{"id":1159,"date":"2026-08-20T10:53:05","date_gmt":"2026-08-20T05:23:05","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1159"},"modified":"2026-08-20T10:53:29","modified_gmt":"2026-08-20T05:23:29","slug":"postcss-malicious-npm-packages-windows-rat","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/postcss-malicious-npm-packages-windows-rat\/","title":{"rendered":"Malicious PostCSS-Themed npm Packages Deliver Windows RAT"},"content":{"rendered":"<p>Attackers continue to exploit one of the weakest links in the software supply chain: developer trust. In the latest campaign, threat actors published PostCSS-themed npm packages that masqueraded as legitimate build utilities while concealing a multi-stage Windows remote access trojan (RAT).<\/p>\n<p>Unlike opportunistic malware delivered through phishing emails or drive-by downloads, malicious npm packages execute as part of the software development workflow. That makes them particularly dangerous, as they can compromise developer workstations and potentially provide attackers with a foothold into engineering environments before the malicious activity is detected.<\/p>\n<h2>How the Attack Works<\/h2>\n<p>The attack begins when a developer installs one of the malicious npm packages, believing it to be a legitimate PostCSS utility. During execution, a JavaScript dropper writes a PowerShell script (<code>settings.ps1<\/code>) to disk and launches it, initiating the next stage of the infection chain.<\/p>\n<p>The PowerShell script downloads a ZIP archive from attacker-controlled infrastructure and extracts multiple components, including:<\/p>\n<ul>\n<li>A VBScript launcher (<code>update.vbs<\/code>)<\/li>\n<li>A bundled Python runtime<\/li>\n<li>A Python loader (<code>loader.py<\/code>)<\/li>\n<li>Nuitka-compiled Python extension modules<\/li>\n<\/ul>\n<p>The VBScript starts the embedded Python environment, allowing <code>loader.py<\/code> to load and execute the RAT without requiring Python to be installed on the victim&#8217;s system. Packaging the malware with its own runtime also helps the attackers maintain a consistent execution environment across compromised Windows endpoints.<\/p>\n<p>Once active, the RAT performs a range of post-compromise activities, including:<\/p>\n<ul>\n<li>Collecting host information to profile the infected system<\/li>\n<li>Checking for virtualized environments, likely to evade sandbox-based analysis<\/li>\n<li>Stealing Google Chrome credentials and browser extension data<\/li>\n<li>Executing arbitrary shell commands received from the command-and-control (C2) server<\/li>\n<li>Uploading and downloading files to support additional attacker objectives<\/li>\n<\/ul>\n<p>This staged execution model enables attackers to keep the initial npm package relatively lightweight while retrieving the full payload only after the malicious package has been executed, reducing the likelihood of early detection during package inspection.<br \/>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Miasma-Malware-Hits-Red-Hat-npm-Packages-in-Developer-Credential-Theft-Campaign-1.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Red Hat npm Packages Compromised by Miasma Credential-Stealing Malware<\/h4><p>Miasma malware infiltrated Red Hat npm packages, stealing developer credentials through a supply chain attack.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/miasma-malware-red-hat-npm-supply-chain-attack\/\" aria-label=\"Red Hat npm Packages Compromised by Miasma Credential-Stealing Malware\"><\/a><\/div><\/div><\/div><\/p>\n<h2>How Hexnode Helps Reduce the Risk<\/h2>\n<p>Defending against software supply chain attacks requires visibility into endpoint activity as well as control over the developer environment. While no single security control can prevent every malicious package from being installed, combining endpoint detection and response (XDR) with unified endpoint management (UEM) significantly reduces the attack surface and accelerates incident response.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\" rel=\"noopener\">Hexnode XDR<\/a> provides security teams with visibility into suspicious endpoint behaviors associated with attacks like this, including:<\/p>\n<ul>\n<li>Unusual PowerShell execution<\/li>\n<li>Suspicious VBScript or Python processes spawned during package execution, import, test, or build activity.<\/li>\n<li>Potential credential-theft or stealer activity, including suspicious process, file, or access patterns where telemetry supports detection<\/li>\n<li>Unexpected outbound connections and other indicators of post-compromise activity<\/li>\n<li>Investigation and response actions to help contain affected endpoints from a centralized console<\/li>\n<\/ul>\n<p>At the same time, <a href=\"https:\/\/www.hexnode.com\/\" rel=\"noopener\">Hexnode UEM<\/a> helps organizations strengthen the security posture of developer workstations by enabling administrators to:<\/p>\n<ul>\n<li>Enforce approved application and software deployment policies<\/li>\n<li>Maintain device compliance across managed endpoints<\/li>\n<li>Keep operating systems and supported applications up to date through patch management<\/li>\n<li>Perform remote management and remediation actions when suspicious activity is identified<\/li>\n<\/ul>\n<p>Together, Hexnode XDR and Hexnode UEM help organizations reduce the likelihood that a malicious dependency can progress from an infected developer workstation to a broader compromise of engineering or production environments.