CYBERSECURITYTRACKER
TRACKING6,902 stories in this site build1,444 vulnerability news stories in this site build
Permanent story citation

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3748

As cited

Copy frozen at (site build).

threat intel

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

Researchers identified eighteen malicious npm packages designed to impersonate legitimate Alibaba developer tools and deliver a cross-platform remote access trojan (RAT) to users in a supply chain attack. The campaign specifically targeted Chinese-speaking developers, with packages like "lib-mtop" mimicking private Alibaba libraries to deceive users into installing them.

Why it matters: Developers using Alibaba tools face immediate risk of trojanized dependencies that grant attackers remote access to their systems and potentially their organizations; practitioners should audit npm installations and verify package legitimacy, especially for Alibaba-related libraries.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary