Find notable cyber news and cases, enriched with sources, timelines, and signals.

Alibaba developer tools npm supply-chain espionage campaign

Campaign
First reported
Last updated
Happening score
H score 44
1 unique sources, 1 articles

Summary

Hide ▲

A targeted npm supply-chain campaign is delivering a cross-platform RAT to Alibaba developer tool users, creating a path to industrial espionage and lateral compromise. Malicious packages impersonate private @ali-scoped dependencies and use a layered delivery chain to hide loader logic. The operation spans March and April 2026 and is aimed at Chinese-speaking developers in Alibaba-linked environments.

Related Happenings

Malicious npm packages delivering a cross-platform RAT to Alibaba developer tools users

Malware Activity
H score37 First: 03.08.2026 21:43 Last: 03.08.2026 21:43 Sources 1

How related: The final payload is a complex backdoor equipped with comprehensive command execution, arbitrary file upload and download, host reconnaissance, payload staging, and lateral movement capabilities.

About this happening: Researchers uncovered 18 malicious npm packages that deliver a cross-platform RAT through a layered dependency tree, putting Alibaba developer tool users in Chinese-...

Malicious npm and PyPI payment SDK typosquat packages

Malware Activity
H score40 First: 09.07.2026 18:09 Last: 09.07.2026 18:09 Sources 1

About this happening: The 17 malicious npm and PyPI packages targeted Paysafe, Skrill, and Neteller SDKs to steal system information and developer secrets, then send the data to an Ng...

North Korean Contagious Interview PolinRider supply-chain campaign

Campaign
H score51 First: 04.07.2026 14:17 Last: 04.07.2026 14:17 Sources 1

About this happening: The Contagious Interview / PolinRider campaign is still active, with 108 unique packages and browser extensions published across npm, Packagist, Go, and Google Chrome....

Rollup polyfill npm package malware activity for remote access and data theft

Malware Activity
H score16 First: 03.07.2026 19:07 Last: 03.07.2026 19:07 Sources 1

About this happening: Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...

Easy-day-js Mastra package-publishing campaign

Campaign
H score30 First: 17.06.2026 10:38 Last: 17.06.2026 10:38 Sources 1

About this happening: The easy-day-js campaign mass-published more than 140 malicious npm packages across the @mastra/* namespace, creating broad supply-chain exposure for developers and bu...

Timeline

  1. 03.08.2026 21:43 2 articles · 1h ago

    Malicious npm packages target Alibaba developer tool users with a cross-platform RAT

    Initial Disclosure

    Researchers found 18 malicious npm packages targeting users of Alibaba developer tools in Chinese-speaking environments, using impersonated `@ali`-scoped packages such as `lib-mtop` to deliver a cross-platform RAT. The dependency tree split loader logic across multiple packages, including `smart-config-manager`, and the campaign was assessed as likely aimed at industrial espionage. The payload chain also used Alibaba-masquerading infrastructure and OS-specific persistence and execution paths.

    Show sources