The Hacker News reports that malicious npm packages impersonating Alibaba developer tools delivered a cross-platform remote-access trojan, with some packages updated through the same maintainer account and researchers still assessing whether account takeover or a rogue maintainer was involved.
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
The Hacker News reports that malicious npm packages impersonating Alibaba developer tools delivered a cross-platform remote-access trojan, with some packages updated through the same maintainer account and researchers still assessing whether account takeover or a rogue maintainer was involved.
Source: Thehackernews