Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-08-04 · updated: 2026-08-18 · tags: [] · confidence: not-rated · affected_sectors: [] · au_impact: false

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

Summary

Researchers discovered malicious npm packages targeting users of Alibaba developer tools with a cross-platform RAT. The package "lib-mtop" was an unscoped package sharing the same name as a private Alibaba package under the @ali scope, first published November 2023 with three malicious versions uploaded in March–April 2026.

Details

The loader fetches a remote JavaScript payload via curl and executes it. The same maintainer account published 17 additional malicious packages, suggesting either an account takeover or a developer gone rogue. This illustrates the ongoing software supply-chain risk for developers using npm registries, reinforcing ACSC's secure software development guidance.

Sources