PostCSS lookalike npm typosquats deliver multi-stage Windows RAT (abdrizak / JFrog)
JFrog disclosed three malicious npm packages published by the abdrizak account that masquerade as postcss-selector-parser tooling. An AES-256-GCM-encrypted blob drops a PowerShell stager which fetches a Windows RAT from nvidiadriver[.]net, persists via the registry, and beacons over encrypted HTTP to 95.216.92.207:8080 to steal Chrome credentials and run remote-shell / file-transfer commands.
Versions named here: 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.0.7, 1.0.8, 1.0.9, 1.0.10, 1.0.11