Malicious npm packages (aes-decode-runner-pro, postcss-minify-selector) impersonating PostCSS tools deliver multi-stage Windows RAT with Python native extension modules. The infection chain: JavaScript dropper → PowerShell downloader...

https://captechgroup.com/threat-intelligence-center/malicious-npm-packages-pose-as-postcss-tools-to-de-2336d4?utm_source=mastodon&utm_medium=social&utm_campaign=threat_intel&utm_content=malicious-npm-packages-pose-as-postcss-tools-to-deliver-windows-rat