Malicious npm Packages Deliver Windows RAT via PostCSS Masquerade
Cybercriminals have published multiple malicious npm packages impersonating the legitimate PostCSS ecosystem to distribute a Windows Remote Access Trojan (RAT). The packages use typosquatting and dependency confusion techniques to trick developers into downloading malware that establishes persistent