A malicious npm package, postcss-minify-selector-parser, impersonated the legitimate postcss-selector-parser library in a software supply-chain attack and installed a multi-stage Windows remote access trojan on developer machines. Researchers linked the package to postcss-minify-selector and aes-decode-runner-pro, all published under the name abdrizak, and found the malware executed on import, decoded an embedded payload, dropped a PowerShell downloader, and fetched additional components from nvidiadriver[.]net before launching Nuitka-compiled modules through a renamed Python launcher.
The recovered implant communicated with 95[.]216[.]92[.]207:8080 over encrypted HTTP POST traffic and supported remote shell access, file transfer, persistence, host profiling, and anti-VM checks. It also targeted Google Chrome saved logins and extension data, including newer app-bound encryption protections, while maintaining persistence through the HKCU Run registry key and tracking victims with files under %TEMP%. Defenders were advised to remove the malicious packages, inspect dependency trees and Windows artifacts such as %TEMP%\winPatch and chost.exe/loader.py execution, block the listed indicators, and rotate credentials from affected developer systems.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
On publication of its research, JFrog reported the malicious packages were already detected by JFrog Xray and JFrog Curation under IDs XRAY-1002983, XRAY-1003986, and XRAY-989675. It advised users to remove the packages, inspect temp-folder and registry artifacts, block listed indicators, and rotate credentials from affected developer machines.
JFrog recovered the implant's command-and-control endpoint at 95[.]216[.]92[.]207:8080 and documented encrypted HTTP POST communications, remote shell, file transfer, host profiling, and anti-VM checks. The analysis also found persistence via the HKCU Run key and functionality to steal Chrome saved logins and extension data, including bypassing newer Chrome encryption protections.
JFrog decoded payloads from the malicious packages and found a multi-stage Windows infection chain in which imported package code dropped and executed a PowerShell downloader. The downloader fetched a payload from nvidiadriver[.]net, unpacked a bundled Python-based implant, and launched a RAT via a VBScript bootstrapper and renamed Python launcher.
A malicious npm package cluster centered on postcss-minify-selector-parser, with related packages postcss-minify-selector and aes-decode-runner-pro, was identified as impersonating the legitimate postcss-selector-parser ecosystem. JFrog linked the packages to the npm publisher name abdrizak and found they were designed to blend into JavaScript build workflows.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 11 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.