18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
ID: 86b73bd9-ee90-55ed-ad10-462fc85cb16c
STIX ID: report--86b73bd9-ee90-55ed-ad10-462fc85cb16c
Feed Name: The Hacker News
Date Published: 2026-08-03
Date Updated: 2026-08-04
Author: [email protected] (The Hacker News)
Cybersecurity researchers uncovered a targeted supply-chain campaign using malicious npm packages that impersonate Alibaba-scoped modules to deliver a multi-stage cross-platform RAT. The attack splits loader logic across several packages and a rule engine that fetches and executes OS-specific payloads from a domain masquerading as Alibaba, enabling persistence, credential theft, lateral movement and tampering with enterprise collaboration apps; users who installed listed packages should assume compromise and rotate credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
