Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developers

released on 2026-07-29 @ 08:57:14 AM
Unknown threat actors distributed malicious downloader functionality across multiple npm packages targeting users of Alibaba tools. The campaign used typosquatting tactics by creating unscoped packages impersonating private packages from Alibaba's @ali scope. Malicious functionality was split across a dependency chain including packages like lib-mtop, smart-config-manager, cloud-config-fetcher, and local-config-parser. The attack employed VM sandbox escape techniques and delivered a sophisticated cross-platform RAT capable of data exfiltration, command execution, and lateral movement through DingTalk collaboration tools. The campaign remained undetected for three months, suggesting possible account takeovers and coordinated publishing across multiple npm accounts in late April 2026, specifically targeting Chinese-speaking developers within Alibaba Group companies for industrial espionage purposes.