FeedWindows RAT Uses Encrypted HTTP C2 and Registry Persistence ...
Cyber Security News

Windows RAT Uses Encrypted HTTP C2 and Registry Persistence After npm Infection

📅 22 June 2026 at 21:00 UTC📰 Cyber Security NewsView original source ↗
Windows RAT Uses Encrypted HTTP C2 and Registry Persistence After npm Infection

A newly discovered malware campaign is targeting Windows systems through a deceptive package on the npm registry. Disguised as a legitimate CSS build tool, the malicious package quietly installs a full-featured Remote Access Trojan, or RAT, on developer machines. The attack is subtle, well-crafted, and far more dangerous than it first appears. The infection begins […] The post Windows RAT Uses Encrypted HTTP C2 and Registry Persistence After npm Infection appeared first on Cyber Security News.

Read the full article

This is a curated summary. The complete article is available at Cyber Security News.

Read on Cyber Security News
← Back to feed