Malware New npm packages deliver remote access trojan targeting Alibaba developers August 4, 2026 Share By SC Staff (Credit: Araki Illustrations – stock.adobe.com) A new set of malicious npm packages were discovered targeting users of Alibaba developer tools with a cross-platform remote access trojan (RAT). This sophisticated software supply chain attack specifically targets Chinese-speaking environments, based on information published by The Hacker News. The attack utilizes packages with names mimicking private Alibaba packages, such as 'lib-mtop.' These packages, published by a maintainer account named 'ch4ce,' function as decoys that initiate the installation of a malicious dependency tree. The loader functionality is split across several packages, ultimately fetching and executing a remote JavaScript payload using curl. The final payload is a complex backdoor capable of command execution, file transfer, host reconnaissance, and lateral movement. It can also achieve persistence by injecting code into enterprise applications like DingTalk and Wukong. The attack infrastructure masquerades as Alibaba services to evade detection. The threat actor's use of Chinese language comments and specific UTC offsets suggests a Chinese-speaking origin, likely aiming for industrial espionage. Developers who have installed any of the identified malicious packages should assume compromise, rotate credentials from a clean machine, and audit their systems. Source: The Hacker News SC Staff Related Malware Fake Roblox Xeno executor installers distribute malware SC Staff August 4, 2026 Fake Xeno Executor installers are targeting Roblox players with malware that provides remote access and steals sensitive information. Supply chain Keyv, cacheable npm supply chain attack hits 400-plus packages Laura French August 4, 2026 The attack is believed to be related to Mini Shai-Hulud. Malware BTMOB Android malware service fragments into a complex ecosystem SC Staff August 4, 2026 BTMOB, an Android RAT sold as a malware-as-a-service, has seen its operation splinter into a vast network of resellers, source-code vendors, independent server operators, and potential impersonators, according to Flare researchers. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Adware You can skip this ad in 5 seconds