[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:distributed-npm-package-cluster-delivers-cross-platform-rat-targeting-alibaba-de-ms5swvlm":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":12,"action_required":18,"article_ids":19,"ioc_summary":21,"source_urls":22,"status":24,"expires_at":25,"created_at":26,"updated_at":27,"articles":28},"fb66169c-517a-477e-8a4a-828aed7843c8","Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developers","distributed-npm-package-cluster-delivers-cross-platform-rat-targeting-alibaba-de-ms5swvlm","Threat actors distributed malicious npm packages mimicking Alibaba dev tools, delivering a cross-platform RAT that went undetected for three months. The multi-stage payload enables data exfiltration, command execution, and lateral movement targeting Alibaba developers and internal tools. Any developer who installed these packages has a compromised environment with persistent remote access.","critical","advisory",[],[13,14,15,16,17],"Alibaba","npm","DingTalk","Alilang","Taobao","Immediately audit npm package dependencies in your environment for malicious packages matching Alibaba tooling names. Scan all developer systems for RAT IOCs, check for suspicious outbound connections, and revoke developer credentials as precaution.",[20],"553a528a-92d6-4832-a9da-e73d00d6cfa5",null,[23],"https:\u002F\u002Fsocket.dev\u002Fblog\u002Fnpm-rat-targets-alibaba?utm_medium=feed","active","2026-07-31T08:06:46.834+00:00","2026-07-29T08:06:49.652947+00:00","2026-07-29T08:08:27.55989+00:00",[29],{"id":20,"title":6,"url":23}]