Lookalike npm Package Hides a Multi-Stage Windows RAT

2026-06-23T20:52:12Z3ec55d99714ebbb9a99c9ccb2815089f38357c6e6a47406ce3209e750206d0b0
ai‑securityapple‑a12apple‑a13bootromedr‑killerfortibleedfortinetfrontier‑AIgentlekillerkluemastranation‑statenorth‑koreanpmoauthopenai‑daybreakphishingpost‑quantumransomwarescamssocgholishsupply‑chaintypo‑squattingwindows‑RAT

What happened

A broad set of high-impact cybersecurity developments: JFrog found a typo‑squatting npm package impersonating postcss‑selector‑parser that drops a multi‑stage Windows RAT; Microsoft links a Mastra AI supply‑chain compromise to North Korean group Sapphire Sleet; a Klue breach exposed OAuth tokens enabling attackers to compromise multiple cybersecurity firms. Other notable threats include GentleKiller (an EDR‑killing framework used by Gentlemen ransomware affiliates), an unpatchable Apple BootROM USB flaw affecting A12/A13 devices, continued FortiBleed fallout for Fortinet customers, and large‑/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
3ec55d99714ebbb9a99c9ccb2815089f38357c6e6a47406ce3209e750206d0b0
Enrichment time
2026-06-23T20:52:12Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Lookalike npm Package Hides a Multi-Stage Windows RAT · Baitaphish