logo

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

ID: 86b73bd9-ee90-55ed-ad10-462fc85cb16c

STIX ID: report--86b73bd9-ee90-55ed-ad10-462fc85cb16c

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-08-03

Date Updated: 2026-08-04

Author: [email protected] (The Hacker News)

...
...

Cybersecurity researchers uncovered a targeted supply-chain campaign using malicious npm packages that impersonate Alibaba-scoped modules to deliver a multi-stage cross-platform RAT. The attack splits loader logic across several packages and a rule engine that fetches and executes OS-specific payloads from a domain masquerading as Alibaba, enabling persistence, credential theft, lateral movement and tampering with enterprise collaboration apps; users who installed listed packages should assume compromise and rotate credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.