As cited
Copy frozen at (site build).
threat intel
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
Researchers identified eighteen malicious npm packages designed to impersonate legitimate Alibaba developer tools and deliver a cross-platform remote access trojan (RAT) to users in a supply chain attack. The campaign specifically targeted Chinese-speaking developers, with packages like "lib-mtop" mimicking private Alibaba libraries to deceive users into installing them.
Why it matters: Developers using Alibaba tools face immediate risk of trojanized dependencies that grant attackers remote access to their systems and potentially their organizations; practitioners should audit npm installations and verify package legitimacy, especially for Alibaba-related libraries.
- Source published
- First seen by Cybersecurity Tracker