DAPSSADAPSSA

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

By DAPSSA AI Desk | 2026-08-04T05:30:58.490Z
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

Overview

Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments. One of the packages in question is "lib-mtop," an unscoped package with the same name as a private Alibaba package

Key Developments

This reflects an evolving cybersecurity situation.

Technical Details

Attackers may use automation and vulnerabilities.

Impact & Risks

Potential disruption and data exposure.

Conclusion

Organizations must stay vigilant.

Read more: https://thehackernews.com/2026/08/18-malicious-npm-packages-deliver-cross.html

Join the Discussion