type: incident · created: 2026-08-04 · updated: 2026-08-18 · tags: [] · confidence: not-rated · affected_sectors: [] · au_impact: false
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
Summary
Researchers discovered malicious npm packages targeting users of Alibaba developer tools with a cross-platform RAT. The package "lib-mtop" was an unscoped package sharing the same name as a private Alibaba package under the @ali scope, first published November 2023 with three malicious versions uploaded in March–April 2026.
Details
The loader fetches a remote JavaScript payload via curl and executes it. The same maintainer account published 17 additional malicious packages, suggesting either an account takeover or a developer gone rogue. This illustrates the ongoing software supply-chain risk for developers using npm registries, reinforcing ACSC's secure software development guidance.