Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious npm Packages Target Alibaba Users with RAT

Malicious npm Packages Target Alibaba Users with RAT

Posted on August 3, 2026 By CWS

Cybersecurity experts have uncovered a new threat targeting users of Alibaba’s developer tools. A series of malicious npm packages have been crafted to deliver a cross-platform remote access trojan (RAT), forming part of a complex supply chain attack aimed at environments where Chinese is predominantly spoken.

Discovery of Malicious npm Packages

Among the malicious packages is ‘lib-mtop,’ which shares its name with a private Alibaba package but is unscoped. This npm package emerged in November 2023, but newer versions were released this year. The mode of infiltration remains unclear, whether through a compromised maintainer account or intentional sabotage. These versions include a loader that uses curl to execute a remote JavaScript payload.

The same account responsible for ‘lib-mtop,’ labeled ‘ch4ce,’ also released additional packages such as ‘aone-kit’ and ‘local-config-parser.’ While some act as empty shells mimicking private Alibaba packages, ‘local-config-parser’ appears legitimate but is part of the RAT delivery mechanism targeting Alibaba Group developers.

Technical Details and Attack Mechanisms

The attack leverages a dependency tree that distributes a malicious loader across several packages. These packages impersonate private Alibaba packages to facilitate a seamless dependency resolution process. A crucial package, ‘smart-config-manager,’ acts as a bridge to the actual harmful components. This setup allows the download and execution of a malicious payload designed to adapt based on the host operating system.

On Windows systems, the attack replaces core components of enterprise applications with a trojanized version. Linux systems receive a detached binary payload, while macOS systems have a malicious script inserted into user profiles. The payload exhibits advanced capabilities such as command execution, file manipulation, and persistence through common enterprise software.

Implications and Recommendations

Although the campaign’s origins remain speculative, evidence suggests a Chinese-speaking actor targeting fellow Chinese developers. The ultimate goal appears to be industrial espionage, leveraging the RAT’s capabilities for lateral movement within networks. Despite limited downloads, the attack’s sophistication poses significant risks.

Developers who installed these packages should presume compromise, promptly change sensitive credentials, and scrutinize systems for anomalies. Meanwhile, a separate threat involves a tampered version of the ‘mrmustard’ Python library, which steals sensitive data like SSH keys and cloud credentials.

Conclusion and Future Outlook

This discovery highlights the ongoing vulnerabilities in software supply chains, emphasizing the need for vigilance and robust security practices among developers. As these threats continue to evolve, staying informed and proactive is crucial to safeguarding sensitive environments and data from such sophisticated attacks.

The Hacker News Tags:Alibaba, Attack, Backdoor, China, cross-platform, Cybersecurity, Developers, Espionage, GitHub, Malware, NPM, RAT, Security, software supply chain, Threat

Post navigation

Previous Post: Malware Exploits Google Passkey Vulnerabilities
Next Post: Critical Rails Vulnerability Threatens Cloud Security

Related Posts

China-Aligned Threat Group Uses Windows Group Policy to Deploy Espionage Malware China-Aligned Threat Group Uses Windows Group Policy to Deploy Espionage Malware The Hacker News
Wormable AirPlay Flaws Enable Zero-Click RCE on Apple Devices via Public Wi-Fi Wormable AirPlay Flaws Enable Zero-Click RCE on Apple Devices via Public Wi-Fi The Hacker News
Apple Zero-Click Flaw in Messages Exploited to Spy on Journalists Using Paragon Spyware Apple Zero-Click Flaw in Messages Exploited to Spy on Journalists Using Paragon Spyware The Hacker News
U.S. DOJ Charges 54 in ATM Jackpotting Scheme Using Ploutus Malware U.S. DOJ Charges 54 in ATM Jackpotting Scheme Using Ploutus Malware The Hacker News
Phishing Campaign Uses UpCrypter in Fake Voicemail Emails to Deliver RAT Payloads Phishing Campaign Uses UpCrypter in Fake Voicemail Emails to Deliver RAT Payloads The Hacker News
UNC6671 Cyber Threat Intensifies with Vishing Attacks UNC6671 Cyber Threat Intensifies with Vishing Attacks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • ShieldBreak: Critical Windows Defender Vulnerability Exposed
  • Cyberattack Disrupts Ceva Logistics in Europe
  • Adobe Fixes Critical ColdFusion and Campaign Classic Vulnerabilities
  • Phishing Campaign Exploits Google Branding with Fake Email
  • Intel and AMD Address Over 80 Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • ShieldBreak: Critical Windows Defender Vulnerability Exposed
  • Cyberattack Disrupts Ceva Logistics in Europe
  • Adobe Fixes Critical ColdFusion and Campaign Classic Vulnerabilities
  • Phishing Campaign Exploits Google Branding with Fake Email
  • Intel and AMD Address Over 80 Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark