18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments.

One of the packages in question is “lib-mtop,” an unscoped package with the same name as a private Alibaba package

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

US gas prices hit an average of $4 a gallon again

US gas prices hit an average of $4 a gallon again Source: Hacker News

Attack Update: Top 5 Attack-IPs auf doode.info – 27.06.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. Keine relevanten IPs erfasst (ruhig oder stark gefiltert). Mehr Live-Daten und die komplette Historie im /attacks/ Watchtower-Bereich

Attack Update: Top 5 Attack-IPs auf doode.info – 25.06.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 89.167.35.212 — 480 requests (recent log) 34.19.254.142 — 464 requests (recent log) 216.73.217.55 — 313 requests (recent