18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments.

One of the packages in question is “lib-mtop,” an unscoped package with the same name as a private Alibaba package

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Gina Gallery of International Naive Art

Gina Gallery of International Naive Art Source: Hacker News

Timeline of the OpenAI accidental attack against Hugging Face

Timeline of the OpenAI accidental attack against Hugging Face Source: Hacker News

Godot will no longer accept AI-authored code contributions

Godot will no longer accept AI-authored code contributions Source: Hacker News