logo

Alibaba npm Supply Chain Attack: Cross-Platform RAT

ID: f3adbb73-70a2-5641-9ad0-39827ef82c5d

STIX ID: report--f3adbb73-70a2-5641-9ad0-39827ef82c5d

Feed Name: CyberNexora News

Threat Score
85/100

Date Published: 2026-07-29

Date Updated: 2026-07-30

Author: Debolina Barik

...
...

**Executive Summary:** The report describes a sophisticated npm supply‑chain campaign that impersonated Alibaba private packages to distribute a modular, cross‑platform Remote Access Trojan (RAT) affecting Windows, macOS, and Linux developer environments; the malicious packages fetched remote configuration from GitHub to enable hidden payloads and persistence, established encrypted reverse TCP tunnels, and left indicators such as an "INJECTMARKER" and modified app.asar — researchers recommend removing affected packages, rotating credentials, inspecting for IoCs, and strengthening dependency verification and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.