SECURITYTHE HACKER NEWS
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
Cybersecurity researchers identified 18 malicious npm packages targeting Alibaba developer tool users with a cross-platform remote access trojan (RAT) as part of a supply chain attack focused on Chinese-speaking environments. One package, 'lib-mtop,' mimics a private Alibaba package to deliver the malware.
Mentioned
Related Signal
Adjacent reporting
- Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT
- Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware
- Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
- New Shai-Hulud malware wave compromises 600 npm packages
- Another npm supply chain worm is tearing through dev environments
- The never-ending supply chain attacks worm into SAP npm packages, other dev tools