Find notable cyber news and cases, enriched with sources, timelines, and signals.

Malicious npm packages delivering a cross-platform RAT to Alibaba developer tools users

Malware Activity
First reported
Last updated
Happening score
H score 37
1 unique sources, 1 articles

Summary

Hide ▲

Researchers uncovered 18 malicious npm packages that deliver a cross-platform RAT through a layered dependency tree, putting Alibaba developer tool users in Chinese-speaking environments at risk of backdoor access. The packages impersonate private @ali-scoped components and use decoy wrappers to activate hidden dependencies. The final payload supports command execution, file upload/download, host reconnaissance, payload staging, and lateral movement, raising the impact of the supply-chain compromise.

Related Happenings

Alibaba developer tools npm supply-chain espionage campaign

Campaign
H score44 First: 03.08.2026 21:43 Last: 03.08.2026 21:43 Sources 1

How related: The goal of the campaign seems to be industrial espionage,

About this happening: A targeted npm supply-chain campaign is delivering a cross-platform RAT to Alibaba developer tool users, creating a path to industrial espionage and lateral compro...

North Korean npm developer-targeting blockchain-C2 campaign

Campaign
H score41 First: 29.07.2026 07:20 Last: 29.07.2026 07:20 Sources 1

About this happening: An ongoing North Korean npm supply-chain campaign is delivering DEV#POPPER-linked payloads through compromised @joyfill packages, exposing developers to remote acces...

Compromised @asyncapi npm packages distributing the Miasma loader

Malware Activity
H score29 First: 15.07.2026 12:16 Last: 15.07.2026 12:16 Sources 1

About this happening: Four compromised @asyncapi npm packages now deliver a multi-stage botnet loader when imported, exposing consumers to Miasma payloads during normal Node.js module load....

Malicious npm and PyPI payment SDK typosquat packages

Malware Activity
H score40 First: 09.07.2026 18:09 Last: 09.07.2026 18:09 Sources 1

About this happening: The 17 malicious npm and PyPI packages targeted Paysafe, Skrill, and Neteller SDKs to steal system information and developer secrets, then send the data to an Ng...

Rollup polyfill npm package malware activity for remote access and data theft

Malware Activity
H score16 First: 03.07.2026 19:07 Last: 03.07.2026 19:07 Sources 1

About this happening: Malicious npm packages disguised as Rollup polyfill tooling are now delivering remote-access and data-theft payloads to developer workstations and build machines. The...

Timeline

  1. 03.08.2026 21:43 2 articles · 1h ago

    Researchers uncover malicious npm packages targeting Alibaba developer tools users

    Initial Disclosure

    Cybersecurity researchers identified a targeted software supply chain attack against users of Alibaba developer tools in Chinese-speaking environments, with malicious npm packages impersonating private @ali-scoped components and delivering a cross-platform RAT. The package set includes lib-mtop and related wrappers, and the malicious versions of lib-mtop were uploaded earlier this March and April. Installed users are advised to assume compromise, rotate sensitive credentials from a clean machine, and audit developer systems for suspicious activity.

    Show sources