18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

Read full story on The Hacker News
Share
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
AI disclosure

Summary

Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments. One of the packages in question is "lib-mtop," an unscoped package with the same name as a private Alibaba package

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.