Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developers
Brief
Unknown threat actors distribute malicious downloader functionality separated across several npm packages targeting users of Alibaba tools.
The final payload is a covert and highly targeted RAT capable of data exfiltration, command execution and lateral spreading using DingTalk tools Analysis of a malicious npm package lib-mtop containing a simple downloader malware led to an investigation into a targeted campaign that remained undetected for 3 months.
The lib-mtop package, originally published three years ago, had three new versions published at the end of March, 2026. This indicates a potential maintainer account takeover, but the possibility of a maintainer going rogue can’t be excluded.
