.


    For defenders, the painful reality is this: npm's decentralized nature means 100% prevention is mathematically impossible. The practical defense shifts from "never install malicious packages" to "assume compromise and monitor for its indicators." Organizations should treat any npm installation in their build pipeline as a potential C2 channel and implement corresponding network segmentation and monitoring.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Malware](https://www.hackwire.news/category/malware) coverage
  • Cross-reference with [Supply Chain Security](https://www.hackwire.news/category/supply-chain-attacks) and [Developer Security](https://www.hackwire.news/category/developer-security)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)