[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fL4fTBk_BnXCM2NLab028Qrct0_D0ugujl23z0_idYmk":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":40},"7726885a-55d4-4bd4-9d8a-249d65799f5d","fake-npm-packages-deliver-rat-to-steal-chrome-credentials","e1076251-e4bb-4f38-b240-e7aa638618eb","Fake npm Packages Deliver RAT to Steal Chrome Credentials","Attackers published malicious npm packages impersonating the widely-used PostCSS tool to trick developers into installing a Windows Remote Access Trojan. This is a classic supply chain attack leveraging typosquatting and name impersonation to exploit developer trust in open-source ecosystems. Once installed, the RAT bypasses Chrome's encryption to harvest saved credentials, turning a developer's workstation into a data exfiltration point. The incident highlights how a single careless package installation can compromise both individual machines and, potentially, entire CI\u002FCD pipelines and production environments downstream.","**Immediate actions:**\n- Audit all current npm dependencies against known-good package registries and remove any unverified or suspicious packages immediately.\n- Rotate all credentials stored in Chrome or other browsers on any developer machine that may have installed these packages.\n- Report the malicious packages to the npm security team for takedown to protect the wider community.\n\n**Long-term improvements:**\n- Enforce the use of a private or proxied npm registry (e.g., Artifactory, Verdaccio) that vets and mirrors only approved packages.\n- Implement a software composition analysis (SCA) tool in your CI\u002FCD pipeline to automatically flag unrecognized or suspicious package publishers.\n- Establish a policy requiring peer review and verification of any new third-party dependency before it is added to a project.\n\n**Detection measures:**\n- Deploy endpoint detection and response (EDR) tools capable of identifying RAT behavior such as unexpected outbound connections or credential-store access.\n- Enable behavioral monitoring on developer workstations to alert on processes attempting to read browser credential files.\n- Integrate npm audit and tools like Socket.dev into automated build pipelines to continuously scan for newly flagged malicious packages.",[12,13,14,15,16,17,18,19],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 16: Application Software Security","NIST SP 800-161: Supply Chain Risk Management","NIST CSF ID.SC-2: Suppliers and third-party partners are identified and prioritized","NIST CSF PR.DS-6: Integrity checking mechanisms are used to verify software","SLSA Framework: Supply-chain Levels for Software Artifacts","OWASP A06:2021 – Vulnerable and Outdated Components","GDPR Article 32: Security of processing (credential theft may trigger breach obligations)","published","2026-06-24T14:20:35.209453+00:00","2026-06-24T14:20:35.108+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fhackread.com\u002Ffake-npm-packages-postcss-tool-steal-chrome-password\u002F","fake-npm-packages-impersonate-postcss-tool-to-steal-chrome-passwords-1e9b18","Fake npm Packages Impersonate PostCSS Tool to Steal Chrome Passwords",[28,34],{"id":29,"name":30,"slug":31,"description":32,"color":33},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":35,"name":36,"slug":37,"description":38,"color":39},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]