SStar Agent Cross-Platform RAT Analysis
Score: 9/10

SStar Agent Cross-Platform RAT Analysis

The SStar Agent is a Go-based cross-platform RAT delivered via a poisoned npm package (tw-style-utils) targeting Web3 developers with surveillance and exfiltration capabilities.

Executive Summary

Iru researchers have identified a sophisticated cross-platform Remote Access Trojan (RAT) dubbed 'SStar Agent'. The malware is delivered through a supply-chain attack involving a poisoned npm package, 'tw-style-utils', which masquerades as a legitimate Tailwind CSS plugin. This delivery is paired with a fake Web3 engineering job assessment lure named 'ChainQuest' to trick developers into executing the payload during their build process.

The malware, written in Go, displays significant capability differences between platforms. While the macOS version focuses on reconnaissance and file exfiltration, the Windows variant is a fully-featured surveillance suite including keylogging, clipboard monitoring, and remote input control. Infrastructure overlaps suggest a connection to the 'OtterCookie' malware family, with Command and Control (C2) operations hosted at api.otter-stack[.]com.

This campaign highlights an evolution in developer-targeted attacks, moving away from simple install-time scripts to build-time execution that bypasses traditional security flags. Organizations in the financial and technology sectors, particularly those involved in cryptocurrency and Web3, should remain highly vigilant.

Key Details

Threat Name

SStar Agent

Affects

—

Adversary

superstar777 Other Adversaries and Aliases: star45674

Malware/Tools

SStar Agent, OtterCookie

Report Score

9out of 10
Quality Score
Excellent
IOC Quality9
TTP Details10
Detection Guidance7
Enterprise Relevance9
Clarity & Structure9
Technical Depth10

Sources