Remcos-style RAT sample flagged by multi-engine scan
Threat actors published malicious npm packages disguised as PostCSS development tools that install a Windows Remote Access Trojan on developer workstations, giving persistent access, credential theft, and lateral movement into internal development infrastructure. Remote access trojans such as Remcos establish command-and-control sessions that let operators control the machine as if seated in front of it (MITRE T1219). Because RAT binaries are continuously recompiled and repacked, no single antivirus vendor catches every variant. Metascan addresses this by running the sample against 30+ anti-malware engines in parallel, aggregating verdicts into a single risk score so detection gaps in any one engine are covered by the others. This demo uses the EICAR test file, a universally recognized and completely safe signature-checking artifact.
Attack Technique
Remote access trojan
MITRE ATT&CK
T1219 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