Fake npm Packages Impersonate PostCSS Tool to Steal Chrome Passwords Hackread – Latest Cybersecurity, Tech, Crypto & Hacking News Por:Deeba Ahmed 24 de Junho de 2026, 10:26 JFrog warns of malicious npm packages that mimic PostCSS tooling, drop a Windows RAT, and target Chrome-stored passwords through a staged infection setup route.