{"id":242146,"date":"2026-08-04T01:19:10","date_gmt":"2026-08-04T06:19:10","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/08\/18-malicious-npm-packages-deliver-crossplatform-rat-to-alibaba-tool-users"},"modified":"2026-08-04T01:19:10","modified_gmt":"2026-08-04T06:19:10","slug":"18-malicious-npm-packages-deliver-crossplatform-rat-to-alibaba-tool-users","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/08\/18-malicious-npm-packages-deliver-crossplatform-rat-to-alibaba-tool-users","title":{"rendered":"18 Malicious npm Packages Deliver CrossPlatform RAT to Alibaba Tool Users"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/18-malicious-npm-packages-deliver-crossplatform-rat-to-alibaba-tool-users.jpg\"><\/a><\/p>\n<p>Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments.<\/p>\n<p>One of the packages in question is \u201c<a href=\"https:\/\/g.alicdn.com\/x-bridge\/mqn\/book\/api\/api-mtop.html\" target=\"_blank\">lib-mtop<\/a>,\u201d an unscoped package with the same name as a private Alibaba package under the \u201c<a href=\"https:\/\/twitter.com\/ali\">@ali<\/a>\u201d scope. Although the npm package was <a href=\"https:\/\/secure.software\/npm\/packages\/lib-mtop\/versions\" target=\"_blank\">first published<\/a> sometime in November 2023 with no functionality, three new versions (v1.0.1, v1.0.2, and v1.0.3) were uploaded earlier this March and April.<\/p>\n<p>It\u2019s currently not clear if this was the result of a maintainer account takeover or the project developer opting to go rogue. Regardless of how the malicious changes were pushed, the newly added changes feature a loader that\u2019s designed to fetch a remote JavaScript payload using curl and then execute it.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments. One of the packages in question is \u201clib-mtop,\u201d an unscoped package with the same name as a [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34],"tags":[],"class_list":["post-242146","post","type-post","status-publish","format-standard","hentry","category-cybercrime-malcode"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/242146","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=242146"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/242146\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=242146"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=242146"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=242146"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}