So it's packaged like this:
rar inside a rar (both passworded)
containing an NSIS installer
which drops and runs a copy of electron.
the electron code is obfuscated, and encrypted. it decrypts itself on run. the encrypted code is also obfuscated.
that JS code does most of the password stealing, but it drops an EXE file off the iwannaeatcats.com site, and sets it up to auto-run next boot. it also grabs the NPM package, for unknown reasons