Malicious npm packages delivering a cross-platform RAT to Alibaba developer tools users
Malware Activity
Summary
Hide ▲
Show ▼
Researchers uncovered 18 malicious npm packages that deliver a cross-platform RAT through a layered dependency tree, putting Alibaba developer tool users in Chinese-speaking environments at risk of backdoor access. The packages impersonate private @ali-scoped components and use decoy wrappers to activate hidden dependencies. The final payload supports command execution, file upload/download, host reconnaissance, payload staging, and lateral movement, raising the impact of the supply-chain compromise.
Related Happenings
Alibaba developer tools npm supply-chain espionage campaign
Campaign
H score44
First: 03.08.2026 21:43
Last: 03.08.2026 21:43
Sources 1
How related:
The goal of the campaign seems to be industrial espionage,
About this happening:
A targeted npm supply-chain campaign is delivering a cross-platform RAT to Alibaba developer tool users, creating a path to industrial espionage and lateral compro...
Alibaba developer tools npm supply-chain espionage campaign
CampaignHow related: The goal of the campaign seems to be industrial espionage,
About this happening: A targeted npm supply-chain campaign is delivering a cross-platform RAT to Alibaba developer tool users, creating a path to industrial espionage and lateral compro...
North Korean npm developer-targeting blockchain-C2 campaign
Campaign
H score41
First: 29.07.2026 07:20
Last: 29.07.2026 07:20
Sources 1
About this happening:
An ongoing North Korean npm supply-chain campaign is delivering DEV#POPPER-linked payloads through compromised @joyfill packages, exposing developers to remote acces...
North Korean npm developer-targeting blockchain-C2 campaign
CampaignAbout this happening: An ongoing North Korean npm supply-chain campaign is delivering DEV#POPPER-linked payloads through compromised @joyfill packages, exposing developers to remote acces...
Compromised @asyncapi npm packages distributing the Miasma loader
Malware Activity
H score29
First: 15.07.2026 12:16
Last: 15.07.2026 12:16
Sources 1
About this happening:
Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....
Compromised @asyncapi npm packages distributing the Miasma loader
Malware ActivityAbout this happening: Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....
Malicious npm and PyPI payment SDK typosquat packages
Malware Activity
H score40
First: 09.07.2026 18:09
Last: 09.07.2026 18:09
Sources 1
About this happening:
The 17 malicious npm and PyPI packages targeted Paysafe, Skrill, and Neteller SDKs to steal system information and developer secrets, then send the data to an Ng...
Malicious npm and PyPI payment SDK typosquat packages
Malware ActivityAbout this happening: The 17 malicious npm and PyPI packages targeted Paysafe, Skrill, and Neteller SDKs to steal system information and developer secrets, then send the data to an Ng...
Rollup polyfill npm package malware activity for remote access and data theft
Malware Activity
H score16
First: 03.07.2026 19:07
Last: 03.07.2026 19:07
Sources 1
About this happening:
Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...
Rollup polyfill npm package malware activity for remote access and data theft
Malware ActivityAbout this happening: Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...
Timeline
-
03.08.2026 21:43 2 articles · 1h ago
Researchers uncover malicious npm packages targeting Alibaba developer tools users
Initial DisclosureCybersecurity researchers identified a targeted software supply chain attack against users of Alibaba developer tools in Chinese-speaking environments, with malicious npm packages impersonating private @ali-scoped components and delivering a cross-platform RAT. The package set includes lib-mtop and related wrappers, and the malicious versions of lib-mtop were uploaded earlier this March and April. Installed users are advised to assume compromise, rotate sensitive credentials from a clean machine, and audit developer systems for suspicious activity.
Show sources
- 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users — thehackernews.com — 03.08.2026 21:43
- 18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users — thehackernews.com — 03.08.2026 21:43