Alibaba developer tools npm supply-chain espionage campaign
Campaign
Summary
Hide ▲
Show ▼
A targeted npm supply-chain campaign is delivering a cross-platform RAT to Alibaba developer tool users, creating a path to industrial espionage and lateral compromise. Malicious packages impersonate private @ali-scoped dependencies and use a layered delivery chain to hide loader logic. The operation spans March and April 2026 and is aimed at Chinese-speaking developers in Alibaba-linked environments.
Related Happenings
Malicious npm packages delivering a cross-platform RAT to Alibaba developer tools users
Malware Activity
H score37
First: 03.08.2026 21:43
Last: 03.08.2026 21:43
Sources 1
How related:
The final payload is a complex backdoor equipped with comprehensive command execution, arbitrary file upload and download, host reconnaissance, payload staging, and lateral movement capabilities.
About this happening:
Researchers uncovered 18 malicious npm packages that deliver a cross-platform RAT through a layered dependency tree, putting Alibaba developer tool users in Chinese-...
Malicious npm packages delivering a cross-platform RAT to Alibaba developer tools users
Malware ActivityHow related: The final payload is a complex backdoor equipped with comprehensive command execution, arbitrary file upload and download, host reconnaissance, payload staging, and lateral movement capabilities.
About this happening: Researchers uncovered 18 malicious npm packages that deliver a cross-platform RAT through a layered dependency tree, putting Alibaba developer tool users in Chinese-...
Malicious npm and PyPI payment SDK typosquat packages
Malware Activity
H score40
First: 09.07.2026 18:09
Last: 09.07.2026 18:09
Sources 1
About this happening:
The 17 malicious npm and PyPI packages targeted Paysafe, Skrill, and Neteller SDKs to steal system information and developer secrets, then send the data to an Ng...
Malicious npm and PyPI payment SDK typosquat packages
Malware ActivityAbout this happening: The 17 malicious npm and PyPI packages targeted Paysafe, Skrill, and Neteller SDKs to steal system information and developer secrets, then send the data to an Ng...
North Korean Contagious Interview PolinRider supply-chain campaign
Campaign
H score51
First: 04.07.2026 14:17
Last: 04.07.2026 14:17
Sources 1
About this happening:
The Contagious Interview / PolinRider campaign is still active, with 108 unique packages and browser extensions published across npm, Packagist, Go, and Google Chrome....
North Korean Contagious Interview PolinRider supply-chain campaign
CampaignAbout this happening: The Contagious Interview / PolinRider campaign is still active, with 108 unique packages and browser extensions published across npm, Packagist, Go, and Google Chrome....
Rollup polyfill npm package malware activity for remote access and data theft
Malware Activity
H score16
First: 03.07.2026 19:07
Last: 03.07.2026 19:07
Sources 1
About this happening:
Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...
Rollup polyfill npm package malware activity for remote access and data theft
Malware ActivityAbout this happening: Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...
Easy-day-js Mastra package-publishing campaign
Campaign
H score30
First: 17.06.2026 10:38
Last: 17.06.2026 10:38
Sources 1
About this happening:
The easy-day-js campaign mass-published more than 140 malicious npm packages across the @mastra/* namespace, creating broad supply-chain exposure for developers and bu...
Easy-day-js Mastra package-publishing campaign
CampaignAbout this happening: The easy-day-js campaign mass-published more than 140 malicious npm packages across the @mastra/* namespace, creating broad supply-chain exposure for developers and bu...
Timeline
-
03.08.2026 21:43 2 articles · 1h ago
Malicious npm packages target Alibaba developer tool users with a cross-platform RAT
Initial DisclosureResearchers found 18 malicious npm packages targeting users of Alibaba developer tools in Chinese-speaking environments, using impersonated `@ali`-scoped packages such as `lib-mtop` to deliver a cross-platform RAT. The dependency tree split loader logic across multiple packages, including `smart-config-manager`, and the campaign was assessed as likely aimed at industrial espionage. The payload chain also used Alibaba-masquerading infrastructure and OS-specific persistence and execution paths.
Show sources
- 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users — thehackernews.com — 03.08.2026 21:43
- 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users — thehackernews.com — 03.08.2026 21:43