HackerFeeds

CyberSecurity News

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

The Hacker News
· August 3, 2026

AI summary

Cybersecurity researchers have found 18 malicious npm packages that deliver a cross-platform remote access trojan to users of Alibaba developer tools. The attack is a targeted software supply chain attack aimed at Chinese-speaking environments. One of the malicious packages is called "lib-mtop", which has the same name as a private Alibaba package, suggesting an attempt to disguise itself as a legitimate package. This set of malicious packages is part of a sophisticated attack. The packages target users of Alibaba tools, potentially giving attackers remote access to compromised systems. The attack highlights the risk of software supply chain attacks in targeted environments.

Read the full article at The Hacker Newsthehackernews.com/2026/08/18-malicious-npm-packages-deliver-cross.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.