<br \/>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-2.webp?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity-kit\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-2.webp?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-2-300x225.webp?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-2-768x576.webp?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-2-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity-kit\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured Resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Cybersecurity kit\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            This resource kit will help your company adopt the right cybersecurity strategy to secure your business.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/resource-kits\/cybersecurity-kit\/'>\n                            Get the Resource kit\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section><\/p>\n<h2>Key Takeaways<\/h2>\n<p>The PostCSS lookalike campaign demonstrates how a seemingly harmless package name can conceal a fully functional remote access trojan (RAT) capable of compromising developer workstations. As software supply chain attacks continue to evolve, organizations can no longer rely solely on package repositories to filter malicious dependencies before they reach development environments.<\/p>\n<p>To reduce risk, enterprises should prioritize:<\/p>\n<ul>\n<li>Package governance to limit the use of unverified or unauthorized dependencies<\/li>\n<li>Endpoint telemetry that can identify suspicious process execution and post-compromise behavior<\/li>\n<li>Rapid credential and secret rotation whenever a developer endpoint is suspected to be compromised<\/li>\n<li>Continuous monitoring of developer workstations and CI\/CD environments for anomalous activity<\/li>\n<\/ul>\n<p>For security and IT teams, the objective extends beyond blocking a single malicious package. The broader challenge is ensuring that a compromised developer endpoint cannot become a gateway to source code, cloud infrastructure, or production systems.<br \/>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Try\u202fHexnode\u202fFree for 14 Days\u202f\u202f\u202f <\/h5><p>Reduce the risk of software supply chain attacks with unified endpoint security and management.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Sign Up Today<\/a><\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Attackers continue to exploit one of the weakest links in the software supply chain: developer&#8230;<\/p>\n","protected":false},"author":8,"featured_media":1160,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[13,16],"class_list":["post-1159","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity-abuse","category-windows","product_category-extended-detection-and-response","tab_group-identity-and-phishing"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Malicious PostCSS-Themed npm Packages Deliver Windows RAT<\/title>\n<meta name=\"description\" content=\"Malicious PostCSS-themed npm packages deliver a Windows RAT that steals Chrome credentials and enables remote commands.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/postcss-malicious-npm-packages-windows-rat\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Malicious PostCSS-Themed npm Packages Deliver Windows RAT\" \/>\n<meta property=\"og:description\" content=\"Malicious PostCSS-themed npm packages deliver a Windows RAT that steals Chrome credentials and enables remote commands.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/postcss-malicious-npm-packages-windows-rat\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-20T05:23:05+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-20T05:23:29+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/malicious-npm-packages.webp?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"535\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Alanna River\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Alanna River\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/postcss-malicious-npm-packages-windows-rat\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/postcss-malicious-npm-packages-windows-rat\\\/\"},\"author\":{\"name\":\"Alanna River\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\"},\"headline\":\"Malicious PostCSS-Themed npm Packages Deliver Windows RAT\",\"datePublished\":\"2026-08-20T05:23:05+00:00\",\"dateModified\":\"2026-08-20T05:23:29+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/postcss-malicious-npm-packages-windows-rat\\\/\"},\"wordCount\":672,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/postcss-malicious-npm-packages-windows-rat\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/malicious-npm-packages.webp?format=webp\",\"articleSection\":[\"Identity Abuse\",\"Windows\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/postcss-malicious-npm-packages-windows-rat\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/postcss-malicious-npm-packages-windows-rat\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/postcss-malicious-npm-packages-windows-rat\\\/\",\"name\":\"Malicious PostCSS-Themed npm Packages Deliver Windows RAT\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/postcss-malicious-npm-packages-windows-rat\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/postcss-malicious-npm-packages-windows-rat\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/malicious-npm-packages.webp?format=webp\",\"datePublished\":\"2026-08-20T05:23:05+00:00\",\"dateModified\":\"2026-08-20T05:23:29+00:00\",\"description\":\"Malicious PostCSS-themed npm packages deliver a Windows RAT that steals Chrome credentials and enables remote commands.