Lookalike npm Package Hides a Multi-Stage Windows RAT
2026-06-23T20:52:12Z•3ec55d99714ebbb9a99c9ccb2815089f38357c6e6a47406ce3209e750206d0b0
ai‑securityapple‑a12apple‑a13bootromedr‑killerfortibleedfortinetfrontier‑AIgentlekillerkluemastranation‑statenorth‑koreanpmoauthopenai‑daybreakphishingpost‑quantumransomwarescamssocgholishsupply‑chaintypo‑squattingwindows‑RAT
What happened
A broad set of high-impact cybersecurity developments: JFrog found a typo‑squatting npm package impersonating postcss‑selector‑parser that drops a multi‑stage Windows RAT; Microsoft links a Mastra AI supply‑chain compromise to North Korean group Sapphire Sleet; a Klue breach exposed OAuth tokens enabling attackers to compromise multiple cybersecurity firms. Other notable threats include GentleKiller (an EDR‑killing framework used by Gentlemen ransomware affiliates), an unpatchable Apple BootROM USB flaw affecting A12/A13 devices, continued FortiBleed fallout for Fortinet customers, and large‑/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- 3ec55d99714ebbb9a99c9ccb2815089f38357c6e6a47406ce3209e750206d0b0
- Enrichment time
- 2026-06-23T20:52:12Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.