Malicious npm packages delivering a cross-platform RAT to Alibaba developer tools users
Malware Activity
Summary
Hide ▲
Show ▼
Researchers uncovered 18 malicious npm packages that deliver a cross-platform RAT through a layered dependency tree, putting Alibaba developer tool users in Chinese-speaking environments at risk of backdoor access. The packages impersonate private @ali-scoped components and use decoy wrappers to activate hidden dependencies. The final payload supports command execution, file upload/download, host reconnaissance, payload staging, and lateral movement, raising the impact of the supply-chain compromise.
Related Happenings
AI Sidebar with Deepseek, ChatGPT, Claude, and more update/uninstall monetization payload
Malware Activity
H score11
First: 12.08.2026 17:09
Last: 12.08.2026 17:09
Sources 1
About this happening:
The AI Sidebar with Deepseek, ChatGPT, Claude, and more extension reintroduced a monetization payload that opens an affiliate link in a foreground tab on every updat...
AI Sidebar with Deepseek, ChatGPT, Claude, and more update/uninstall monetization payload
Malware ActivityAbout this happening: The AI Sidebar with Deepseek, ChatGPT, Claude, and more extension reintroduced a monetization payload that opens an affiliate link in a foreground tab on every updat...
Alibaba developer tools npm supply-chain espionage campaign
Campaign
H score44
First: 03.08.2026 21:43
Last: 03.08.2026 21:43
Sources 1
How related:
The goal of the campaign seems to be industrial espionage,
About this happening:
A targeted npm supply-chain campaign is delivering a cross-platform RAT to Alibaba developer tool users, creating a path to industrial espionage and lateral compro...
Alibaba developer tools npm supply-chain espionage campaign
CampaignHow related: The goal of the campaign seems to be industrial espionage,
About this happening: A targeted npm supply-chain campaign is delivering a cross-platform RAT to Alibaba developer tool users, creating a path to industrial espionage and lateral compro...
North Korean npm developer-targeting blockchain-C2 campaign
Campaign
H score41
First: 29.07.2026 07:20
Last: 29.07.2026 07:20
Sources 1
About this happening:
An ongoing North Korean npm supply-chain campaign is delivering DEV#POPPER-linked payloads through compromised @joyfill packages, exposing developers to remote acces...
North Korean npm developer-targeting blockchain-C2 campaign
CampaignAbout this happening: An ongoing North Korean npm supply-chain campaign is delivering DEV#POPPER-linked payloads through compromised @joyfill packages, exposing developers to remote acces...
Compromised @asyncapi npm packages distributing the Miasma loader
Malware Activity
H score29
First: 15.07.2026 12:16
Last: 15.07.2026 12:16
Sources 1
About this happening:
Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....
Compromised @asyncapi npm packages distributing the Miasma loader
Malware ActivityAbout this happening: Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....
Malicious npm and PyPI payment SDK typosquat packages
Malware Activity
H score40
First: 09.07.2026 18:09
Last: 09.07.2026 18:09
Sources 1
About this happening:
The 17 malicious npm and PyPI packages targeted Paysafe, Skrill, and Neteller SDKs to steal system information and developer secrets, then send the data to an Ng...
Malicious npm and PyPI payment SDK typosquat packages
Malware ActivityAbout this happening: The 17 malicious npm and PyPI packages targeted Paysafe, Skrill, and Neteller SDKs to steal system information and developer secrets, then send the data to an Ng...
Timeline
-
03.08.2026 21:43 2 articles · 13d ago
Researchers uncover malicious npm packages targeting Alibaba developer tools users
Initial DisclosureCybersecurity researchers identified a targeted software supply chain attack against users of Alibaba developer tools in Chinese-speaking environments, with malicious npm packages impersonating private @ali-scoped components and delivering a cross-platform RAT. The package set includes lib-mtop and related wrappers, and the malicious versions of lib-mtop were uploaded earlier this March and April. Installed users are advised to assume compromise, rotate sensitive credentials from a clean machine, and audit developer systems for suspicious activity.
Show sources
- 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users — thehackernews.com — 03.08.2026 21:43
- 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users — thehackernews.com — 03.08.2026 21:43