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/postcss-malicious-npm-packages-windows-rat\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/postcss-malicious-npm-packages-windows-rat\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/postcss-malicious-npm-packages-windows-rat\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/malicious-npm-packages.webp?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/malicious-npm-packages.webp?format=webp\",\"width\":1024,\"height\":535,\"caption\":\"malicious-npm-packages\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/postcss-malicious-npm-packages-windows-rat\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Malicious PostCSS-Themed npm Packages Deliver Windows RAT\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/c2ed050402be36f7ece23a9b07bc9e64\",\"name\":\"Alanna River\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g\",\"caption\":\"Alanna River\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/alanna-river\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Malicious PostCSS-Themed npm Packages Deliver Windows RAT","description":"Malicious PostCSS-themed npm packages deliver a Windows RAT that steals Chrome credentials and enables remote commands.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/postcss-malicious-npm-packages-windows-rat\/","og_locale":"en_US","og_type":"article","og_title":"Malicious PostCSS-Themed npm Packages Deliver Windows RAT","og_description":"Malicious PostCSS-themed npm packages deliver a Windows RAT that steals Chrome credentials and enables remote commands.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/postcss-malicious-npm-packages-windows-rat\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-08-20T05:23:05+00:00","article_modified_time":"2026-08-20T05:23:29+00:00","og_image":[{"width":1024,"height":535,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/malicious-npm-packages.webp?format=webp","type":"image\/webp"}],"author":"Alanna River","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Alanna River","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/postcss-malicious-npm-packages-windows-rat\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/postcss-malicious-npm-packages-windows-rat\/"},"author":{"name":"Alanna River","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64"},"headline":"Malicious PostCSS-Themed npm Packages Deliver Windows RAT","datePublished":"2026-08-20T05:23:05+00:00","dateModified":"2026-08-20T05:23:29+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/postcss-malicious-npm-packages-windows-rat\/"},"wordCount":672,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/postcss-malicious-npm-packages-windows-rat\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/malicious-npm-packages.webp?format=webp","articleSection":["Identity Abuse","Windows"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/postcss-malicious-npm-packages-windows-rat\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/postcss-malicious-npm-packages-windows-rat\/","url":"https:\/\/www.hexnode.com\/threat-watch\/postcss-malicious-npm-packages-windows-rat\/","name":"Malicious PostCSS-Themed npm Packages Deliver Windows RAT","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/postcss-malicious-npm-packages-windows-rat\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/postcss-malicious-npm-packages-windows-rat\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/malicious-npm-packages.webp?format=webp","datePublished":"2026-08-20T05:23:05+00:00","dateModified":"2026-08-20T05:23:29+00:00","description":"Malicious PostCSS-themed npm packages deliver a Windows RAT that steals Chrome credentials and enables remote commands.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/postcss-malicious-npm-packages-windows-rat\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/postcss-malicious-npm-packages-windows-rat\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/postcss-malicious-npm-packages-windows-rat\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/malicious-npm-packages.webp?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/malicious-npm-packages.webp?format=webp","width":1024,"height":535,"caption":"malicious-npm-packages"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/postcss-malicious-npm-packages-windows-rat\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Malicious PostCSS-Themed npm Packages Deliver Windows RAT"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/c2ed050402be36f7ece23a9b07bc9e64","name":"Alanna River","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/1d91e52e837001aa3e782febef8d4339b30257abee06ef86933aebc57aa48248?s=96&d=mm&r=g","caption":"Alanna River"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/alanna-river\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1159","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1159"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1159\/revisions"}],"predecessor-version":[{"id":1165,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1159\/revisions\/1165"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1160"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1159"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1159"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}