Malicious npm Packages Deploy Cross-Platform RAT Targeting Alibaba Developers
Cybersecurity researchers identified 18 malicious npm packages impersonating Alibaba's private packages, delivering a cross-platform Remote Access Trojan (RAT) to target Chinese-speaking developers. The attack uses a sophisticated supply chain method, leveraging compromised dependencies to execute payloads across Windows, Linux, and macOS, enabling espionage and lateral movement.
Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments.
One of the packages in question is "lib-mtop," an unscoped package with the same name as a private Alibaba package
*** END OF TRANSMISSION ***