Executive Summary
Iru researchers have identified a sophisticated cross-platform Remote Access Trojan (RAT) dubbed 'SStar Agent'. The malware is delivered through a supply-chain attack involving a poisoned npm package, 'tw-style-utils', which masquerades as a legitimate Tailwind CSS plugin. This delivery is paired with a fake Web3 engineering job assessment lure named 'ChainQuest' to trick developers into executing the payload during their build process.
The malware, written in Go, displays significant capability differences between platforms. While the macOS version focuses on reconnaissance and file exfiltration, the Windows variant is a fully-featured surveillance suite including keylogging, clipboard monitoring, and remote input control. Infrastructure overlaps suggest a connection to the 'OtterCookie' malware family, with Command and Control (C2) operations hosted at api.otter-stack[.]com.
This campaign highlights an evolution in developer-targeted attacks, moving away from simple install-time scripts to build-time execution that bypasses traditional security flags. Organizations in the financial and technology sectors, particularly those involved in cryptocurrency and Web3, should remain highly vigilant.
