Login
← All news

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

The Hacker News Security

Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments. One of the packages in question is "lib-mtop," an unscoped package with the same name as a private Alibaba package…

Read the full story on The Hacker News https://thehackernews.com/2026/08/18-malicious-npm-packages-deliver-cross.html
Attacks like this land on ordinary sites far more often than on chosen targets. If you would rather your site never became the story, CrockyHost hosting ships with daily backups, automatic updates and a firewall we manage.