Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

A Sophisticated Software Supply Chain Attack: The Rise of Cross-Platform RAT Malware


A sophisticated software supply chain attack has been uncovered by cybersecurity researchers, targeting users of Alibaba developer tools with a cross-platform remote access trojan (RAT) malware. The attack is notable for its sophistication and targeted nature, highlighting the ongoing threat landscape and the importance of staying informed and taking steps to protect oneself.

  • Alibaba developer tools users were targeted with a cross-platform remote access trojan (RAT) malware.
  • The malicious packages were published on the npm repository and delivered advanced RAT capabilities to Chinese-speaking environments.
  • The attack used sophisticated techniques, including an unscoped package named "lib-mtop," to deliver the malware.
  • Experts suspect a Chinese-speaking threat actor is behind the attack due to language comments in source code and timestamped GitHub commits.
  • Security researchers advise users to assume compromise and take steps to rotate sensitive credentials and audit developer systems for suspicious activity.



  • A recent discovery by cybersecurity researchers has shed light on a sophisticated software supply chain attack that has been targeting users of Alibaba developer tools with a cross-platform remote access trojan (RAT) malware. The malicious packages, which were published on the npm (Node Package Manager) repository, have been found to deliver advanced RAT capabilities to Chinese-speaking environments.

    The attack is notable for its sophistication and targeted nature, with the attackers using a combination of techniques to deliver the malware. One of the key components of the attack was the use of an unscoped package named "lib-mtop" that was published in November 2023 but saw significant updates in March and April. The malicious changes added a loader that fetched a remote JavaScript payload using curl, which was then executed.

    The attackers also used another package called "aone-kit" to deliver the malware, with four other packages, including "local-config-parser," being used as conduits for the RAT. The malicious loader functionality was split and embedded into several packages delivered to the targets as part of the same dependency tree. This allowed the attackers to target developers who were likely working in companies that are part of the Alibaba Group.

    The impact of the attack is difficult to evaluate, but it is clear that the goal of the campaign was industrial espionage. The malicious payload is capable of performing a range of actions, including terminating enterprise security applications, downloading and running binary payloads, and injecting malicious code into common enterprise collaboration applications.

    Experts have noted that the presence of Chinese language comments in the source code, combined with the fact that GitHub commits are timestamped with the UTC+08:00 offset, suggests that the attack is likely the work of a Chinese-speaking threat actor. The attackers appear to have used sophisticated techniques to evade detection and have made significant efforts to obscure their tracks.

    In response to the attack, security researchers are advising users who have installed any of the affected packages to assume compromise and take steps to rotate sensitive credentials and audit developer systems for signs of suspicious activity. The incident highlights the importance of software supply chain security and the need for developers to be vigilant when using third-party libraries and dependencies.

    The recent discovery of this sophisticated software supply chain attack serves as a stark reminder of the ongoing threat landscape and the importance of staying informed and taking steps to protect oneself. As technology continues to evolve, it is essential that we remain proactive in addressing these threats and ensuring the security of our systems.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/A-Sophisticated-Software-Supply-Chain-Attack-The-Rise-of-Cross-Platform-RAT-Malware-ehn.shtml

  • https://thehackernews.com/2026/08/18-malicious-npm-packages-deliver-cross.html

  • https://cybersecuritynews.com/npm-packages-cross-platform-rat/


  • Published: Mon Aug 3 14:59:45 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us