Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious npm Packages Target Alibaba Users with RAT

Malicious npm Packages Target Alibaba Users with RAT

Posted on August 3, 2026 By CWS

Cybersecurity experts have uncovered a new threat targeting users of Alibaba’s developer tools. A series of malicious npm packages have been crafted to deliver a cross-platform remote access trojan (RAT), forming part of a complex supply chain attack aimed at environments where Chinese is predominantly spoken.

Discovery of Malicious npm Packages

Among the malicious packages is ‘lib-mtop,’ which shares its name with a private Alibaba package but is unscoped. This npm package emerged in November 2023, but newer versions were released this year. The mode of infiltration remains unclear, whether through a compromised maintainer account or intentional sabotage. These versions include a loader that uses curl to execute a remote JavaScript payload.

The same account responsible for ‘lib-mtop,’ labeled ‘ch4ce,’ also released additional packages such as ‘aone-kit’ and ‘local-config-parser.’ While some act as empty shells mimicking private Alibaba packages, ‘local-config-parser’ appears legitimate but is part of the RAT delivery mechanism targeting Alibaba Group developers.

Technical Details and Attack Mechanisms

The attack leverages a dependency tree that distributes a malicious loader across several packages. These packages impersonate private Alibaba packages to facilitate a seamless dependency resolution process. A crucial package, ‘smart-config-manager,’ acts as a bridge to the actual harmful components. This setup allows the download and execution of a malicious payload designed to adapt based on the host operating system.

On Windows systems, the attack replaces core components of enterprise applications with a trojanized version. Linux systems receive a detached binary payload, while macOS systems have a malicious script inserted into user profiles. The payload exhibits advanced capabilities such as command execution, file manipulation, and persistence through common enterprise software.

Implications and Recommendations

Although the campaign’s origins remain speculative, evidence suggests a Chinese-speaking actor targeting fellow Chinese developers. The ultimate goal appears to be industrial espionage, leveraging the RAT’s capabilities for lateral movement within networks. Despite limited downloads, the attack’s sophistication poses significant risks.

Developers who installed these packages should presume compromise, promptly change sensitive credentials, and scrutinize systems for anomalies. Meanwhile, a separate threat involves a tampered version of the ‘mrmustard’ Python library, which steals sensitive data like SSH keys and cloud credentials.

Conclusion and Future Outlook

This discovery highlights the ongoing vulnerabilities in software supply chains, emphasizing the need for vigilance and robust security practices among developers. As these threats continue to evolve, staying informed and proactive is crucial to safeguarding sensitive environments and data from such sophisticated attacks.

The Hacker News Tags:Alibaba, Attack, Backdoor, China, cross-platform, Cybersecurity, Developers, Espionage, GitHub, Malware, NPM, RAT, Security, software supply chain, Threat

Post navigation

Previous Post: Malware Exploits Google Passkey Vulnerabilities
Next Post: Critical Rails Vulnerability Threatens Cloud Security

Related Posts

38,000+ FreeDrain Subdomains Found Exploiting SEO to Steal Crypto Wallet Seed Phrases 38,000+ FreeDrain Subdomains Found Exploiting SEO to Steal Crypto Wallet Seed Phrases The Hacker News
Hackers Using New QuirkyLoader Malware to Spread Agent Tesla, AsyncRAT and Snake Keylogger Hackers Using New QuirkyLoader Malware to Spread Agent Tesla, AsyncRAT and Snake Keylogger The Hacker News
Critical Adobe Campaign Flaw Poses Code Execution Risk Critical Adobe Campaign Flaw Poses Code Execution Risk The Hacker News
Qilin Ransomware Turns South Korean MSP Breach Into 28-Victim ‘Korean Leaks’ Data Heist Qilin Ransomware Turns South Korean MSP Breach Into 28-Victim ‘Korean Leaks’ Data Heist The Hacker News
OXLOADER Exploits Malicious Ads to Spread CastleStealer OXLOADER Exploits Malicious Ads to Spread CastleStealer The Hacker News
Urgent: cPanel and WHM Security Updates Released Urgent: cPanel and WHM Security Updates Released The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Plugin4Shell Exploit Threatens AI Coding Tools
  • Security Flaw Exposes OpenAI Code via AI-Generated Exploit
  • Brevo Attack Compromises Over 100,000 WordPress Sites
  • Gyazo Data Breach Exposes 23 Million User Records
  • WeaselBiscuit Malware Detected in 13 npm Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Plugin4Shell Exploit Threatens AI Coding Tools
  • Security Flaw Exposes OpenAI Code via AI-Generated Exploit
  • Brevo Attack Compromises Over 100,000 WordPress Sites
  • Gyazo Data Breach Exposes 23 Million User Records
  • WeaselBiscuit Malware Detected in 13 npm Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark