threat-intel
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
High
Summary
A sophisticated supply chain attack targeting Chinese-speaking developers using Alibaba tools has been discovered. Researchers found a set of malicious npm packages, including wrappers mimicking private Alibaba packages, that deliver a cross-platform remote access trojan (RAT). The attack leverages a dependency tree to install a complex backdoor capable of lateral movement and persistence across Windows, Linux, and macOS, with the goal of industrial espionage. The campaign likely originates from a Chinese-speaking threat actor.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
