PostCSS lookalike npm typosquats deliver multi-stage Windows RAT (abdrizak / JFrog)
JFrog disclosed three malicious npm packages published by the abdrizak account that masquerade as postcss-selector-parser tooling. An AES-256-GCM-encrypted blob drops a PowerShell stager which fetches a Windows RAT from nvidiadriver[.]net, persists via the registry, and beacons over encrypted HTTP to 95.216.92.207:8080 to steal Chrome credentials and run remote-shell / file-transfer commands.
Versions named here: 1.0.11, 1.0.12, 1.0.13, 1.0.14, 1.0.15, 1.0.16, 1.0.17, 1.0.18, 2.0.1, 2.0.2