PostCSS lookalike npm typosquats deliver multi-stage Windows RAT (abdrizak / JFrog)
JFrog disclosed three malicious npm packages published by the abdrizak account that masquerade as postcss-selector-parser tooling. An AES-256-GCM-encrypted blob drops a PowerShell stager which fetches a Windows RAT from nvidiadriver[.]net, persists via the registry, and beacons over encrypted HTTP to 95.216.92.207:8080 to steal Chrome credentials and run remote-shell / file-transfer commands.
Versions named here: 0.1.2, 0.1.3, 0.1.4, 0.1.5, 0.1.6, 0.1.7, 0.1.8, 0.1.9, 0.1.10, 0.1.11, 2.0.1, 2.0.2